About The Position

Develops, implements and operationalizes the Information Security governance and risk management functions to ensure the Program is compliant with established security controls frameworks, regulatory and legal requirements, policies and standards. Ensures that Information Security risk to the institution is appropriately managed. Subject matter expert on mature security governance structures and processes, risk management processes (enterprise and third party), and contractual, regulatory compliance requirements Leads and executes enterprise-wide security assessments and strategic projects to mature the Program. This position will support Texas Behavioral Health Center.

Requirements

  • Bachelor's Degree in computer science, information technology, or related field
  • 8 years of progressively responsible technology governance experience
  • Additional years of directly related experience may be substituted for stated degree on a year for year basis.

Nice To Haves

  • Progressively responsible experience establishing Information Security frameworks and aligning security controls (e.g. CIS, NIST, HIPAA, PCI), framework and Control gap analysis and remediation, project management, threat and risk modeling, building and maintaining a risk register.
  • Ability to respond to and audits, and leverage GRC tools (e.g. Archer, Logic Manager, Optro).
  • Experience creating framework-based risk assessments and consulting with technical and non-technical staff to implement and advance GRC initiatives based on best practices.
  • Possession of an industry certification, such as CRISC, CGRC, CISA.
  • Preferred experience working within a behavioral or mental health care environment, specifically performing information security, compliance, or risk management functions.
  • Expertise in HIPAA, The Joint Commission standards, Texas Administrative Code Chapter 477 (Information Security Standards), and the Texas Health and Safety Code.

Responsibilities

  • Implements established risk frameworks for the Information Security program.
  • Establishes and operationalizes formal security risk assessment frameworks to quantify and qualify risk including for third-party vendor risk, technology procurement (ISAC) and internal security controls.
  • Leads and executes enterprise-wide security assessments and strategic projects to mature the Program.
  • Tracks audit findings, coordinates creation of audit deliverables and ensures audit compliance.
  • Ensures Information Security Program compliance with established security controls framework, and regulatory and legal requirements, policies and standards.
  • Develops metrics and KPIs for Information Security Program maturity and operational and executive reporting.
  • Assists with creation and management of program governance.
  • Interfaces with departments, Information Resources, third-party vendors, and business partners to identify areas of risk and assist with development of plans to establish and maintain ongoing compliance.
  • Assists with various Information Security projects.
  • Stays up to date with regulatory changes, modern technology & security controls and practices.
  • Performs other duties as assigned.

Benefits

  • PPO medical plan, available day one at no cost for full-time employee-only coverage
  • 100%25 coverage for preventive healthcare-no copay
  • Paid Time Off, available day one
  • Retirement Programs through the Teacher Retirement System of Texas (TRS)
  • Paid Parental Leave Benefit
  • Wellness programs
  • Tuition Reimbursement
  • Public Service Loan Forgiveness (PSLF) Qualified Employer
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service