CareerMoonshot

Director of Cybersecurity Governance, Risk and Compliance

University of Texas at Austin Staff ยท Utah

๐Ÿ“ UT MAIN CAMPUSvia workdayFirst listed here 2026-09-22
Apply on company site โ†—
Career Moonshot pulls this listing straight from the employer's hiring system โ€” no recruiter middleman, no reposts. Applying takes you directly to University of Texas at Austin Staff.
Job Posting Title: Director of Cybersecurity Governance, Risk and Compliance ---- Hiring Department: Dell Medical School ---- Position Open To: All Applicants ---- Weekly Scheduled Hours: 40 ---- FLSA Status: Exempt from FLSA ---- Earliest Start Date: Immediately ---- Position Duration: Expected to Continue ---- Location: UT MAIN CAMPUS ---- Job Details: General Notes Dell Medical School is seeking an experienced cybersecurity governance, risk and compliance leader to help shape and mature the cybersecurity GRC program supporting its growing clinical, academic, and research mission and path toward full hospital operations in 2030. The Director of Cybersecurity Governance, Risk and Compliance leads the information security GRC program for UT Medicine and Dell Medical School. Reporting to the Deputy CISO, this role builds and operates a mature GRC function that enables the organization to assess, manage, and mitigate cybersecurity risk across a complex clinical, academic, and research environment. Dell Medical School operates within UT Austin's established enterprise security program and inherits a baseline of enterprise policies, procedures, and tooling. Within this federated model, the Director focuses on cybersecurity risks and governance requirements specific to Dell Medical School's healthcare delivery, clinical research, regulatory compliance, and evolving operational environment. This is a program-building leadership opportunity with responsibility for GRC strategy, cybersecurity risk management, healthcare- and research-specific security governance, third-party risk, incident response coordination, business continuity and disaster recovery, and executive-level reporting. The role partners closely with technology, clinical, research, legal, privacy, audit, compliance, and UT Austin information security stakeholders as Dell Medical School continues to build capabilities that can scale with its future hospital operations. Purpose The Director of Cybersecurity Governance, Risk and Compliance provides strategic leadership for Dell Medical School's information security governance, risk management, and compliance program. Reporting to the Deputy CISO, the Director leads cybersecurity risk and governance activities across Dell Medical School's clinical, academic, research, and administrative environments while building capabilities that support continued organizational growth toward full hospital operations in 2030. Responsibilities GRC Program Leadership and Strategy Develop and execute the Dell Medical School GRC strategy aligned with organizational objectives, regulatory requirements, and the 2030 hospital opening. Build and lead a team of GRC analysts and security compliance professionals, providing ongoing coaching and career development. Deliver executive-level reporting on risk posture, compliance status, and program maturity to the Deputy CISO and governance bodies. Develop a GRC metrics and KPI framework measuring program effectiveness, employee compliance behavior, and security posture improvement over time. Evaluate cybersecurity insurance options and risk-transfer mechanisms as part of the organization's residual risk strategy. Coordinate with internal audit, legal, privacy, and enterprise compliance to align governance activities and manage risk consistently across organizational units. Risk Assessment and Security Posture Lead the annual HIPAA Security Risk Analysis and coordinate remediation planning with technology and operational leaders. Conduct security risk assessments of infrastructure solutions and clinical platforms to evaluate control adequacy and identify gaps. Maintain a risk register and hold technology and operational leaders accountable to remediation timelines across the clinical, academic, research, and administrative technology portfolio. Perform business impact analysis to evaluate the effect of cybersecurity risks on critical clinical operations and business functions. Evaluate the cost-effectiveness of security controls through structured cost-benefit analysis to optimize risk reduction relative to available resources. Conduct cyber risk trend analysis and reporting to identify emerging threats and inform remediation priorities. Execute security authorization reviews for new system acquisitions and major system changes, with authority to withhold security authorization until risks are reduced to acceptable thresholds. Governance, Policy and Compliance Author and maintain Dell Medical School cybersecurity policies, including policies that are more stringent than UT Austin baseline requirements where HIPAA, clinical operations, or research compliance demands. Ensure Dell Medical School security policies comply with applicable federal and state regulations and operate within the UT Austin enterprise security charter. Leverage applicable UT Austin security standards and guidelines and develop Dell Medical School-specific standards for clinical, biomedical, and clinical trial environments. Retain ownership of Dell Medical School security processes and procedures across operational domains. Identify top human cybersecurity risks and design behavioral mitigation campaigns targeting clinical, research, and administrative staff populations. Design and deliver a security awareness program using adult learning principles and maintain metrics to measure employee behavior change and program effectiveness. Respond to regulatory inquiries and support external audit engagements in coordination with Legal and Privacy while maintaining comprehensive compliance documentation. Third-Party and Vendor Risk Management Develop and operate a vendor security assessment program covering new software acquisitions, SaaS platforms, and technology service providers. Review Business Associate Agreements and technology contracts for security requirements and appropriate data-handling provisions. Evalua

More Utah jobs

Utah jobs ยท Browse all locations