The role also provides leadership for third-party risk management, incident response coordination, business continuity and disaster recovery, research security governance, and application security ...
The role also provides leadership for third-party risk management, incident response coordination, business continuity and disaster recovery, research security governance, and application security ...
$100 - $125/hr
... disaster risk reduction and preparedness. * Provide technical solutions globally, for regional and ... implementation research, internally and externally, including publications in peer reviewed ...
$100 - $125/hr
... disaster risk reduction and preparedness. * Provide technical solutions globally, for regional and ... implementation research, internally and externally, including publications in peer reviewed ...
$100 - $125/hr
... disaster risk reduction. * Deploy rapidly as part of emergency responses to support funding ... Establish and maintain relationships with donors, peer organizations, research and other ...
New
$100 - $125/hr
... disaster risk reduction. * Deploy rapidly as part of emergency responses to support funding ... Establish and maintain relationships with donors, peer organizations, research and other ...
New
... life sciences, and research institutions with scientific, technological, and operational ... Partner with Infrastructure and Security teams to ensure Disaster Recovery capabilities support ...
... life sciences, and research institutions with scientific, technological, and operational ... Partner with Infrastructure and Security teams to ensure Disaster Recovery capabilities support ...
... life sciences, and research institutions with scientific, technological, and operational ... Partner with Infrastructure and Security teams to ensure Disaster Recovery capabilities support ...
... life sciences, and research institutions with scientific, technological, and operational ... Partner with Infrastructure and Security teams to ensure Disaster Recovery capabilities support ...
... disaster recovery (BCDR), third-party risk management (TPRM), and AI governance. This is a ... research vendor markets to surface emerging risks and trends. * Own AI and third-party risk ...
... disaster recovery (BCDR), third-party risk management (TPRM), and AI governance. This is a ... research vendor markets to surface emerging risks and trends. * Own AI and third-party risk ...
Manager, Enterprise Risk Management
Cincinnati, OH · On-site
$100 - $125/hr
Conduct periodic risk assessments to identify emerging threats and coverage gaps; support business continuity and disaster recovery planning; research and implement tools and best practices to ...
Manager, Enterprise Risk Management
Cincinnati, OH · On-site
$100 - $125/hr
Conduct periodic risk assessments to identify emerging threats and coverage gaps; support business continuity and disaster recovery planning; research and implement tools and best practices to ...
... disaster recovery (BCDR), third-party risk management (TPRM), and AI governance. This is a ... research vendor markets to surface emerging risks and trends. * Own AI and third-party risk ...
Quick apply
... disaster recovery (BCDR), third-party risk management (TPRM), and AI governance. This is a ... research vendor markets to surface emerging risks and trends. * Own AI and third-party risk ...
$100 - $125/hr
Evidence of scholarly productivity or clear potential for developing an active research program ... risk communication, vulnerable populations, disaster behavior health, or emergency response to mass ...
$100 - $125/hr
Evidence of scholarly productivity or clear potential for developing an active research program ... risk communication, vulnerable populations, disaster behavior health, or emergency response to mass ...
Public Health-Graduate-Assistant/Associate Professor in Emergency Planning and Disaster Management (
Winston Salem, NC · On-site
$100 - $125/hr
Evidence of scholarly productivity or clear potential for developing an active research program ... risk communication, vulnerable populations, disaster behavior health, or emergency response to mass ...
Public Health-Graduate-Assistant/Associate Professor in Emergency Planning and Disaster Management (
Winston Salem, NC · On-site
$100 - $125/hr
Evidence of scholarly productivity or clear potential for developing an active research program ... risk communication, vulnerable populations, disaster behavior health, or emergency response to mass ...
$40 - $45/hr
... research, documentation review, workshop support and the development of client work products. Job ... Supports requirements gathering and documentation for business continuity, disaster recovery ...
$40 - $45/hr
... research, documentation review, workshop support and the development of client work products. Job ... Supports requirements gathering and documentation for business continuity, disaster recovery ...
Public Health-Graduate-Assistant/Associate Professor in Emergency Planning and Disaster Management (
Winston Salem, NC · On-site
Evidence of scholarly productivity or clear potential for developing an active research program ... emergencies, risk communication, vulnerable populations, disaster behavior health, or emergency ...
Public Health-Graduate-Assistant/Associate Professor in Emergency Planning and Disaster Management (
Winston Salem, NC · On-site
Evidence of scholarly productivity or clear potential for developing an active research program ... emergencies, risk communication, vulnerable populations, disaster behavior health, or emergency ...
Advisory Intern, Risk, Resilience - Summer 2027 (New York)
Manhattan, NY · On-site
$40 - $45/hr
... research, documentation review, workshop support and the development of client work products. Job ... Supports requirements gathering and documentation for business continuity, disaster recovery ...
Advisory Intern, Risk, Resilience - Summer 2027 (New York)
Manhattan, NY · On-site
$40 - $45/hr
... research, documentation review, workshop support and the development of client work products. Job ... Supports requirements gathering and documentation for business continuity, disaster recovery ...
Advisory Intern, Risk, Resilience - Summer 2027 (New York)
Manhattan, NY · On-site
$40 - $45/hr
... research, documentation review, workshop support and the development of client work products. Job ... Supports requirements gathering and documentation for business continuity, disaster recovery ...
Advisory Intern, Risk, Resilience - Summer 2027 (New York)
Manhattan, NY · On-site
$40 - $45/hr
... research, documentation review, workshop support and the development of client work products. Job ... Supports requirements gathering and documentation for business continuity, disaster recovery ...
Insurance & Risk Analyst
Mooresville, NC · On-site
Research, analyze, and prepare supporting materials for insurance underwriting meetings and renewal ... and providing disaster relief to communities in need. For more information, visit Lowes.com
Insurance & Risk Analyst
Mooresville, NC · On-site
Research, analyze, and prepare supporting materials for insurance underwriting meetings and renewal ... and providing disaster relief to communities in need. For more information, visit Lowes.com
Insurance & Risk Analyst
Mooresville, NC · On-site
Research, analyze, and prepare supporting materials for insurance underwriting meetings and renewal ... and providing disaster relief to communities in need. For more information, visit Lowes.com
Insurance & Risk Analyst
Mooresville, NC · On-site
Research, analyze, and prepare supporting materials for insurance underwriting meetings and renewal ... and providing disaster relief to communities in need. For more information, visit Lowes.com
Research regulatory updates and communicate changes to management and business units. * Assist with ... Support business continuity and disaster recovery planning efforts. * Participate in vendor ...
Research regulatory updates and communicate changes to management and business units. * Assist with ... Support business continuity and disaster recovery planning efforts. * Participate in vendor ...
Manager - IT Disaster Recovery
$85K - $104K/yr
... risk analyses and business impact analysis * Local and wide area networking concepts, principles ... Familiarity with AI assisted research, summarization, and content generation * Understanding of ...
Manager - IT Disaster Recovery
$85K - $104K/yr
... risk analyses and business impact analysis * Local and wide area networking concepts, principles ... Familiarity with AI assisted research, summarization, and content generation * Understanding of ...
Advisory Intern, Risk, Resilience - Summer 2027 (New York)
Manhattan, NY · On-site
$40 - $45/hr
Supports requirements gathering and documentation for business continuity, disaster recovery ... Compiles program metrics and performs basic research or analysis using documented procedures ...
Advisory Intern, Risk, Resilience - Summer 2027 (New York)
Manhattan, NY · On-site
$40 - $45/hr
Supports requirements gathering and documentation for business continuity, disaster recovery ... Compiles program metrics and performs basic research or analysis using documented procedures ...
Advisory Intern, Risk, Resilience - Summer 2027 (New York)
Manhattan, NY · On-site
$40 - $45/hr
Supports requirements gathering and documentation for business continuity, disaster recovery ... Compiles program metrics and performs basic research or analysis using documented procedures ...
Advisory Intern, Risk, Resilience - Summer 2027 (New York)
Manhattan, NY · On-site
$40 - $45/hr
Supports requirements gathering and documentation for business continuity, disaster recovery ... Compiles program metrics and performs basic research or analysis using documented procedures ...
Disaster Risk Researcher information
See salary details
$30K - $42.2K
4% of jobs
$42.2K - $54.5K
3% of jobs
$54.5K - $66.7K
18% of jobs
$67K is the 25th percentile. Wages below this are outliers.
$66.7K - $78.9K
9% of jobs
$78.9K - $91.1K
8% of jobs
$91.1K - $103.4K
3% of jobs
$103.4K - $115.6K
3% of jobs
The median wage is $120.2K / yr.
$115.6K - $127.8K
4% of jobs
$127.8K - $140K
3% of jobs
$140K - $152.3K
3% of jobs
$157.1K is the 75th percentile. Wages above this are outliers.
$152.3K - $164.5K
41% of jobs
$30K
$113.1K
$164.5K
How much do disaster risk researcher jobs pay per year?
What does a disaster risk researcher do?
What are the key skills and qualifications needed to thrive as a disaster risk researcher, and why are they important?
What are some common challenges disaster risk researchers face when collecting and analyzing field data?
What cities are hiring for Disaster Risk Researcher jobs?
Cities with the most Disaster Risk Researcher job openings:
What states have the most Disaster Risk Researcher jobs?
States with the most job openings for Disaster Risk Researcher jobs include:
What are popular job titles related to Disaster Risk Researcher jobs?
For Disaster Risk Researcher jobs, the most frequently searched job titles are:
Director of Cybersecurity Governance, Risk and Compliance
Austin, TX • On-site
Full-time
Posted 8 days ago
University Of Texas at Austin rating
8.3
Based on 64 frontline employees who took The Breakroom Quiz
128th of 631 rated colleges and universities
Job description
Director of Cybersecurity Governance, Risk and Compliance
----
Hiring Department:
Dell Medical School
----
Position Open To:
All Applicants
----
Weekly Scheduled Hours:
40
----
FLSA Status:
Exempt from FLSA
----
Earliest Start Date:
Immediately
----
Position Duration:
Expected to Continue
----
Location:
UT MAIN CAMPUS
----
Job Details:
General Notes
The Director of Cybersecurity Governance, Risk and Compliance leads the information security Governance, Risk and Compliance (GRC) program for UT Medicine and Dell Medical School. Reporting to the Deputy CISO, this role builds and operates a mature GRC function that enables the organization to assess, manage, and mitigate cybersecurity risk across a clinical, academic, and research environment on a path toward full hospital operations in 2030.
Dell Medical School operates within UT Austin's established enterprise security program, inheriting a baseline of policies, procedures, and tooling. This allows Dell Medical School's cybersecurity governance program to focus on areas of risk specific to its clinical and research mission. Rather than rebuilding foundational controls, this role concentrates on assessing risk and developing security policies, standards, and procedures specific to healthcare delivery, clinical research, and regulatory compliance.
Beyond GRC, this role owns Dell Medical School's incident response coordination capability for events that exceed UT Austin's initial response scope, including driving communication, escalation, and decision-making across clinical and business stakeholders through resolution. This includes maintaining business continuity and disaster recovery plans for clinical and business systems where Dell Medical School bears primary responsibility.
Purpose
The Director of Cybersecurity Governance, Risk and Compliance provides strategic leadership for Dell Medical School's information security governance, risk management, and compliance program. This position develops and executes GRC strategy, evaluates cybersecurity risk, establishes healthcare- and research-specific security governance, oversees regulatory compliance, and provides executive-level reporting on organizational risk posture and program maturity.
Operating within UT Austin's federated security environment, the Director partners with technology, clinical, research, legal, privacy, audit, and compliance stakeholders to manage cybersecurity risk while supporting Dell Medical School's continued growth toward full hospital operations. The role also provides leadership for third-party risk management, incident response coordination, business continuity and disaster recovery, research security governance, and application security governance.
Responsibilities
GRC Program Leadership and Strategy
- Develop and execute the Dell Medical School GRC strategy aligned with organizational objectives, regulatory requirements, and the 2030 hospital opening.
- Build and lead a team of GRC analysts and security compliance professionals, providing ongoing coaching and career development.
- Deliver executive-level reporting on risk posture, compliance status, and program maturity to the Deputy CISO and governance bodies.
- Develop a GRC metrics and KPI framework measuring program effectiveness, employee compliance behavior, and security posture improvement over time.
- Evaluate cybersecurity insurance options and risk-transfer mechanisms as part of the organization's residual risk strategy.
- Coordinate with internal audit, legal, privacy, and enterprise compliance to align governance activities and manage risk consistently across organizational units.
Risk Assessment and Security Posture
- Lead the annual HIPAA Security Risk Analysis and coordinate remediation planning with technology and operational leaders.
- Conduct security risk assessments of infrastructure solutions and clinical platforms to evaluate control adequacy and identify gaps.
- Maintain a risk register and hold technology and operational leaders accountable to remediation timelines across the clinical, academic, research, and administrative technology portfolio.
- Perform business impact analysis to evaluate the effect of cybersecurity risks on critical clinical operations and business functions.
- Evaluate the cost-effectiveness of security controls through structured cost-benefit analysis to optimize risk reduction relative to available resources.
- Conduct cyber risk trend analysis and reporting to identify emerging threats and inform remediation priorities.
- Execute security authorization reviews for new system acquisitions and major system changes, with authority to withhold security authorization until risks are reduced to acceptable thresholds.
Governance, Policy and Compliance
- Author and maintain Dell Medical School cybersecurity policies, including policies that are more stringent than UT Austin baseline requirements where HIPAA, clinical operations, or research compliance demands.
- Ensure Dell Medical School security policies comply with applicable federal and state regulations and operate within the UT Austin enterprise security charter.
- Leverage applicable UT Austin security standards and guidelines and develop Dell Medical School-specific standards for clinical, biomedical, and clinical trial environments.
- Retain ownership of Dell Medical School security processes and procedures across operational domains.
- Identify top human cybersecurity risks and design behavioral mitigation campaigns targeting clinical, research, and administrative staff populations.
- Design and deliver a security awareness program using adult learning principles and maintain metrics to measure employee behavior change and program effectiveness.
- Respond to regulatory inquiries and support external audit engagements in coordination with Legal and Privacy while maintaining comprehensive compliance documentation.
Third-Party and Vendor Risk Management
- Develop and operate a vendor security assessment program covering new software acquisitions, SaaS platforms, and technology service providers.
- Review Business Associate Agreements and technology contracts for security requirements and appropriate data-handling provisions.
- Evaluate proposed vendor solutions through review of SOC 2 reports, penetration test results, and security questionnaire responses.
- Develop and maintain vendor security onboarding procedures, including risk tiering and baseline assessment requirements for new technology partners.
- Build escalation and communication plans for third-party risk events and develop remediation action plans when deficiencies are identified.
- Approve vendor onboarding based on security assessment outcomes in coordination with Procurement and Legal and withhold approval when security requirements are not met.
Incident Response and Business Continuity
- Own and maintain Dell Medical School's incident response capability for events requiring a response beyond UT Austin's initial handling scope.
- Develop business continuity and disaster recovery plans for clinical and business systems where Dell Medical School bears primary responsibility.
- Design tabletop exercise scenarios and coordinate preparedness exercises with internal teams and UT Austin campus security operations.
- Define escalation paths, communication protocols, and recovery playbooks for security events affecting clinical and business systems.
- Coordinate with legal, privacy, and communications teams to incorporate regulatory notification obligations and crisis communication requirements into response plans.
Research and Application Security Governance
- Establish and maintain cybersecurity governance requirements for research computing environments involving Controlled Unclassified Information (CUI), Protected Health Information (PHI), and export-controlled information.
- Define application security standards and secure coding requirements integrated throughout the software development and integration lifecycle.
- Oversee security testing activities, including static analysis and vulnerability scanning for internally developed and integrated applications.
- Facilitate threat modeling for new applications and services to identify and address security design risks before deployment.
- Develop and maintain cloud security governance policies covering SaaS platform adoption and cloud-hosted infrastructure.
Marginal or Periodic Functions
- Represent the organization at cybersecurity and healthcare security conferences and industry forums.
- Participate in enterprise risk committees and strategic planning sessions.
- Maintain awareness of industry trends, emerging threats, and regulatory developments to continuously improve the GRC program.
- Perform related duties as required.
Knowledge, Skills, and Abilities
Strategic Risk Thinking
- Translate complex regulatory requirements and threat landscapes into actionable risk management strategies.
- Develop GRC frameworks aligned with the mission of a clinical, academic, and research enterprise.
- Evaluate and prioritize security investments based on risk reduction, compliance impact, and business value.
- Adapt governance strategies to an evolving environment, including cloud adoption, biomedical expansion, and the 2030 hospital opening.
- Apply quantitative and qualitative approaches to risk measurement, business impact analysis, and executive reporting.
- Evaluate cybersecurity insurance and risk transfer as components of a mature residual risk program.
Decision Quality
- Make sound decisions grounded in risk analysis, regulatory context, and operational judgment.
- Apply cost-benefit analysis principles to security control selection and resource prioritization.
- Oversee vendor relationships and contracts to protect organizational data and systems.
- Collaborate across IT and clinical teams to align governance decisions with operational priorities.
- Balance regulatory rigor with operational practicality when developing policies and controls.
Managing Vision and Purpose
- Communicate the value of the GRC program clearly to audiences ranging from clinical staff to executive leadership.
- Align cybersecurity governance with organizational mission and compliance objectives.
- Influence leaders and stakeholders to secure commitment to security and compliance programs.
- Drive behavioral change through targeted awareness campaigns for diverse clinical and administrative populations.
- Foster shared accountability for information security across the organization.
Building Effective Teams
- Define team structures for the GRC function as the organization grows toward the 2030 hospital opening.
- Develop security professionals through coaching, mentoring, and professional development opportunities.
- Coordinate cross-functional activities with HR, risk management, legal, and compliance to support integrated governance.
- Promote accountability, transparency, and continuous improvement across the security governance function.
Technical and Regulatory Learning
- Maintain current knowledge of the HIPAA Security Rule, NIST CSF, NIST 800-171, and emerging healthcare security regulations.
- Apply understanding of Epic EHR security architecture to access governance and configuration risk assessments.
- Maintain knowledge of CMMC requirements as they apply to research activities at an academic medical center.
- Maintain working knowledge of NIST CSF, ISO 27001, MITRE ATT&CK, and COBIT as applied to healthcare and academic environments.
- Understand the UT Austin federated security governance model and maintain collaborative relationships with the UT Austin Information Security Office.
- Understand cloud security architecture principles, including shared responsibility models for SaaS and IaaS environments.
Required Qualifications
- Master's degree in Information Technology, Cybersecurity, Health Informatics, or a related field.
- Minimum of five years of experience in progressive leadership roles in information security governance or Governance, Risk and Compliance (GRC).
- Minimum of eight years of experience in healthcare, banking, defense, or other high-security environments.
Preferred Qualifications
- Demonstrated experience conducting HIPAA Security Risk Analyses in a covered entity or business associate environment.
- Experience with CMMC or NIST 800-171 compliance programs in an academic or research setting.
- Experience managing third-party cybersecurity risk programs in a highly regulated environment.
- Experience designing cybersecurity awareness programs using behavior-based learning approaches.
Licenses/Registrations/Certifications
Required
- CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager).
Preferred
- HCISPP (Healthcare Information Security and Privacy Practitioner).
- CRISC (Certified in Risk and Information Systems Control).
- CISA (Certified Information Systems Auditor).
- Healthcare-specific GRC certifications.
Salary Range
$170,368+ depending on qualifications
Working Conditions
- Standard office environment and equipment.
- Repetitive use of a keyboard and computer.
- Standard exposure risk associated with a clinical and academic environment.
What University Of Texas at Austin employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About University Of Texas
Sourced by ZipRecruiter
Industry
Education and retail
Company size
10,000+ Employees
Headquarters location
Austin, TX, US