More jobs:
Lead GRC Analyst; IT/Security
Job in
Manor, Travis County, Texas, 78653, USA
Listed on 2026-07-13
Listing for:
Ultra Clean Technology
Full Time
position Listed on 2026-07-13
Job specializations:
-
IT/Tech
Cybersecurity, Information Security, IT Business Analyst
Job Description & How to Apply Below
Analyst III, IT Information Security
Location:
Austin, TX.
Analyst III, IT Information Security is a contributor responsible for strengthening the organization’s security posture through analysis, detection, incident response, and security program development. This role blends technical expertise with strategic thinking, ensuring that security controls, policies, and processes effectively protect systems, data, and users across the enterprise.
Role Overview- The UCT GRC Specialist will support the design, execution, and maturity of UCT’s IT governance, risk, and compliance program. This role is responsible for coordinating IT risk management activities, supporting control design and testing, maintaining audit‑ready evidence, and partnering with IT, Security, Legal, Finance, HR, Operations, and business stakeholders to embed compliance into day‑to‑day processes.
- The role will help maintain a structured GRC program aligned with applicable regulatory requirements, SOX obligations, cybersecurity frameworks, internal policies, and UCT’s risk appetite. The specialist will also support continuous improvement initiatives, including automation, workflow optimization, reporting, and development of playbooks and self‑service resources.
- Support the vendor and cloud service provider risk review process, including intake, security questionnaire review, SOC 2 report review, architecture and access considerations, contract support, risk documentation, and stakeholder follow‑up.
- Evaluate vendor security posture in coordination with technical subject matter experts and document risks, compensating controls, remediation commitments, and risk acceptance decisions where applicable.
- Maintain vendor risk records and support reporting on third‑party risk themes, overdue remediation items, and exceptions that require management awareness.
- Administer, optimize, and support GRC and compliance automation platforms to improve workflow efficiency, reduce manual effort, and strengthen reporting consistency.
- Develop and maintain compliance metrics, dashboards, process trackers, and executive reports to communicate program status, control performance, audit readiness, and remediation progress.
- Identify opportunities to streamline recurring compliance activities, standardize evidence collection, automate reminders, and improve stakeholder visibility into open tasks and deadlines.
- Establish, maintain, and mature the Enterprise IT Risk Register, including risk identification, categorization, likelihood and impact scoring, ownership assignment, risk response, and status tracking.
- Partner with risk owners to develop and monitor risk treatment plans, track remediation progress, and escalate high or critical risks when timelines, ownership, or mitigation plans require leadership attention.
- Develop and present risk dashboards, compliance metrics, and executive‑ready reports that provide leadership with a clear view of UCT’s IT risk environment, control gaps, remediation status, and program maturity.
- Support the scoping, design, and maturity of UCT’s IT compliance program by mapping IT controls to applicable frameworks and requirements, including SOX, ITGC expectations, CIS, NIST CSF, ISO 27001, SOC 2, and other relevant regulatory or customer obligations.
- Perform control gap analyses, document findings, assess control maturity, and develop remediation roadmaps in partnership with control owners, system owners, and process owners.
- Design, document, and improve internal controls and common control frameworks to support evolving compliance requirements, reduce duplication, and improve consistency across applications, infrastructure, and business processes.
- Plan, coordinate, and perform site walkthroughs to evaluate local IT operations, physical and logical access practices, change management procedures, backup and recovery processes, asset management, and compliance with established IT policies and control requirements.
- Partner…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×