Job Details
Senior IT Governance, Risk, and Compliance (GRC) Analyst
Job ID: 303701
Location: Kennesaw, Georgia
Full/Part Time: Full Time
Regular/Temporary: Regular
About Us
Are you ready to transform lives through academic excellence, innovative research, strong community partnerships and economic opportunity? Kennesaw State University is one of the 50 largest public institutions in the country. With growing enrollment and global reach, we continue to expand our institutional influence and prominence beyond the state of Georgia. We offer more than 190 undergraduate, graduate, and doctoral degrees to empower over 50,000 students to become thought leaders, lifelong learners, and informed global citizens. Our entrepreneurial spirit, high-impact research, and Division I athletics draw students from throughout the region and from more than 100 countries across the globe. Our university's vibrant culture, career opportunities, rich benefits, and values of respect, integrity, collaboration, inclusivity, and accountability make us an employer of choice. We are part of the University System of Georgia. We are searching for talented people to join Kennesaw State University in our vision. Come Take Flight at KSU!
Location
(Primary Location for Job Responsibilities) Our Kennesaw campus is located at 1000 Chastain Road NW, Kennesaw, GA 30144.
Our Marietta campus is located at 1100 South Marietta Parkway, Marietta, GA 30060.
Job Summary
The position leads enterprise cybersecurity governance, risk management, compliance, and third-party risk activities while supporting alignment with institutional, state, and federal requirements. This position serves as a senior subject matter expert, providing strategic guidance, leading complex assessments, and promoting risk-informed decision-making across the university.
Responsibilities
KEY RESPONSIBILITIES:
1. Leads enterprise IT and cybersecurity risk assessments using NIST, CIS, and institutional frameworks, evaluating compensating controls and contextual risk to support informed decision-making.
2. Maintains and enhances the enterprise IT risk register, ensuring accurate risk documentation, ownership assignment, remediation tracking, and risk acceptance processes.
3. Leads third-party vendor risk assessments, analyzing SOC reports, HECVATs, security questionnaires, and supporting documentation to evaluate organizational risk.
4. Coordinates audit readiness activities, evidence collection, stakeholder engagement, response tracking, and remediation efforts related to cybersecurity and regulatory audits.
5. Assesses and validates technical, administrative, and operational controls against GLBA, HIPAA, FERPA, PCI-DSS, NIST, and related compliance requirements.
6. Supports the University's data privacy program, including Records of Processing Activities (RoPA), data privacy consultations and assessments, data privacy requests, privacy risk identification and mitigation, and the development and implementation of data privacy awareness and training initiatives.
7. Develops, reviews, and maintains cybersecurity policies, standards, procedures, and governance documentation to support compliance and operational maturity.
8. Collaborates with internal stakeholders to evaluate, validate, and reassess IT controls, identify control gaps and risks, and support the development and implementation of appropriate remediation strategies.
9. Collaborates with the Office of Research, faculty, and other key stakeholders to support the governance, compliance, risk management, and security and privacy requirements associated with sponsored research, controlled information, and regulated research environments.
10. Partners with business, academic, and technology stakeholders to identify risks, recommend mitigation strategies, and support implementation of corrective actions.
11. Develops metrics, dashboards, and executive reports that communicate cybersecurity risk, compliance status, trends, and program effectiveness to leadership.
Required Qualifications
Educational Requirements
Bachelor's degree from an accredited institution of higher education or an equivalent combination of relevant education and/or experience.
Required Experience
Five (5) years of professional experience supporting governance, risk, compliance, audit, legal, cybersecurity, or related functions and disciplines.
Preferred Qualifications
Additional Preferred Qualifications
Relevant certifications such as CISSP, CISA, CRISC, CGRC, CISM, Security+, or ITIL Foundation
Preferred Educational Qualifications
An advanced degree from an accredited institution of higher education in a related field such as Information Technology, Cybersecurity, Information Systems, Business Administration, or Risk Management
Preferred Experience
Experience in higher education or regulated environments (FERPA, GLBA, HIPAA, PCI-DSS, NIST 800-171, CMMC)
Experience with GRC platforms such as ServiceNow GRC, RSA Archer, OneTrust, Apptega, or similar systems
Knowledge, Skills, & Abilities
ABILITIES
Ability to interpret regulatory, contractual, and institutional compliance requirements
Ability to develop governance documentation, policies, standards, and procedures
Ability to communicate technical and risk-related concepts to technical and non-technical audiences
Ability to prepare executive-level reports, metrics, and recommendations
Strong analytical and problem-solving skills with the ability to evaluate complex risk scenarios
Able to handle multiple tasks or projects at one time, meeting assigned deadlines
KNOWLEDGE
Advanced knowledge of cybersecurity governance, risk management, compliance, and privacy principles and frameworks
Knowledge of cybersecurity frameworks including NIST, RMF, CIS, ISO 27001, and related standards
Knowledge of research security principles and applicable requirements governing federally sponsored research, controlled information, and regulated research environments.
Experience leading IT risk assessments and evaluating compensating controls and contextual risk
Experience with GRC tools, dashboards, and compliance tracking systems
Strong understanding of vendor risk management and third-party security assessment practices
SKILLS
Excellent interpersonal, initiative, teamwork, problem-solving, independent judgment, organization, communication (verbal and written), time management, project management, and presentation skills
Proficient with computer applications and programs associated with the position (i.e., Microsoft Office suite)
Strong attention to detail and follow-up skills
Strong customer service skills and phone and e-mail etiquette
USG Core Values
The University System of Georgia is comprised of our 25 institutions of higher education and learning as well as the System Office. Our USG Statement of Core Values are Integrity, Excellence, Accountability, and Respect. These values serve as the foundation for all that we do as an organization, and each USG community member is responsible for demonstrating and upholding these standards. More details on the USG Statement of Core Values and Code of Conduct are available in USG Board Policy 8.2.18.1.2 and can be found on-line at https://www.usg.edu/policymanual/section8/C224/#p8.2.18_personnel_conduct.
Additionally, USG supports Freedom of Expression as stated in Board Policy 6.5 Freedom of Expression and Academic Freedom found on-line at https://www.usg.edu/policymanual/section6/C2653.
Equal Employment Opportunity
Kennesaw State University is an Equal Employment Opportunity Employer. The University is committed to maintaining a fair and respectful environment for living, work and study. To that end, and in accordance with federal and state law, Board of Regents policy, and University policy, the University prohibits harassment of or discrimination against any person because of race, color, sex (including sexual harassment, pregnancy, and medical conditions related to pregnancy), sexual orientation, gender identity, gender expression, ethnicity or national origin, religion, age, genetic information, disability, or veteran or military status by any member of the KSU Community on campus, in connection with a University program or activity, or in a manner that creates a hostile environment for members of the KSU community.
For additional information on this policy, or to file a complaint under the provisions of this policy, students, employees, applicants for employment or admission or other third parties should contact the Office of Institutional Equity at English Building, Suite 225, eeo@kennesaw.edu.
Other Information
This is not a supervisory position.
This position does not have any financial responsibilities.
This position will not be required to drive.
This role is considered a position of trust.
This position does not require a purchasing card (P-Card).
This position may travel 1% - 24% of the time
This position does not require security clearance.
Background Check
- Standard Enhanced
- Education
Per the University System of Georgia background check policy, all final candidates will be required to consent to a criminal background investigation. Final candidates may be asked to disclose criminal record history during the initial screening process and prior to a conditional offer of employment. Applicants for positions of trust with screening results which confirm a disqualifying criminal history will be immediately disqualified from employment eligibility
All applicants are required to include professional references as part of their application process. Some positions may require additional job-based screenings such as motor vehicle report, credit check, pre-employment drug screening and/or verification of academic credentials.
https://www.usg.edu/hr/assets/hr/hrap_manual/HRAP_Background_Investigation_Employment.pdf
To apply, visit https://careers.hprod.onehcm.usg.edu/psp/careers/CAREERS/HRMS/c/HRS_HRAM_FL.HRS_CG_SEARCH_FL.GBL?Page=HRS_APP_JBPST_FL&Action=U&FOCUS=Applicant&SiteId=43000&JobOpeningId=303701&PostingSeq=1
Copyright 2025 Jobelephant.com Inc. All rights reserved.
Posted by the FREE value-added recruitment advertising agency
je-18c20814396d4a859a18ac364bdd92fc