Information Security Analyst Sr

Travis County
  • Austin, TX
  • Remote
  • $86,403.20–$120,000 Per Year
1 day ago

Job Description

Information Security Analyst Sr

Salary

$86,403.20 - $120,000.00 Annually

Location

700 Lavaca Street, Austin, TX

Job Type

Full Time

Remote Employment

Flexible/Hybrid

Job Number

26-10909

Department

Information Security

Opening Date

10/08/2026

Closing Date

10/29/2026 11:59 PM Central

  • Description
  • Benefits
  • Questions

Job Summary

Travis County Technology and Operations is seeking an Information Security Analyst Sr to join the Enterprise Risk Management Division.

Performs advanced information security, compliance, risk management, and audit activities in support of the Countys Information Assurance and cybersecurity programs. Serves as a senior-level subject matter resource for assessing compliance with information security requirements, with significant responsibility for supporting the Countys Criminal Justice Information Services (CJIS) compliance program and evaluating compliance with the FBI CJIS Security Policy.

Plans and conducts technical and administrative security assessments and audits; evaluates security controls; identifies compliance gaps and risks; develops findings and recommendations; and monitors corrective action and remediation activities. Assists County departments with interpreting and implementing applicable security requirements, including CJIS, NIST, HIPAA, County policies, and other regulatory or contractual requirements.

Conducts information technology risk assessments and evaluates administrative, technical, and physical safeguards protecting County systems and information. Reviews system configurations, policies, procedures, documentation, audit records, access controls, security architecture, and supporting evidence to determine whether security controls are appropriately designed, implemented, and operating as intended.

Develops assessment methodologies, audit procedures, control checklists, compliance documentation, risk reports, and executive-level summaries. Collaborates with County departments, Information Technology personnel, information security staff, departmental security representatives, management, vendors, auditors, and external agencies to strengthen security governance and maintain regulatory compliance

This position is eligible for teleworking, in office as needed.

Distinguishing Characteristics:

This is a senior-level information security classification within the Information Technology job family. Incumbents perform complex information security, compliance, audit, and risk management activities requiring advanced knowledge of cybersecurity principles, regulatory requirements, security frameworks, and information technology controls.

The Information Security Analyst Senior exercises considerable independent judgment in planning and conducting security assessments and audits, interpreting security and compliance requirements, evaluating technical and administrative controls, identifying deficiencies and risks, and developing recommendations for corrective action.

The position will serve as a subject matter resource for the Countys Criminal Justice Information Services (CJIS) compliance program and will coordinate compliance and audit activities across multiple County departments that access, process, store, transmit, or support Criminal Justice Information (CJI). Responsibilities may include assessing compliance with the FBI CJIS Security Policy, preparing departments for internal and external audits, documenting findings, monitoring remediation activities, and assisting departments with implementation of required security controls.

This classification may lead projects, mentor or provide technical guidance to other staff, and represent the department in meetings with County departments, auditors, regulatory entities, vendors, and other governmental agencies. This classification may require a flexible work schedule to meet operational or audit requirements.

Duties and Responsibilities

  • Plans, conducts, documents, and reports information security compliance assessments, technical and administrative audits, and risk assessments of County departments, systems, applications, processes, and third-party services.

  • Supports administration of the Countys Criminal Justice Information Services (CJIS) compliance program and evaluates compliance with applicable FBI CJIS Security Policy requirements.

  • Conducts CJIS compliance assessments and internal audits of multiple County departments and systems that access, process, store, transmit, or support Criminal Justice Information (CJI).

  • Develops and maintains audit methodologies, assessment procedures, evidence requirements, control checklists, questionnaires, workpapers, compliance documentation, and other tools necessary to evaluate and demonstrate compliance.

  • Coordinates audit preparation and evidence collection activities with County departments, Information Technology personnel, departmental security representatives, management, vendors, and other stakeholders.

  • Reviews policies, procedures, system configurations, access controls, security documentation, audit logs, network and system architecture, data flows, training records, personnel security documentation, incident response processes, physical safeguards, and other evidence to determine compliance with applicable requirements.

  • Documents audit and assessment findings, identifies control deficiencies and associated risks, develops recommendations for corrective action, and communicates results to technical personnel, departmental management, and executive leadership.

  • Develops, tracks, and monitors corrective action plans, plans of action and milestones (POA&Ms), risk treatment activities, exceptions, and other remediation efforts resulting from security assessments and audits.

  • Performs follow-up assessments to validate that corrective actions have been implemented and identified security deficiencies have been appropriately addressed.

  • Assists County departments with interpreting CJIS Security Policy requirements and translating security requirements into practical administrative, technical, and operational controls.

  • Supports County preparation for external CJIS audits and assessments, including coordinating evidence collection, reviewing documentation, facilitating interviews, responding to audit requests, documenting findings, and monitoring corrective actions.

  • Conducts information technology and cybersecurity risk assessments using qualitative and quantitative methodologies and evaluates risks associated with systems, applications, technology services, vendors, business processes, and security control deficiencies.

  • Evaluates administrative, technical, and physical security controls against applicable laws, regulations, contractual requirements, County policies, and recognized cybersecurity frameworks and standards.

  • Reviews proposed and existing technologies to identify security, privacy, regulatory, and compliance risks and recommends appropriate safeguards and risk treatment measures.

  • Develops and maintains information security policies, standards, procedures, guidelines, assessment methodologies, and supporting documentation based on changes in technology, threats, regulatory requirements, and industry standards.

  • Analyzes changes to the FBI CJIS Security Policy and other applicable cybersecurity requirements and evaluates their impact on County systems, departments, policies, procedures, and security controls.

  • Prepares technical reports, risk assessments, audit reports, compliance reports, dashboards, presentations, executive summaries, and other documentation communicating security risks, findings, remediation status, and compliance posture.

  • Collaborates with information security, Information Technology, privacy, legal, risk management, departmental personnel, and external organizations regarding cybersecurity risk and compliance matters.

  • Provides consultation, guidance, training, and awareness to County departments regarding information security requirements, CJIS compliance responsibilities, security controls, and audit readiness.

  • Participates in security governance, risk management, compliance, incident response, business continuity, and other Information Assurance initiatives as assigned.

  • May lead projects, mentor staff, review work performed by other analysts, and provide technical or compliance guidance to junior staff.

  • Performs other job-related duties as assigned.

Minimum Requirements

Education and Experience:

Bachelors degree in Computer Science, Information Systems, Business Administration or a directly related field AND five (5) years of relevant work experience, including at least three (3) years experience in information security;

OR,

Any combination of education and experience that has been achieved and is equivalent to the stated education and experience and required knowledge, skills, and abilities sufficient to successfully perform the duties and responsibilities of this job.

Licenses, Registrations, Certifications, or Special Requirements:

Valid Texas Drivers License.

Preferred:

Industry-recognized certification such as CompTIA Security+, Certified Information Systems Auditor (CISA), Certified Risk and Information Systems Control (CRISC), or Certified Governance Risk & Compliance (CGRC)

Knowledge, Skills, and Abilities:

Knowledge of:

  • Information security governance, risk management, compliance, and audit principles and practices.
  • FBI Criminal Justice Information Services (CJIS) Security Policy requirements and security controls applicable to systems that access, process, store, or transmit Criminal Justice Information.
  • National Institute of Standards and Technology (NIST) cybersecurity standards and frameworks, including NIST SP 800-53, NIST AI RMF, NIST CSF 2.0, and related security control assessment and risk management concepts.
  • Federal, State, Local and County applicable laws, regulations, policies, standards, and contractual requirements applicable to information security and privacy, including the Health Insurance Portability and Accountability Act (HIPAA).
  • Information security audit methodologies, evidence collection techniques, control testing, sampling, documentation, workpapers, findings development, and corrective action monitoring.
  • Information technology risk assessment and risk management methodologies, including qualitative and quantitative approaches.
  • Security control design, implementation, assessment, monitoring, and remediation.
  • Data protection concepts including encryption, cryptographic controls, data classification, data loss prevention, removable media protection, transmission security, and secure disposal.
  • Third-party and vendor cybersecurity risk management.
  • Cloud computing and Software-as-a-Service security concepts and shared responsibility models.
  • Principles and practices for developing security policies, standards, procedures, guidelines, and technical documentation.
  • Methods for communicating technical, security, risk, and compliance information to technical and non-technical audiences.
  • Computer equipment to include word processing, spreadsheets, databases and a variety of software packages.

Skill in:

  • Conducting information security audits, compliance assessments, security control assessments, and information technology risk assessments.
  • Interpreting and applying cybersecurity frameworks, regulatory requirements, policies, standards, and technical requirements.
  • Evaluating administrative, technical, and physical security controls and determining whether sufficient evidence demonstrates compliance.
  • Identifying control deficiencies, analyzing associated risk, determining root causes, and developing practical recommendations for corrective action.
  • Developing audit workpapers, assessment documentation, findings, risk statements, corrective action plans, and executive-level reports.
  • Collecting, reviewing, analyzing, and documenting technical and administrative evidence.
  • Researching cybersecurity requirements and applying them to complex information technology environments.
  • Managing multiple assessments, audits, findings, and remediation activities simultaneously.
  • Communicating complex technical and regulatory requirements in clear, understandable language to technical and non-technical audiences.
  • Providing consultation, guidance, training, and technical assistance to County departments and stakeholders.
  • Building collaborative working relationships across organizational and departmental boundaries.
  • Problem-solving, critical thinking, analysis, and independent decision-making.
  • Preparing and delivering professional written reports, presentations, briefings, and recommendations.

Ability to:

  • Interpret complex cybersecurity policies, standards, laws, regulations, and contractual requirements and translate them into measurable security controls and operational requirements.
  • Independently plan, organize, conduct, document, and report information security audits, assessments, and risk analyses.
  • Evaluate evidence objectively and determine whether security controls are appropriately designed, implemented, and operating effectively.
  • Identify and clearly articulate security control deficiencies, compliance gaps, risks, and recommended corrective actions.
  • Apply CJIS Security Policy requirements to diverse technical environments, business processes, County departments, and information systems.
  • Communicate audit findings and security risks professionally and effectively.
  • Work collaboratively with technical personnel, departmental leadership, auditors, vendors, legal counsel, risk management personnel, and other governmental entities.
  • Maintain independence, objectivity, confidentiality, and professional judgment when conducting audits and assessments.
  • Manage multiple complex assignments, prioritize competing requirements, meet deadlines, and maintain accurate assessment and compliance documentation.
  • Research, compile, analyze, interpret, and present complex technical and regulatory information.
  • Develop practical recommendations that balance security and compliance requirements with operational and business needs.
  • Provide guidance, mentoring, and technical assistance to other staff.
  • Establish and maintain effective working relationships with County departments, elected and appointed officials, external agencies, vendors, auditors, and other stakeholders.
  • Work independently with limited supervision while contributing effectively as a member of multidisciplinary teams.

Work Environment & Other Information

Work primarily performed in office setting, either on-site or in a secure hybrid/telework environment. May involve occasional visits to data centers, agency offices, or vendor locations for security inspections, audits, or meetings. Must adhere to strict security protocols and procedures, including physical access controls, background checks, and secure area clearances. May occasionally work outside normal business hours to respond to security incidents or meet project deadlines.

Physical requirements include extended periods of sitting, using a computer and other standard office equipment. Subject to visual acuity, speech and hearing, hand and eye coordination and manual dexterity necessary to operate a computer and office equipment. Occasional lifting or carrying of equipment or materials (typically less than 25 pounds) may be required. Must be able to remain focused and alert while working on detailed technical tasks, especially during incident response or time-sensitive audits.

Travis County employees play an important role in business continuity. As such, employees can be assigned to business continuity efforts outside of normal job functions.

Work Hours: 8 am - 5 pm, Monday-Friday. May work some holidays, some nights, some weekends

Location: 700 Lavaca St, Austin, TX 78701

This position is eligible for teleworking, in office as needed.

Department: Information Security

Criminal, Driving, Education, and Employment Background Checks Required.

For updates or questions on this position, contact: Serena.Abshier@traviscountytx.gov

This job description is intended to be generic in nature. It is not necessarily an exhaustive list of all duties and responsibilities. The essential duties, functions and responsibilities and overtime eligibility may vary based on the specific tasks assigned to the position.

Benefits

Employment at Travis County comes with a full array of benefits. We offer comprehensive health insurance, a no-cost, on-site Health and Wellness clinic, longevity pay, paid vacations, sick time and personal holidays, not to mention an industry competitive salary structure and a friendly, stable work environment.

FY2027 Travis County Benefit Guide

In this valuable Travis County Benefits Guide you will find benefit summaries, eligibility requirements, costs, contact numbers and addresses as well as other general information on the benefits available to Travis County Employees and Retirees.

Credit Union

Employees may join the Travis County Credit Union which offers low-interest loans, savings plans through payroll deduction, safe deposit boxes and other benefits.

Deferred Compensation

Employees may enroll in a tax- free sheltered investment plan through payroll deduction.

Direct Deposit

Employees may sign up for direct bank deposit.

Employee Assistance Program

Travis County provides a confidential counseling and referral service free of charge to county employees and their family.

Employee Organizations

Membership in the American Federation of State, County, and Municipal Employees Union is available through payroll deduction.

Employee Health & Wellness Clinic

Employees may access the clinic for a variety of wellness program and health care services with no co-pay, no deductible and no co-insurance costs.

Holidays

An average of eleven paid holidays are designated by the Travis County Commissioners Court at the beginning of each fiscal year.

Insurance

Employees may select from four plans: an Exclusive Physician Organization (EPO), Choice Plus Preferred Physician Organization (PPO), Consumer Choice or a High Deductible Health Plan (HDHP) with a Health Savings Account (HSA). All four options include a Pharmacy Plan. Travis County's current policy is to pay 100% of the employee's health insurance premium for the Consumer Choice and HDHP. Employees will pay a premium for both the EPO and PPO. Other insurance benefits include $50,000 Basic Life and AD&D paid by the County.

The following benefits are employee paid:

  • Dental
  • Vision
  • Supplemental Life, AD&D
  • Dependent Life
  • Short Term Disability
  • Long Term Disability
  • Long Term Care

New employees are covered on the first day of the month following 28 calendar days of employment.

Longevity

Longevity pay is paid for each year completed after three years of continuous service. Peace Officers in a law enforcement activity, whose job requires state peace officer certification, receive pay after one year of certification.

On the regular payday on or after the employees fourth and subsequent adjusted service dates, he or she receives a single payment for the previous year.

Parking

A limited number of assigned parking spaces are available to employees in the Courthouse Complex.

Personal Holidays

Regular, full-time employees are eligible for up to three paid personal holidays each calendar year. Part-time employees shall be granted personal holidays on a prorated basis. New employees earn personal holidays for the calendar year in which he/she begins employment, based on the month in which employment begins:

January - March

3 personal holidays

April - June

2 personal holidays

July - September

1 personal holiday

October - December

None

New employees are eligible to take personal holidays after 90 days of employment.

Retirement

Travis County is a member of the Texas County & District Retirement System with mandatory participation by certain classes of employees. Seven percent (7%) of the gross salary is deducted each pay period. An employee is fully vested after eight years of service. Benefits are prorated for part-time employees.

Sick Leave

Regular employees earn sick leave at a rate of eight hours per month with unlimited accrual during employment. Part-time employees earn sick leave on a pro-rated basis.

Parental Leave

Each Full-time Paid Parental Leave Eligible (PPL) Employee is entitled to a total of 320 hours of Paid Parental Leave in a 12 month period. Paid Parental Leave for Part-time PPL Eligible Employees is prorated based on the number of hours that they are regularly scheduled to work.

Tuition Refund

Certain classes of full-time employees may receive reimbursement for fees associated with pre-approved, job related course work completed satisfactorily.

Vacation

Based on years of county service, regular, full-time employees earn vacation time at the following rates:

0 to 5 years

4.0 hours per pay period

6 to 10 years

4.5 hours per pay period

11 to 15 years

5.0 hours per pay period

16 to 20 years

5.5 hours per pay period

21 plus years

6.0 hours per pay period

Part-time employees earn vacation leave on a pro-rated basis.

Workers Compensation

The county provides all employees workers compensation coverage with benefits in accordance with state statute, if the employee sustains an injury out of, or in the course of work.

01

Do you have an Industry-recognized certification such as CompTIA Security+, Certified Information Systems Auditor (CISA), Certified Risk and Information Systems Control (CRISC), or Certified Governance Risk & Compliance (CGRC)?

  • Yes
  • No

02

Do you have professional experience working with the FBI Criminal Justice Information Services (CJIS) Security Policy or assessing systems or organizations that access, process, store, or transmit Criminal Justice Information (CJI)?

  • Yes
  • No

03

Do you have experience tracking audit findings, corrective action plans, remediation activities, or Plans of Action and Milestones (POA&Ms) through resolution?

  • Yes
  • No

04

Do you currently or will in the next 30 to 60 days reside in the state of Texas?

  • Yes
  • No

Required Question

Employer Travis County

Address 700 Lavaca Street

Austin, Texas, 78701

Website https://www.traviscountytx.gov/human-resources/jobs

Numbers & Facts

LocationAustin, TX (
Remote
)
Salary$86,403.20–$120,000 Per Year

Skills

  • Access Controlunmatched
  • Accidental Death and Dismemberment (AD&D)unmatched
  • Analysis Skillsunmatched
  • Artificial Intelligence (AI)unmatched
  • Auditingunmatched
  • Background Investigationunmatched
  • Business Administrationunmatched
  • Business Processesunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • Cloud Computingunmatched
  • Co-Paymentsunmatched
  • Communication Skillsunmatched
  • CompTIA - Computing Technology Industry Associationunmatched
  • CompTIA Security+unmatched
  • Compensation and Benefitsunmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Computer Softwareunmatched
  • Contract Requirementsunmatched
  • Corrective Actionunmatched
  • Criminal Justiceunmatched
  • Cross-Functionalunmatched
  • Cryptographyunmatched
  • Documentationunmatched
  • Documentation Reviewunmatched
  • Driver's Licenseunmatched
  • Employee Assistance Planunmatched
  • Employee Orientationunmatched
  • Establish Prioritiesunmatched
  • External Auditunmatched
  • Federal Bureau of Investigation (FBI)unmatched
  • HIPAA (Health Insurance Portability and Accountability Act)unmatched
  • Health Planunmatched
  • Healthcareunmatched
  • Incident Responseunmatched
  • Industry Standardsunmatched
  • Information Systems/Technology IS/IT Administrationunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Insuranceunmatched
  • Internal Auditunmatched
  • Internet Securityunmatched
  • Law Enforcementunmatched
  • Leadershipunmatched
  • Legalunmatched
  • Loss Preventionunmatched
  • Maintain Complianceunmatched
  • Manual Dexterityunmatched
  • Mentoringunmatched
  • Network Operations Centerunmatched
  • Office Equipmentunmatched
  • Payroll Taxunmatched
  • People Managementunmatched
  • Pharmacyunmatched
  • Physical Demandsunmatched
  • Physical Securityunmatched
  • Policy Developmentunmatched
  • Preferred Provider Organization (PPO)unmatched
  • Privacy Controlsunmatched
  • Privacy Regulationsunmatched
  • Problem Solving Skillsunmatched
  • Project/Program Coordinationunmatched
  • Quantitative Analysisunmatched
  • Regulationsunmatched
  • Regulatory Complianceunmatched
  • Regulatory Requirementsunmatched
  • Reimbursementunmatched
  • Reporting Dashboardsunmatched
  • Reporting Skillsunmatched
  • Requirements Managementunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Root Cause Analysisunmatched
  • Security Analysisunmatched
  • Security Architectureunmatched
  • Security Auditingunmatched
  • Security Complianceunmatched
  • Security Designunmatched
  • Security Policyunmatched
  • Security Protocolsunmatched
  • Software as a Service (SaaS)unmatched
  • Spreadsheetsunmatched
  • State Laws and Regulationsunmatched
  • Systems Administration/Managementunmatched
  • Systems Analysisunmatched
  • Team Playerunmatched
  • Technical Analysisunmatched
  • Technical Leadershipunmatched
  • Technical Operationsunmatched
  • Technical Presentationunmatched
  • Technical Supportunmatched
  • Technical Writingunmatched
  • Technology Analysisunmatched
  • Time Managementunmatched
  • Transmission Security (TRANSEC)unmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Vendor/Supplier Evaluationunmatched
  • Word Processingunmatched
  • Worker's Compensationunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder