Travis County Technology and Operations is seeking an Information Security Analyst Sr to join the Enterprise Risk Management Division. Performs advanced information security, compliance, risk management, and audit activities in support of the County's Information Assurance and cybersecurity programs. Serves as a senior-level subject matter resource for assessing compliance with information security requirements, with significant responsibility for supporting the County's Criminal Justice Information Services (CJIS) compliance program and evaluating compliance with the FBI CJIS Security Policy. Plans and conducts technical and administrative security assessments and audits; evaluates security controls; identifies compliance gaps and risks; develops findings and recommendations; and monitors corrective action and remediation activities. Assists County departments with interpreting and implementing applicable security requirements, including CJIS, NIST, HIPAA, County policies, and other regulatory or contractual requirements. Conducts information technology risk assessments and evaluates administrative, technical, and physical safeguards protecting County systems and information. Reviews system configurations, policies, procedures, documentation, audit records, access controls, security architecture, and supporting evidence to determine whether security controls are appropriately designed, implemented, and operating as intended. Develops assessment methodologies, audit procedures, control checklists, compliance documentation, risk reports, and executive-level summaries. Collaborates with County departments, Information Technology personnel, information security staff, departmental security representatives, management, vendors, auditors, and external agencies to strengthen security governance and maintain regulatory compliance. This position is eligible for teleworking, in office as needed. This is a senior-level information security classification within the Information Technology job family. Incumbents perform complex information security, compliance, audit, and risk management activities requiring advanced knowledge of cybersecurity principles, regulatory requirements, security frameworks, and information technology controls. The Information Security Analyst Senior exercises considerable independent judgment in planning and conducting security assessments and audits, interpreting security and compliance requirements, evaluating technical and administrative controls, identifying deficiencies and risks, and developing recommendations for corrective action. The position will serve as a subject matter resource for the County's Criminal Justice Information Services (CJIS) compliance program and will coordinate compliance and audit activities across multiple County departments that access, process, store, transmit, or support Criminal Justice Information (CJI). Responsibilities may include assessing compliance with the FBI CJIS Security Policy, preparing departments for internal and external audits, documenting findings, monitoring remediation activities, and assisting departments with implementation of required security controls. This classification may lead projects, mentor or provide technical guidance to other staff, and represent the department in meetings with County departments, auditors, regulatory entities, vendors, and other governmental agencies. This classification may require a flexible work schedule to meet operational or audit requirements.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior