Texas Health and Human Services Commission logo

Cybersecurity Compliance Analyst

Texas Health and Human Services Commission

On-siteAustin, TXmid$84k–$125kPosted 2h ago

Visa & sponsorship

  • The posting says it will not sponsor a visa for this role.

Job description

Join the Texas Health and Human Services Commission (HHSC) and be part of a team committed to creating a positive impact in the lives of fellow Texans. At HHSC, your contributions matter, and we support you at each stage of your life and work journey. Our comprehensive benefits package includes 100% paid employee health insurance for full-time eligible employees, a defined benefit pension plan, generous time off benefits, numerous opportunities for career advancement and more. Explore more details on the Benefits of Working at HHS webpage.

Functional Title: Cybersecurity Compliance Analyst

Job Title: Cybersecurity Analyst III

Agency: Health & Human Services Comm

Department: CHIEF INFO SECURITY OFFICE

Posting Number: 20838

Closing Date: 10/01/2026

Posting Audience: Internal and External

Occupational Category: Computer and Mathematical

Salary Range: $7,015.16- $10,416.66

Pay Frequency: Monthly

Salary Group: TEXAS-B-27

Shift: Day

Additional Shift: Days (First)

Telework:

Travel:

Regular/Temporary: Regular

Full Time/Part Time: Full time

FLSA Exempt/Non-Exempt: Exempt

Facility Location:

Job Location City: AUSTIN

Job Location Address: 701 W 51ST ST

Other Locations:

MOS Codes: 0605,0630,0631,0639,0670,0679,0681,1702,1705,1710,1720,1721,1799,2611,2659,8055,8858,14N,14NX,170A

170B,17A,17B,17C,17C0,17DX,17S,17SX,17X,181X,182X,183X,184X,1B4X1,1D7X1,1N4X1,255A,255N,255S,25B,25D

26A,26B,26Z,514A,5C0X1D,5C0X1N,5C0X1R,5C0X1S,5IX,681X,682X,683X,781X,782X,783X,784X,CTI,CTM,CTR,CWT

CYB10,CYB11,CYB12,CYB13,CYB14,IS,ISM,ISS,IT,ITS

Brief Job Description:

This position is open to U.S. Citizens and permanent residents.

This onsite role requires the selected candidate to work from an HHS office in Austin, Texas.

The Cybersecurity Compliance Analyst performs professional-level work supporting cybersecurity compliance, audit coordination, policy and standards, publication, and procurement and contract support. The position supports alignment with applicable regulatory and policy requirements, strengthens compliance readiness, and promotes integration of security controls and statues within enterprise governance and external business engagements.

This position is responsible for interpreting regulatory changes, legislative reviews, state and federal laws, analyzing materials for applicability to agency requirements, and supporting enterprise cybersecurity governance activities. Work includes assisting with compliance implementation, research and analyses, critical thinking, accountability, audit task, agency publication management, documentation management, and incorporation of security requirements into procurement and third-party business processes. This position performs highly complex information security and cybersecurity analysis work. Works under limited supervision, with considerable latitude for the use of initiative and independent judgment. The position is responsible for research and implement new security risk and mitigation strategies, tools, techniques, and solutions for the prevention, detection, containment, and correction of data security breaches.

Essential Job Functions (EJFs):

Essential Job Functions represent the principal duties of the position and serve as the basis for performance evaluation, accountability, and successful execution of cybersecurity compliance, governance, audit readiness, policy maintenance, and third-party security responsibilities.

(20%) EJF 1 – Cybersecurity Governance, Regulatory Analysis, and Compliance Program Support

  • Supports administration and maturity of the information security compliance program by coordinating compliance activities, tracking deliverables, maintaining governance documentation, and ensuring assigned tasks are completed accurately and timely.

  • Reviews penetration testing results, supports vulnerability remediation efforts, and uses security tools to evaluate and track risk.

  • Analyzes regulatory, statutory, state, federal, and agency security requirements to determine applicability, assess impacts, and communicate compliance with obligations, risks, and recommend appropriate stakeholders.

  • Maintains authoritative compliance records, trackers, evidence repositories, decision logs, and supporting documentation to promote consistency, traceability, audit readiness, and executive-level visibility into compliance status.

  • Provides governance support by preparing meeting materials, documenting decisions, coordinating follow-up actions, monitoring compliance initiatives, and escalating risks, dependencies, or overdue items as appropriate.

  • Documents project scope, objectives, assumptions, timelines, deliverables, risks, and status updates for assigned compliance and governance tasks; coordinates resources and stakeholder communications to support successful and accountable execution.

  • Conducts detailed research and review of technical and non-technical information, evidentiary materials, legal and regulatory references, and supporting documentation; applies analytical methods to identify, organize, correlate, and document information for compliance with NIST SP 800-53, Texas Department of Information Resources (DIR) requirements, Criminal Justice Information Services (CJIS), IRS Publication 1075, privacy requirements, security policy requirements, applicable legal standards, and proposed legislative impacts.

(40%) EJF 2 – Cybersecurity Policy, Standards, Process, and Publication Management

  • Leads and supports review, development, maintenance, and publication of cybersecurity policies, processes, standards, procedures, and guidance to ensure alignment with TAC 202, enterprise security requirements, regulatory obligations, and operational needs.

  • Evaluates security, regulatory, privacy, data protection, and operational requirements to identify gaps, inconsistencies, outdated language, or control deficiencies in existing policies, processes, standards, and publications.

  • Research emerging cybersecurity topics, technologies, regulatory trends, and industry practices, including cloud services, artificial intelligence, data protection, and third-party risk, and incorporates findings into agency policies, standards, processes, and guidance materials.

  • Coordinates updates, reviews, approvals, version control, and lifecycle maintenance of cybersecurity policies, standards, processes, and publications to ensure artifacts remain current, accurate, enforceable, and auditable.

  • Develops and maintains security implementation guidance, control language, compliance references, and procedural materials that promote consistent interpretation, implementation, monitoring, and auditability of security requirements.

  • Ensures IT security publications, procedures, guidelines, templates, reference materials, and knowledge artifacts are organized, accessible, consistently formatted, and aligned with agency governance and compliance expectations.

(10%) EJF 3 – Audit Coordination, Evidence Management, and Remediation Support

  • Coordinates audit readiness activities by collecting, validating, organizing, and maintaining evidence mapped to applicable policies, standards, processes, regulatory requirements, and control expectations.

  • Reviews audit evidence and supporting documentation for completeness, accuracy, consistency, and alignment with established security policies, procedures, standards, and control requirements; identifies discrepancies and escalates issues as needed.

  • Supports stakeholders in responding to audit requests, control inquiries, corrective action plans, and remediation activities by interpreting applicable security requirements and referencing approved policy, process, standard, and publication artifacts.

  • Tracks audit findings, management responses, remediation actions, target dates, evidence updates, and closure documentation; supports updates to policies, processes, and standards, and published guidance to prevent recurrence and strengthen compliance posture.

(20%) EJF 4 – Third-Party Security, Risk Management, and Procurement Support

  • Supports risk management framework activities by assisting with categorization, control identification, documentation review, risk tracking, evidence collection, and coordination of security requirements throughout the system or vendor lifecycle. Including POA&M, RBD and document entries in Archer GRC.

  • Reviews third-party security documentation, including data use agreements, memoranda of understanding, security exhibits, contract terms, attestations, and vendor-provided materials, to assess alignment with agency policies, standards, privacy requirements, and published security expectations.

  • Supports procurement, contract, and vendor review activities by verifying that required security controls, deliverables, reporting obligations, data protection requirements, and policy-based expectations are documented and traceable.

  • Ensures security expectations are incorporated into procurement documentation, vendor communications, standards, procedures, formal publications, and other governance artifacts where applicable.

  • Collaborates with security, IT, legal, procurement, privacy, contract management, and business stakeholders to promote consistent implementation, understanding, and documentation of security requirements across third-party engagements.

(10%) EJF 5 – Other Duties as Assigned: Performs other duties as assigned within the scope of the position, including activities that support cybersecurity governance, compliance, audit readiness, policy maintenance, risk management, and agency operational needs.

Knowledge, Skills and Abilities (KSAs):

The following knowledge, skills, and abilities are required to successfully perform the essential functions of this position and support effective execution of cybersecurity compliance, governance, audit readiness, policy maintenance, third-party security, and risk management responsibilities:

  • Knowledge of cybersecurity governance, risk, and compliance principles, including security control frameworks, regulatory requirements, agency policies, standards, procedures, audit support practices, and third-party security review concepts.

  • Knowledge of applicable cybersecurity and compliance requirements, including NIST SP 800-53, Texas Department of Information Resources requirements, TAC 202, CJIS, IRS Publication 1075, privacy requirements, data protection expectations, and related legal or regulatory obligations.

  • Skill in interpreting regulatory, statutory, technical, and policy requirements; assessing applicability to agency operations; identifying gaps, risks, and dependencies; and documenting clear, supportable compliance recommendations.

  • Skill in developing, reviewing, maintaining, and organizing cybersecurity policies, standards, procedures, implementation guidance, publications, evidence repositories, trackers, decision logs, and other governance artifacts.

  • Skill in coordinating audit readiness activities, collecting and validating evidence, supporting corrective action plans, tracking remediation, and maintaining documentation that demonstrates compliance and supports audit closure.

  • Skill in reviewing procurement, contract, vendor, data use, and third-party security documentation to ensure security controls, reporting expectations, data protection requirements, and compliance obligations are appropriately documented and traceable.

  • Ability to compile, analyze, correlate, and evaluate technical and non-technical information, including evidentiary materials, regulatory references, security documentation, and operational data, to support sound compliance and risk-based decisions.

  • Ability to communicate complex cybersecurity, compliance, audit, and risk information clearly and professionally to technical, business, procurement, legal, privacy, contract management, and executive stakeholders.

  • Ability to manage multiple priorities, meet deadlines, maintain accountability for assigned tasks, coordinate cross-functional activities, and escalate risks, issues, or overdue items in a timely and appropriate manner.

Analytical, Organizational, and Governance Skills:

  • Ability to interpret, evaluate, and apply regulatory, statutory, technical, privacy, and security requirements to agency policies, standards, procedures, procurement activities, and audit documentation.

  • Ability to manage documentation, evidence, trackers, version history, approvals, and supporting artifacts in a manner that promotes accuracy, consistency, traceability, audit readiness, and accountability.

  • Ability to identify process gaps, recommend practical improvements, strengthen governance practices, and support maturity of cybersecurity compliance, policy management, audit readiness, and third-party security processes.

Communication, Collaboration and Formal documentation Skills:

  • Ability to communicate cybersecurity risk, compliance obligations, audit concerns, and policy requirements in a clear business language that supports informed decision-making and timely action.

  • Ability to facilitate governance meetings, working sessions, document reviews, audit discussions, and follow-up activities with clear agendas, documented outcomes, action tracking, and appropriate escalation.

  • Ability to build effective working relationships across technical teams, business programs, procurement, legal, privacy, contract management, vendors, auditors, and executive stakeholders.

  • Ability to prepare clear, accurate, and professional written materials, including summaries, status updates, policy language, audit responses, guidance documents, meeting notes, and executive-ready communications.

  • Ability to maintain confidentiality, protect sensitive information, and support the security and integrity of critical infrastructure systems by ensuring compliance with applicable laws, regulations, policies, and security requirements

Registrations, Licensure Requirements or Certifications:

N/A

Initial Screening Criteria:

Minimum Required Qualifications

  • Bachelor’s degree in information security, Information Technology, or related field, or equivalent experience on a year-for-year basis.

  • Minimum of five (5) years of experience in cybersecurity governance, risk management, or compliance.

  • Experience implementing RMF and security authorization processes.

  • Experience working with enterprise GRC and IT service management tools.

Preferred Qualifications

  • Experience in public sector or healthcare security governance environments.

  • Experience with audit, procurement or contract support

Additional Information:

Candidates for this position will be subject to a pre-employment security review to determine employment eligibility*.*

This is a hybrid position based in Austin, TX with at least 3 days in the office required.

Any employment offer is contingent upon available budgeted funds. The offered salary will be determined in accordance with budgetary limits and the requirements of HHSC Human Resources Manual.

#LI-IN1

Review our Tips for Success when applying for jobs at DFPS, DSHS and HHSC.

Active Duty, Military, Reservists, Guardsmen, and Veterans:

Military occupation(s) that relate to the initial selection criteria and registration or licensure requirements for this position may include, but not limited to those listed in this posting. All active-duty military, reservists, guardsmen, and veterans are encouraged to apply if qualified to fill this position. For more information please see the Texas State Auditor’s Job Descriptions, Military Crosswalk and Military Crosswalk Guide at Texas State Auditor's Office - Job Descriptions.

ADA Accommodations:

In compliance with the Americans with Disabilities Act (ADA), HHSC and DSHS agencies will provide reasonable accommodation during the hiring and selection process for qualified individuals with a disability. If you need assistance completing the on-line application, contact the HHS Employee Service Center at 1-888-894-4747. If you are contacted for an interview and need accommodation to participate in the interview process, please notify the person scheduling the interview.

Pre-Employment Checks and Work Eligibility:

Depending on the program area and position requirements, applicants selected for hire may be required to pass background and other due diligence checks.

HHSC uses E-Verify. You must bring your I-9 documentation with you on your first day of work. Download the I-9 Form

Telework Disclaimer:

This position may be eligible for telework. Please note, all HHS positions are subject to state and agency telework policies in addition to the discretion of the direct supervisor and business needs.