Posted 07 August, 2026
IT SPECIALIST - IT Governance, Risk, and Compliance
Southwest Research Institute - Fulltime
San Antonio, TX, US
Full Time
Job Description
Who We Are: SwRI’s cybersecurity mission is to secure the enterprise by evaluating, implementing, and operating a full suite of cybersecurity tools, services, and processes. Objectives of this Role: Compliantly pursue selection, acquisition, and maintenance of technologies. Apply cybersecurity frameworks and policies across the Institute and provide opportunities for remediations. Raise awareness of cyber risks to the Institute through the application of the risk assessment process and report to leadership for risk mitigation. Propose, generate, and review security metrics to demonstrate security progress and opportunities for improvement. Assist in contract review and third-party risk. Daily and Monthly Responsibilities: Evaluating the Institute’s compliance with cybersecurity internal controls and industry frameworks. Authoring and tracking Plans of Actions and Milestones to bring security controls into compliance. Support risk management activities by operating the Institute’s IT risk management process. Assist in developing training, standards, and guidance to support cyber governance processes. Evaluating policy exception requests and make recommendations to the CISO regarding risk reduction and approval. Requirements: Requires a Bachelors degree in Cybersecurity, Information Technology, or related degree with relevant experience. In lieu of a Bachelors degree, 6 years of Cybersecurity and/or IT administration experience an Associates degree or high school education or equivalent and related certifications is required. Certified Information Systems Security Professional (CISSP) preferred. 3 years: Experience auditing IT controls environments or conducting compliance assessments 3 years: Experience in any of various IT and security functions (E.g., IT audit, cybersecurity, IT administration, programming, contracts management, IT GRC) is desirable 3 years: Knowledge of information security standards, E.g., NIST 800-171 or 800-53, CIS Critical Security Controls 3 years: Exposure to/understanding of the fundamentals of network and systems administration (e.g., Windows Server and desktop, Linux, TCP/IP, network subnetting) A valid/clear driver's license is required.
