Job Posting Title:
Director of Cybersecurity Governance, Risk and Compliance
----
Hiring Department:
Dell Medical School
----
Position Open To:
All Applicants
----
Weekly Scheduled Hours:
40
----
FLSA Status:
Exempt from FLSA
----
Earliest Start Date:
Immediately
----
Position Duration:
Expected to Continue
----
Location:
UT MAIN CAMPUS
----
Job Details:
General NotesDell Medical School is seeking an experienced cybersecurity governance, risk and compliance leader to help shape and mature the cybersecurity GRC program supporting its growing clinical, academic, and research mission and path toward full hospital operations in 2030.
The Director of Cybersecurity Governance, Risk and Compliance leads the information security GRC program for UT Medicine and Dell Medical School. Reporting to the Deputy CISO, this role builds and operates a mature GRC function that enables the organization to assess, manage, and mitigate cybersecurity risk across a complex clinical, academic, and research environment.
Dell Medical School operates within UT Austin's established enterprise security program and inherits a baseline of enterprise policies, procedures, and tooling. Within this federated model, the Director focuses on cybersecurity risks and governance requirements specific to Dell Medical School's healthcare delivery, clinical research, regulatory compliance, and evolving operational environment.
This is a program-building leadership opportunity with responsibility for GRC strategy, cybersecurity risk management, healthcare- and research-specific security governance, third-party risk, incident response coordination, business continuity and disaster recovery, and executive-level reporting. The role partners closely with technology, clinical, research, legal, privacy, audit, compliance, and UT Austin information security stakeholders as Dell Medical School continues to build capabilities that can scale with its future hospital operations.
PurposeThe Director of Cybersecurity Governance, Risk and Compliance provides strategic leadership for Dell Medical School's information security governance, risk management, and compliance program. Reporting to the Deputy CISO, the Director leads cybersecurity risk and governance activities across Dell Medical School's clinical, academic, research, and administrative environments while building capabilities that support continued organizational growth toward full hospital operations in 2030.
ResponsibilitiesGRC Program Leadership and Strategy
Develop and execute the Dell Medical School GRC strategy aligned with organizational objectives, regulatory requirements, and the 2030 hospital opening.
Build and lead a team of GRC analysts and security compliance professionals, providing ongoing coaching and career development.
Deliver executive-level reporting on risk posture, compliance status, and program maturity to the Deputy CISO and governance bodies.
Develop a GRC metrics and KPI framework measuring program effectiveness, employee compliance behavior, and security posture improvement over time.
Evaluate cybersecurity insurance options and risk-transfer mechanisms as part of the organization's residual risk strategy.
Coordinate with internal audit, legal, privacy, and enterprise compliance to align governance activities and manage risk consistently across organizational units.
Risk Assessment and Security Posture
Lead the annual HIPAA Security Risk Analysis and coordinate remediation planning with technology and operational leaders.
Conduct security risk assessments of infrastructure solutions and clinical platforms to evaluate control adequacy and identify gaps.
Maintain a risk register and hold technology and operational leaders accountable to remediation timelines across the clinical, academic, research, and administrative technology portfolio.
Perform business impact analysis to evaluate the effect of cybersecurity risks on critical clinical operations and business functions.
Evaluate the cost-effectiveness of security controls through structured cost-benefit analysis to optimize risk reduction relative to available resources.
Conduct cyber risk trend analysis and reporting to identify emerging threats and inform remediation priorities.
Execute security authorization reviews for new system acquisitions and major system changes, with authority to withhold security authorization until risks are reduced to acceptable thresholds.
Governance, Policy and Compliance
Author and maintain Dell Medical School cybersecurity policies, including policies that are more stringent than UT Austin baseline requirements where HIPAA, clinical operations, or research compliance demands.
Ensure Dell Medical School security policies comply with applicable federal and state regulations and operate within the UT Austin enterprise security charter.
Leverage applicable UT Austin security standards and guidelines and develop Dell Medical School-specific standards for clinical, biomedical, and clinical trial environments.
Retain ownership of Dell Medical School security processes and procedures across operational domains.
Identify top human cybersecurity risks and design behavioral mitigation campaigns targeting clinical, research, and administrative staff populations.
Design and deliver a security awareness program using adult learning principles and maintain metrics to measure employee behavior change and program effectiveness.
Respond to regulatory inquiries and support external audit engagements in coordination with Legal and Privacy while maintaining comprehensive compliance documentation.
Third-Party and Vendor Risk Management
Develop and operate a vendor security assessment program covering new software acquisitions, SaaS platforms, and technology service providers.
Review Business Associate Agreements and technology contracts for security requirements and appropriate data-handling provisions.
Evaluate proposed vendor solutions through review of SOC 2 reports, penetration test results, and security questionnaire responses.
Develop and maintain vendor security onboarding procedures, including risk tiering and baseline assessment requirements for new technology partners.
Build escalation and communication plans for third-party risk events and develop remediation action plans when deficiencies are identified.
Approve vendor onboarding based on security assessment outcomes in coordination with Procurement and Legal and withhold approval when security requirements are not met.
Incident Response and Business Continuity
Own and maintain Dell Medical School's incident response capability for events requiring a response beyond UT Austin's initial handling scope.
Develop business continuity and disaster recovery plans for clinical and business systems where Dell Medical School bears primary responsibility.
Design tabletop exercise scenarios and coordinate preparedness exercises with internal teams and UT Austin campus security operations.
Define escalation paths, communication protocols, and recovery playbooks for security events affecting clinical and business systems.
Coordinate with legal, privacy, and communications teams to incorporate regulatory notification obligations and crisis communication requirements into response plans.
Research and Application Security Governance
Establish and maintain cybersecurity governance requirements for research computing environments involving Controlled Unclassified Information (CUI), Protected Health Information (PHI), and export-controlled information.
Define application security standards and secure coding requirements integrated throughout the software development and integration lifecycle.
Oversee security testing activities, including static analysis and vulnerability scanning for internally developed and integrated applications.
Facilitate threat modeling for new applications and services to identify and address security design risks before deployment.
Develop and maintain cloud security governance policies covering SaaS platform adoption and cloud-hosted infrastructure.
Additional Responsibilities
Represent the organization at cybersecurity and healthcare security conferences and industry forums.
Participate in enterprise risk committees and strategic planning sessions.
Maintain awareness of industry trends, emerging threats, and regulatory developments to continuously improve the GRC program.
Perform related duties as required.
Required QualificationsMaster's degree in Information Technology, Cybersecurity, Health Informatics, or a related field.
Minimum of five years of experience in progressive leadership roles in information security governance or Governance, Risk and Compliance (GRC).
Minimum of eight years of experience in healthcare, banking, defense, or other high-security environments.
CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager).
Relevant education and experience may be substituted as appropriate.
Preferred QualificationsDemonstrated experience conducting HIPAA Security Risk Analyses in a covered entity or business associate environment.
Experience with CMMC or NIST 800-171 compliance programs in an academic or research setting.
Experience managing third-party cybersecurity risk programs in a highly regulated environment.
Experience designing cybersecurity awareness programs using behavior-based learning approaches.
HCISPP (Healthcare Information Security and Privacy Practitioner).
CRISC (Certified in Risk and Information Systems Control).
CISA (Certified Information Systems Auditor).
Healthcare-specific GRC certifications.
Salary Range$170,368+ depending on qualifications
Working ConditionsStandard office environment and equipment.
Repetitive use of a keyboard.
Standard exposure risk associated with a clinical and academic environment.
Required MaterialsImportant for applicants who are NOT current university employees or contingent workers: You will be prompted to submit your resume the first time you apply, then you will be provided an option to upload a new Resume for subsequent applications. Any additional Required Materials (letter of interest, references, etc.) will be uploaded in the Application Questions section; you will be able to multi-select additional files. Before submitting your online job application, ensure that ALL Required Materials have been uploaded. Once your job application has been submitted, you cannot make changes.
Important for Current university employees and contingent workers: As a current university employee or contingent worker, you MUST apply within Workday by searching for Find UT Jobs. If you are a current University employee, log-in to Workday, navigate to your Worker Profile, click the Career link in the left hand navigation menu and then update the sections in your Professional Profile before you apply. This information will be pulled in to your application. The application is one page and you will be prompted to upload your resume. In addition, you must respond to the application questions presented to upload any additional Required Materials (letter of interest, references, etc.) that were noted above.