What are the responsibilities and job description for the Information Security Risk Governance Manager position at Avc?
Information Security Risk Governance Manager
Location: Austin, TX (Remote/Hybrid options may be available)
Employment Type: Contract (Duration: Project-based, est. 6-12 months)
We are seeking an experienced Information Security Risk Governance Manager (equivalent to Information Security Manager 3 level) for a critical contract role. You will design and implement an enterprise-wide risk management framework to strengthen TEA's cybersecurity and technology risk posture. All work products are "works made for hire" and become the property of TEA. Potential candidates must satisfy criminal background checks as authorized by Texas law. TEA pays no fees for interviews or discussions during selection.
Key Responsibilities:
- Define end-to-end governance workflows for risk identification/intake, review/validation, acceptance/mitigation/transfer, and ongoing monitoring/reassessment.
- Establish roles and responsibilities for risk owners, reviewers, and governance bodies.
- Design escalation and reporting processes for high-risk and accepted risks.
- Engage stakeholders across business, technology, security, and governance functions to validate requirements and workflows.
- Facilitate workshops to socialize the risk register and processes.
- Support onboarding of initial risks into the enterprise risk register.
- Produce audit-ready documentation on risk register structure/data definitions, scoring methodology, workflows, and decision authorities.
- Provide knowledge transfer to TEA security staff for sustainability.
Deliverables:
- Enterprise Risk Register Framework: Standardized template and taxonomy.
- Risk Scoring and Prioritization Model: Documented likelihood/impact scales, scoring methodology, and prioritization logic.
- Risk Governance Model: Workflows for intake/review/acceptance/monitoring; roles/responsibilities matrix.
- Initial Population of Risk Register: Documented set of current cybersecurity/technology risks.
- Final Documentation Package: Consolidated guidance and operating procedures.
Minimum Qualifications (8 Years Required in Each):
- Experience with Risk Register Design and Framework.
- Experience with Risk Scoring and Prioritization Model.
- Experience with Governance Processes and Workflows.
- Experience with Stakeholder Engagement and Enablement.
- Demonstrated skills in documentation and knowledge transfer.
Preferred Qualifications:
- Expertise in education sector or public agency risk management.
- Familiarity with NIST, ISO 27001, or similar frameworks.
- Strong facilitation and communication skills for workshops/stakeholder sessions.
- Bachelor's degree in Information Security, Cybersecurity, IT, or related field.
Pay: $39.30 - $84,652.27 per hour
Work Location: Hybrid remote in Austin, TX
Salary : $39,300 - $84,652