Please paste the following URL into a browser to view the entire job posting in the CAPPS Career Section: https://capps.taleo.net/careersection/ex/jobdetail.ftljob=00056958
You may apply to the job directly through the CAPPS Career Section. It is not necessary to apply both through Work In Texas and CAPPS Career Section
Job Posting:00056958Opened:3/16/2026Closes:3/31/2026Position Title:Cybersecurity Analyst III (Shared Technology Services Governance, Risk, and Compliance Analyst)Class/Group:0321/B27Military Occupation Specialty Code:Army: 17C, 25D; Navy: IT; Coast Guard: CYB10, CYB11, CYB12; Marine Corps: 0681, 0605; Air Force: 1D7X1, 1N4X1, Space Force: 5C0X1D, 5C0X1N, 5C0X1SFair Labor Standards Act Status:ExemptNumber of Vacancies:1Division/Section:COO/Shared Technology Services SecuritySalary Range:$8,333.34 - $10,000.00/monthDuration:RegularHours Worked Weekly:40Travel:OccasionalWork Location:North / Austin, Texas 78758Web site:https://dir.texas.gov/Refer Inquiries to:People and Culture OfficeTelephone:(512) 475-4957How To Apply:Select the link below to search for this position: https://capps.taleo.net/careersection/313/jobsearch.ftllang=en
Enter the job posting number and#8220;00056958and#8221; in the keyword search.You must create a CAPPS Career Section candidate profile or be logged in to apply.Update your profile and apply for the job by navigating through the pages and steps.Once ready, select and#8220;Submitand#8221; on the and#8220;Review and Submitand#8221; page.If you have problems accessing the CAPPS Career Section, please follow the instructions in the Resetting CAPPS Password for Job Candidate desk aid.Special Instructions:Applicants must provide in-depth information in theEXPERIENCE CREDENTIALSsection to demonstrate howthey meet the position qualifications. Incomplete applications may result in disqualification.Resumes may be uploaded as an attachment but are not accepted in lieu of the information required in theEXPERIENCE CREDENTIALSsection of the application.Interview Place/Time:Candidates will be notified for appointments as determined by the selection committee.Selective Service Registration:Section 651.005 of the Government Code requires males, ages 18 through 25 years, to provide proof of their Selective Service registration or proof of their exemption from the requirement as a condition of state employment.H-1B Visa Sponsorship:We are unable to sponsor or take over sponsorship of an employment Visa at this time.Equal Opportunity EmployerThe Department of Information Resources does not exclude anyone from consideration for recruitment, selection, appointment, training, promotion, retention, or any other personnel action, or deny any benefits or participation in programs or activities, which it sponsors on the grounds of race, color, national origin, sex, religion, age, or disability. Please call 512-475-4922 to request reasonable accommodation.Position DescriptionWhat We DoWe are a technology agency powered by people.DIR offers secure, modern, and cost-effective technology to help government entities in Texas serve their constituents.DIR is a fast-paced and collaborative environment with highly motivated, innovative, and engaged employees dedicated to achieving the best value for the state. We have over 325 professionals working at DIR who are honored to serve as the cornerstone of public sector technology in Texas. By joining DIR, you will be an integral part of transforming how Texas government serves Texans.Position SummaryThis Cybersecurity Analyst III (STS GRC Analyst) role within the Chief Operations Office (COO) supports DIRand#8217;s Shared Technology Services (STS) security program through governance, risk, and compliance (GRC) oversight and vendor security assurance. The position works with state agencies, DIR teams, and vendor partners to strengthen security governance, validate security documentation and control implementation, and support risk-based decision-making for services delivered through STS. The role also supports situational awareness of threats and vulnerabilities and communicates actionable security information to a wide range of stakeholders.This role performs highly complex (senior-level) cybersecurity analysis work. Interacts frequently with state agencies, state agency government staff and leadership, STS vendor personnel and leadership, and other interagency personnel using a variety of communication mechanisms to engage and deliver incident response services. May provide guidance to others. Works under limited supervision, with considerable latitude for the use of initiative and independent judgment.and#183; Provides GRC oversight for STS services by reviewing System Security Plans (SSPs), Service Management Manuals (SMMs), and supporting security artifacts to ensure documentation is accurate, complete, testable, and aligned with DIR requirements and applicable frameworks.and#183; Serves as a primary interface between DIR, agencies, and vendors to translate security and compliance requirements into clear, auditable expectations and measurable deliverables.and#183; Reviews vendor operational process documentation (for example incident/change/access/vulnerability management, logging/monitoring, backup/DR, configuration management) and validate alignment between documented controls and operational execution; identify gaps and drive corrective actions to closure.and#183; Supports periodic risk assessments, compliance reviews, and security exception evaluations, ensuring risk decisions include impact, compensating controls, accountable owners, and timelines.and#183; Reviews vendor assurance artifacts, including SOC 2 Type II reports and bridge letters, to assess scope alignment, control coverage, test period relevance, exceptions, subservice organization considerations, and residual risk to STS services.and#183; Analyzes SOC 2 exceptions and auditor observations, validate complementary user entity controls (CUECs), review vendor security policies and standards, and translate findings into actionable requirements, remediation expectations, and risk statements.and#183; Maintains situational awareness of emerging risks and threats impacting STS services, produce clear written outputs for leadership and stakeholders (findings summaries, remediation tracking, and program metrics), contribute to continuous improvement of STS security governance (workflows, checklists/templates, reporting cadence), and participate in an on-call rotation for incident escalation support and oversight.and#183; Performs other work-related duties as assigned.
Qualifications: Educationand#183; Graduation from an accredited four-year college or university with major coursework in information technology security, computer information systems, computer science, cybersecurity, management information systems, or a related field.and#183; Additional work-related experience may be substituted for education on a year-for-year basis (High-school diploma required).Experience and Training Requiredand#183; Five (5) years of experience in information security, IT risk management, compliance, or related IT security functions.and#183; Experience in one or more of the following areas: vulnerability management/scanning, formal risk assessments, security documentation/technical writing, regulatory compliance (TX-RAMP, FedRAMP, CJIS, IRS Pub. 1075, etc.), third-party/vendor assurance, or enterprise/data center security.and#183; Experience reviewing and interpreting security documentation and evidence, and producing clear written outputs such as findings, risk statements, and remediation tracking.and#183; Working knowledge of control frameworks and requirements mapping (for example NIST SP 800-53 or comparable control frameworks), including control narratives and evidence expectations.Experience and Training Preferredand#183; Experience and training in analyzing, recommending, developing, and implementi