Develop and execute the organizationâ™s GRC strategy, ensuring alignment with the organization goals and regulatory requirements.
Manage and mentor GRC team member(s) and/or internship, fostering collaboration, professional growth and performance culture.
Build and maintain strong relationships between the organization and internal/external parties, including, but not limited to, auditors, sponsors, and other 8UChicago organizations on topics related to information security and GRC.
Collaborate with business teams to review and update processes for reviewing contract terms and data protection agreements across the Center, ensuring alignment with NIST 800-53, Rev. 5, and/or other applicable standards.
Lead implementation and maintenance of all required documents related to authorizations to use and/or operate information systems compliant with FedRAMP, FISMA, CMMC, and/or any other relevant compliance and authorization frameworks, including, but not necessarily limited to, System Security Plans, Plans of Action and Milestones, policies and procedures, etc.
Drive and participate in continuous improvement of risk management processes including quantitative analysis and adapting to new methodologies and use cases as needed.
Serve as or delegate role of compliance lead for multiple annual internal and external assessments against frameworks such as FISMA, FedRAMP, and CMMC.
Coordinate cross-functional efforts to address and resolve audit findings, ensuring compliance with timelines and risk mitigation priorities.
Lead the security awareness program, developing and delivering training in coordination with other CTDS information security professionals, emerging trends and best practices, and the requirements of CTDS information technology and subject matter experts.
Lead regular review of procedures and process to ensure alignment with operational requirements and information security and compliance controls, including gathering information from CTDS personnel and developing new procedures and processes as needed.
Support the Security Operations team in managing security events and incidents, producing reports, and following communication.
Conduct third-party risk assessments, ensuring compliance with University, departmental, and regulatory requirements.
Lead initiatives to enhance control maturity and improve compliance processes by updating existing and implementing new solutions.
Develop and maintain dashboards and reports to communicate the status and maturity of GRC activities.
Uses depth and breadth of IT expertise to develop and implement security and compliance policies, guidelines, and safe practices for university-wide computing and networking systems.
Leads teams to conduct in-depth information technology risk assessments; makes recommendations and designs improvements to IT security procedures.
Solves complex problems relating to user security needs and supports the implementation of procedures to accommodate them. Ensures that user community understands and adheres to necessary procedures to maintain security.
Performs other related work as needed.
Preferred Qualifications
Experience:
7+ years business/technical/information security/risk compliance.
Information security risk analysis, auditing, compliance, policies, and overall governance and communication.
Demonstrated success implementing and Information Security control frameworks and standards such as ITIL, CIS Top 20, Soc2, GDPR, NIST CSF / 800-53, FISMA, and FedRAMP.
Strong knowledge of audit and risk management methodologies, such as COBIT, NIST 800-37/800-30, 800-171, FAIR.
Experience with implementing, maintaining, and enhancing use of GRC, IAM, and risk management tools and solutions.
Experience with information security and GRC matters related to bioinformatics and other computing and data sharing environments related to human subject data like NCI Genomic Data Commons and Gen3.
Licenses and Certifications:
CISA, CRISC, GIAC, CISM, or CISSP Certifications highly preferred.
Preferred Competencies
Knowledge of hybrid IT systems, networking, and cloud environments (AWS, Google, etc.).
Ability to respond to changing priorities and operate effectively in a dynamic demand-based environment, requiring extreme flexibility and responsiveness.
Ability to weigh Center, partner, and agency needs against security and risk tolerance.
Ability to conceptualize a course of action and to organize for the successful completion of that action are critical, often under tight deadlines.
Ability to present information in a consistent and concise manner.
Strong written and verbal communication skills and ability to foster collaborative working relationships.
Knowledge of data and privacy risks and concerns related to emerging ML/AI technologies.
Working Conditions
Hybrid.
Office environment.
1-2 days per week in office.
Application Documents
Resume (required)
Cover Letter (preferred)
The University of Chicago is an Affirmative Action/Equal Opportunity/Disabled/Veterans Employer and does not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national or ethnic origin, age, status as an individual with a disability, protected veteran status, genetic information, or other protected classes under the law. For additional information please see the University's Notice of Nondiscrimination.
Staff Job seekers in need of a reasonable accommodation to complete the application process should call 773-702-5800 or submit a request via the Applicant Inquiry Form.
The University of Chicago's Annual Security & Fire Safety Report (Report) provides information about University offices and programs that provide safety support, crime and fire statistics, emergency response and communications plans, and other policies and information. The Report can be accessed online at: securityreport.uchicago.edu. Paper copies of the Report are available, upon request, from the University of Chicago Police Department, 850 E. 61st Street, Chicago, IL 60637.
One of the world's premier academic and research institutions, the University of Chicago has driven new ways of thinking since our 1890 founding. Today, UChicago is an intellectual destination that draws inspired scholars to our Hyde Park and international campuses, keeping UChicago at the nexus of ideas that challenge and change the world.