Principal Cybersecurity Analyst - Risk Mgmt & AI Security
Listed on 2026-09-03
-
IT/Tech
Cybersecurity, Information Security & Data Protection
The University of Texas MD Anderson Cancer Center is seeking a highly skilled Principal Cybersecurity Analyst to serve as a technical authority within its Cybersecurity department.
The Principal Cybersecurity Analyst plays a critical role in shaping and advancing enterprise-wide governance, risk, and compliance (GRC) programs, with expanded accountability for emerging AI security and governance initiatives. This role operates at a strategic and architectural level while also ensuring operational effectiveness across cybersecurity risk management practices.
The Principal Cybersecurity Analyst contributes directly to safeguarding sensitive data, maintaining regulatory compliance, and strengthening the organization's security posture through innovative, data-driven risk management and governance strategies. The Principal Cybersecurity Analyst serves as a trusted advisor, architect, and leader within the cybersecurity function.
The ideal candidate brings advanced education in information systems or cybersecurity, extensive experience leading enterprise risk management or GRC programs, and strong knowledge of frameworks such as NIST, HIPAA, and HITRUST. Preferred candidates will also have hands‑on experience assessing AI/ML risk, strong executive communication skills, and certifications such as CISSP, CISM, or PMP.
Minimum $123,000 - Midpoint $154,000 - Maximum $185,000
Work Location:
Remote 100%
At UT MD Anderson, the Principal Cybersecurity Analyst plays an essential role in advancing cybersecurity innovation in a mission-driven healthcare environment. This position offers the opportunity to shape enterprise risk strategy, influence executive decision‑making, and lead emerging AI governance practices, all while supporting an organization dedicated to saving lives. Employees benefit from a collaborative culture, professional development opportunities, and a strong commitment to work‑life balance.
- Employer‑paid medical coverage starting day one for employees working 30+ hours/week, plus optional group dental, vision, life, AD&D, and disability insurance.
- Accruals for PTO and Extended Illness Bank, plus paid holidays, wellness, childcare, and other leave options.
- Tuition Assistance Program after six months of service and access to extensive wellness, fitness, and employee resource groups.
- Defined-benefit pension through the Teachers Retirement System, voluntary retirement plans, and employer‑paid life and reduced salary protection programs.
- Serve as principal architect and subject matter expert for enterprise GRC and cybersecurity risk programs
- Define and maintain risk assessment methodologies, control frameworks, and risk scoring models
- Establish workflows across development, staging, and production environments
- Develop SOPs, roles, segregation of duties, and change management processes
- Lead design and execution of enterprise risk management strategies
- Architect and maintain integrations across Archer, Tenable, Service Now, Microsoft Configuration Manager (SCCM/MECM), and Medigate
- Design automated workflows consolidating asset, vulnerability, and risk data
- Enable enterprise‑wide risk visibility and reporting through data‑driven systems
- Ensure data quality, reconciliation, and interoperability across platforms and CMDB
- Apply frameworks including NIST CSF, NIST 800‑53, HIPAA, and HITRUST
- Conduct control mapping, gap assessments, and compliance reportingli>
- Advise stakeholders on remediation strategies and regulatory requirements
- Align institutional policies with regulatory and accreditation standards
- Establish and mature AI security and governance programs
- Develop AI risk assessment criteria and governance standards
- Align controls to NIST AI Risk Management Framework and institutional policies
- Evaluate AI/ML tools and vendors for data protection and compliance risks
- Partner with data governance, privacy, and legal teams on AI initiatives
- Develop…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).