Job Details - Information Security Portfolio Manager - 52663186 | HHSC Health And Specialty Care System

Information Security Portfolio Manager (ISPM) in Austin, TX

Location: Austin, TX
Career Level: Mid-Senior Level
Industries: Government Administration

Description

Join the Texas Health and Human Services Commission (HHSC) and be part of a team committed to creating a positive impact in the lives of fellow Texans. At HHSC, your contributions matter, and we support you at each stage of your life and work journey. Our comprehensive benefits package includes 100% paid employee health insurance for full-time eligible employees, a defined benefit pension plan, generous time off benefits, numerous opportunities for career advancement and more. Explore more details on the Benefits of Working at HHS webpage.

 

Functional Title: Information Security Portfolio Manager (ISPM) 
Job Title: 
Cybersecurity Analyst III 
Agency: 
Health & Human Services Comm 
Department: 
CHIEF INFO SECURITY OFFICE 
Posting Number: 
16696 
Closing Date: 
07/05/2026 
Posting Audience: 
Internal and External 
Occupational Category: 
Computer and Mathematical 
Salary Range: 
$7,015.16 - $10,416.66 
Pay Frequency:
Monthly
Salary Group: 
TEXAS-B-27 
Shift: 
Day 
Additional Shift: 
Days (First) 
Telework: 
 
Travel: 
 
Regular/Temporary: 
Regular 
Full Time/Part Time: 
Full time 
FLSA Exempt/Non-Exempt:
 Exempt 
Facility Location:
  
Job Location City:
 AUSTIN 
Job Location Address:
 701 W 51ST ST 
Other Locations:
  
MOS Codes:
0605,0630,0631,0639,0670,0679,0681,1702,1705,1710,1720,1721,1799,2611,2659,8055,8858,14N,14NX,170A 
170B,17A,17B,17C,17C0,17DX,17S,17SX,17X,181X,182X,183X,184X,1B4X1,1D7X1,1N4X1,255A,255N,255S,25B,25D 
26A,26B,26Z,514A,5C0X1D,5C0X1N,5C0X1R,5C0X1S,5IX,681X,682X,683X,781X,782X,783X,784X,CTI,CTM,CTR,CWT 
CYB10,CYB11,CYB12,CYB13,CYB14,IS,ISM,ISS,IT,ITS 

This position is open to U.S. Citizens and permanent residents.


This onsite role requires the selected candidate to work from an HHS office in Austin, Texas.

 

Brief Job Description:

This position performs senior-level information security analysis with emphasis on Archer eGRC development and administration functions. Researches, evaluates, and recommends managerial, technical and operational controls and procedures for the appropriate protection and reduction of risk for information resources. Evaluates business objectives and advises business partners on the security and compliance requirements as well as the risks within various business initiatives. Develops, recommends and evaluates the implementation of plans designed to safeguard information systems and information resources against accidental or unauthorized modification, destruction, or disclosure for agency administered systems as well as third party administered systems. Develops, monitors, evaluates, and maintains system security plans and corrective action plans to ensure the protection of information systems and information resources from unauthorized users. Designs and develops solutions in the eGRC platform. Provides guidance to agency staff on the eGRC platform. Coordinates/interacts/trains HHS Agencies on the development of eGRC solutions.

Independently interfaces with executive management throughout the agency and enterprise to assist the CISO in the delivery of the Information Security Program. 

 

Essential Job Functions (EJFs):

Provides highly advanced consultative and technical assistance regarding development and administration of the Archer eGRC platform. (55%)

 

Provides Archer eGRC subject matter leadership to other personnel where applicable (25%)

 

Performs needs assessment to identify requirements of automated systems and evaluates enterprise information security compliance standards. (10%)

 

Provides security and risk management services by performing risk identification, assessment, and remediation as well as regulatory and internal compliance monitoring using standards and processes as required to adequately protect HHS personnel, facilities, infrastructure, information, and business operations. Advises management and users regarding enterprise security program functions. (5%)

 

Attends work on a regular and predictable schedule in accordance with agency leave policy and performs other duties as assigned (5%). 

 

Knowledge, Skills and Abilities (KSAs):

  • Knowledge of enterprise security program management using Enterprise Governance Risk and Compliance solutions.
  • Knowledge of effective project management practices and ability to effectively manage multiple priorities within a security function providing services to numerous clients.
  • Knowledge of compliance requirements including 1 TAC 202, HIPAA/HITECH, IRS Publication 1075, Social Security Administration requirements, Texas Business and Commerce Code, and Texas Health and Safety Code. 
  • Knowledge in analyzing, recommending, and developing enterprise-wide security policies, standards, and guidelines within appropriate organizational risk tolerances
  • Knowledge and understanding of audit principles for the coordination and advisement of appropriate management action plans that will address the cause of control deficiencies.
  • This position requires an in-depth knowledge and understanding of the National Institute of Standards (NIST) Special Publications (800 Series) with particular emphasis on the SP 800-53 Security and Privacy Controls for Federal Information Systems and Organizations.
  • Knowledge and understanding of security program deficiencies and articulating those deficiencies to stakeholders.
  • Extensive knowledge of the control structures and application of controls.
  • Knowledge and understanding of audit principles related to responding to IT and Security audits.
  • Knowledgeable of National Institute of Standards and Technology (NIST) classes and families.
  • Knowledge of compliance requirements including 1 TAC 202, HIPAA/HITECH, IRS Publication 1075, Social Security Administration requirements, Texas Business and Commerce Code, and Texas Health and Safety Code. Experience performing risk assessments.
  • Professional presentation skills.
  • Skill and demonstrated ability in interpersonal communications and collaboration as part of a team providing security services to multiple clients.
  • Skill in critical thinking, root cause analysis and complex problem solving of information technology security threats relating to confidentiality, integrity and availability of agency data and systems.
  • Skill in implementing enforcement of security policy within technology solutions.
  • Skill in evaluating enterprise networks and systems for assurance of control requirements as specified by the IRS Publication 1075, Tax Information Security Guidelines for Federal, State and Local Agencies.
  • Ability to manage the control assertion and corrective action plan processes including the coordination of status updates and report submission.
  • Ability to maintain the security and integrity of critical infrastructure systems by preventing unauthorized access and ensuring compliance with laws and regulations related to national security and foreign ownership restrictions

 

Registrations, Licensure Requirements or Certifications:

Certified Information Systems Security Professional (CISSP), Certified Information Systems Auditor (CISA), Certified Information Systems Manager (CISM), Global Information Assurance Certification (GIAC), RSA Archer Certified Administrator 5.x or similar certifications preferred. 

 

Initial Screening Criteria:

Minimum Qualifications

  • Bachelor's degree in information security, Information Technology, or related field, or equivalent experience on a year-for-year basis.
  • Minimum of five (5) years of experience in cybersecurity governance, risk management, or compliance.
  • Experience implementing RMF and security authorization processes.
  • Experience working with enterprise GRC and IT service management tools.

 

Preferred Qualifications

  • Experience in public sector or healthcare security governance environments.

 

 

Additional Information:

  • Candidates for this position will be subject to a pre-employment security review to determine employment eligibility.
  • This is an onsite position, with 5 days in office required.
  • Any employment offer is contingent upon available budgeted funds. The offered salary will be determined in accordance with budgetary limits and the requirements of HHSC Human Resources Manual.

 

#LI-IN1

Review our Tips for Success when applying for jobs at DFPS, DSHS and HHSC.

 

Active Duty, Military, Reservists, Guardsmen, and Veterans:

Military occupation(s) that relate to the initial selection criteria and registration or licensure requirements for this position may include, but not limited to those listed in this posting. All active-duty military, reservists, guardsmen, and veterans are encouraged to apply if qualified to fill this position. For more information please see the Texas State Auditor's Job Descriptions, Military Crosswalk and Military Crosswalk Guide at Texas State Auditor's Office - Job Descriptions.

 

ADA Accommodations:

In compliance with the Americans with Disabilities Act (ADA), HHSC and DSHS agencies will provide reasonable accommodation during the hiring and selection process for qualified individuals with a disability. If you need assistance completing the on-line application, contact the HHS Employee Service Center at 1-888-894-4747. If you are contacted for an interview and need accommodation to participate in the interview process, please notify the person scheduling the interview.

 

Pre-Employment Checks and Work Eligibility:

Depending on the program area and position requirements, applicants selected for hire may be required to pass background and other due diligence checks.

 

HHSC uses E-Verify. You must bring your I-9 documentation with you on your first day of work. Download the I-9 Form

Telework Disclaimer:

This position may be eligible for telework.  Please note, all HHS positions are subject to state and agency telework policies in addition to the discretion of the direct supervisor and business needs.


 Apply on company website
Powered by CareerArc