Ent Security Analyst II -GRC
Listed on 2026-05-22
-
Security
Cybersecurity, Information Security
Company Overview
Texas Tech University Health Sciences Center is enriching the lives of others by educating students, providing excellent patient care, and advancing knowledge through innovative research. TTUHSC graduates more health care professionals than any other health care institution in the state, conferring 24.2% of all degrees and certificates awarded from health‑related institutions in Texas. By providing comprehensive clinical services to more than 10 million individuals across 121 counties, TTUHSC is dedicated to advancing the health of people throughout Texas and beyond.
This is where world‑class education meets compassionate patient care – and we believe that our people are the reason for our institution’s lasting success and bright future.
We are nationally recognized as a great college to work for and provide many benefits, including paid leave, retirement plans, wellness programs, health insurance and more. Ready to start building a rewarding career in a positive environment where you can develop and thrive?
Visa InformationTTUHSC, at its sole discretion, may initiate new H‑1B I‑129 visa petitions in accordance with the directive issued by Governor Abbott. Approval from the Texas Workforce Commission is required. On a limited, case‑by‑case basis, the institution may also sponsor eligible individuals for change‑of‑status or change‑of‑employer petitions for qualifying positions. TTUHSC will not pay the $100,000 fee, if applicable.
Position DescriptionThe Enterprise Security Analyst II’s scope of responsibility includes information security management at the enterprise level. This includes ensuring that necessary safeguards are present, operational, and effective. The role involves assisting with training team members, leading or managing projects, and interfacing with users, vendors, or other stakeholders in providing operational support. Discretion and sound judgment are expected. Enterprise positions are restricted for use in central IT Division areas reporting to the institutional CIO and, as such, may interface with key IT leadership and/or other functional leadership from the Texas Tech University System institutions.
Major/ Essential Functions
- Conduct risk assessments to identify and evaluate potential threats and vulnerabilities. Manage the risk registry, including documenting, tracking and escalating risks. Develop and implement risk mitigation plans.
- Design, implement and test internal controls to mitigate identified risks. Ensure that internal controls are functioning as intended and effectively securing HSC (Health Sciences Center) and other risks.
- Document and maintain accurate records of internal control activities.
- Effectively monitor and track compliance with relevant laws, regulations and internal policies. Generate timely and accurate reports on compliance statuses, identifying any non‑compliance issues.
- Implement and maintain robust compliance programs to ensure adherence to regulatory requirements.
- Develop, review and maintain information security policies and procedures. Ensure policies align with regulatory requirements and HSC standards.
- Understand and interpret regulatory requirements and industry standards. Conduct regulatory compliance audits and assessments. Ensure compliance with internal policies, procedures and standards.
- Effectively communicate GRC‑related information to stakeholders, including management and employees.
- Collaborate with other departments and teams to ensure the effective implementation of GRC programs.
- Provide training and education to employees on GRC‑related policies and procedures.
Bachelor’s degree with coursework in computer science, MIS, IT, or other related area plus one (1) year related full‑time paid experience OR a combination of related education and/or experience to equal five (5) years.
In accordance with Texas Executive Order GA‑48 and applicable state or federal law, this position may involve access to, work on, or conduct research involving critical infrastructure. It will require background checks, including, but not limited to, criminal history and other security‑related screenings. Employment is…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).