Overview
Skills
Job Details
Role: Senior Risk Management Specialist
Expected Duration: 22 Months
Location: Austin, TX (Hybrid. Candidate must be local to Austin, TX)
Summary:
The client is looking for Risk Management Specialist with experience in information security or cyber risk to lead the design, implementation, and optimization of enterprise and third-party risk management programs.
Responsibilities include (but are not limited to):
Evaluate, implement, and enhance enterprise and third-party risk management programs to align with organizational goals and standards.
Configure risk tools, integrate with existing systems, and apply governance standards including TAC 202, TX-RAMP, and TCF.
Prepare reports, define metrics, and communicate risk reduction strategies to assess and improve program effectiveness.
Minimum Candidate Characteristics:
6+ years of experience designing and deploying security platforms, analytics, and risk programs across federated governance environments.
Skilled in coordinating interagency efforts and program reviews across diverse operational settings.
Experience simplifying regulatory requirements and risk strategies for executive audiences and converting mandates (e.g., TAC 202, TX-RAMP) into actionable assessments.
Exceptional Candidate Characteristics
Experience with one or more Texas State Agencies
Responsibilities:
Perform advanced (senior-level) risk management work. Works under minimal supervision, with extensive latitude for the use of initiative and independent judgement. Resources at this level may independently perform the most complex risk management work and may:
Evaluate and optimize risk prevention, reduction, retention, transfer, and control measures through program reviews and coordinated interagency risk management programs to ensure alignment with organizational goals.
Lead in implementation and configuration of information security risk platform, integration with existing platforms, development of reporting and analytics capabilities, and alignment with governance standards and frameworks.
Directly support the design, development, and evaluation of enterprise risk management and third-party risk programs and guidelines.
Adapt Texas specific controls and frameworks (TCF, TAC 202, and TXRAMP) into standardized, established risk assessment ranking and prioritization rubrics.
Apply expertise in information security risk reduction, measurement, and communication in support of procedures and milestones to measure the effectiveness and performance of risk management programs.
Prepare technical and comprehensive reports, plans, and procedures for developing risk management programs, reviews, and inspections.
Other Requirements:
The individual s experience must be related to information security or cyber risk. We are not considering individuals with experience mostly or wholly in physical security.
Required Skills:
6 Years of Required Proven track record of leading advanced risk management initiatives by designing and deploying integrated security platforms and analytics solutions
6 Years of Required Demonstrated ability to orchestrate cross-functional program reviews and interagency collaboration across diverse operational environments
6 Years of Required Demonstrated ability to translate complex risk management concepts, strategies, and methods into understandable formats for diverse audiences including executive leadership
6 Years of Required Experience in developing and refining information security risk management programs in a federated governance environment
6 Years of Required Expertise in translating complex state specific information security frameworks and regulatory mandates (e.g. TCF, TAC 202, TEXRAMP) into actionable prioritized risk assessment methodologies.
Preferred Skills:
8 Years of Preferred Exceptional writing and communication skills producing through clear risk management documentation that supports strategic decision making
8 Years of Preferred Hands on experience in configuring and operationalizing risk management tools and platforms. Ensuring seamless integration with legacy platforms and processes