Data Privacy and Compliance Analyst (Experienced) - ICD - Open Rank (Hybrid)

Atlanta, GA

Georgia Tech Research Institute

View all jobs at Georgia Tech Research Institute

Apply now Apply later

Overview:

The Georgia Tech Research Institute (GTRI) is the nonprofit, applied research division of the Georgia Institute of Technology (Georgia Tech). Founded in 1934 as the Engineering Experiment Station, GTRI has grown to more than 2,900 employees, supporting eight laboratories in over 20 locations around the country and performing more than $940 million of problem-solving research annually for government and industry. GTRI's renowned researchers combine science, engineering, economics, policy, and technical expertise to solve complex problems for the U.S. federal government, state, and industry.   

Georgia Tech's Mission and Values

Georgia Tech's mission is to develop leaders who advance technology and improve the human condition. The Institute has nine key values that are foundational to everything we do: 

1. Students are our top priority.
2. We strive for excellence.
3. We thrive on diversity.
4. We celebrate collaboration.
5. We champion innovation.
6. We safeguard freedom of inquiry and expression.
7. We nurture the wellbeing of our community.
8. We act ethically.
9. We are responsible stewards.

Over the next decade, Georgia Tech will become an example of inclusive innovation, a leading technological research university of unmatched scale, relentlessly committed to serving the public good; breaking new ground in addressing the biggest local, national, and global challenges and opportunities of our time; making technology broadly accessible; and developing exceptional, principled leaders from all backgrounds ready to produce novel ideas and create solutions with real human impact.

Location

Atlanta, GA

Project/Unit Description

As part of the Information and Cybersecurity Department (ICD), the Senior Laboratory Cybersecurity Ambassador (LCA) will perform as a senior cyber audit and compliance specialist responsible for managing and driving efficiencies across the Security Regulatory Compliance programs at the laboratory (lab) level, including DFARS 7012, CMMC, based on NIST frameworks such as SP 800-171 and SP 800-53. Foster a security controls culture to reduce overall cyber risk to GTRI, ensuring control owners understand and are held accountable to operating required controls. Build strong partnerships across the lab, IT, cyber and leadership and influence others in order to mature the program and maintain regulatory compliance, while minimizing stakeholder impact. The ideal candidate for this role is able to provide leadership and mentoring to the team while also being able to participate in technical audit and compliance activities as needed. They also have both technical expertise and experience, as well as communication and leadership skills to influence and seamlessly collaborate across multiple stakeholder groups. This role reports to the ICD. This position has been designated as hybrid and work will be performed within Eastern Time (ET) Zone in Atlanta, GA.

Job Purpose

The Data Privacy and Compliance Analyst is responsible for assessing business policies, procedures, and operations to ensure the organization meets privacy requirements and government regulations for the protection of sensitive information. Privacy and Compliance Analysts manage the legal and operational risks related to sensitive and critical information assets, continuously assess business unit operations, and develop policies, procedures and user training necessary to meet or exceed privacy requirements.

Key Responsibilities

  • Assists with difficult cybersecurity questions and requests from GTRI customers.
  • Direct sponsor engagement as required to review current and planned requirements for secure infrastructures that require compliance.
  • Guide requirements gathering and analysis.
  • Leads validation of security control configuration on systems, ensure all systems are configured to necessary controls, such as NIST, DFARS 252.204-7012, CMMC, and other similar requirements.
  • Articulates privacy requirements into product life-cycle including definition, requirements analysis, synthesis, cyber engineering analysis and implementation.
  • Conducts privacy impact analyses and identify areas needing improvement and recommend necessary enhancements to achieve privacy goals.
  • Reviews modifications to critical information systems and directs implementation of configuration changes.
  • Mentors lower-level cybersecurity and IT professionals across the enterprise.

Required Minimum Qualifications

  • Experience in cyber-Governance, Risk, and Compliance (GRC).
  • Experience in a cyber assessment or inspection related role, ideally with experience in cybersecurity incident response.
  • Solid technical understanding of cybersecurity concepts, standards, guidelines, and principles.
  • Experience with industry-recognized security compliance frameworks (NIST, PCI-DSS, HIPAA, etc.).
  • Experience with data aggregation/analytics and/or SIEM tools.
  • Experience with Endpoint Detection and Response (EDR) solutions.
  • Experience with Vulnerability Management tools.
  • Ability to handle time-sensitive situations with a calm and professional attitude while maintaining an appropriate sense of urgency.
  • Ability to work at a technical level to assessments of IT environments, capable of identifying vectors of threats, vulnerabilities, and areas on non-compliance.
  • Ability to communicate and present at various levels of technical detail depending on audience, ranging from cybersecurity deep dives to non-technical stakeholders.
  • Effective project management and organizational skills, including managing multiple, concurrent tasks and meeting deadlines.
  • Excellent interpersonal skills and ability to create collaborative relationships with colleagues across various groups and levels, and influence without authority.
  • Demonstrates leadership skills with ability to communicate effectively and work independently, both as part of and leading a team.
  • Ability to mentor team members at all levels, develop training plans, and foster personal and professional growth within the team.
  • CompTIA Advanced Security Practitioner (CASP), Certification Authorization Professional (CAP), GIAC Security Leadership Certificate (GSLC), Health Care Information Security and Privacy Practitioner (HCISPP), or equivalent certification.

Preferred Qualifications

  • Active Secret Clearance.
  • Master’s degree in cybersecurity, information technology, engineering, or a related field.
  • Experience as an incident manager, commander, or leader.
  • 10+ years of progressive work-related experience in information security, public accounting or internal audit, with a focus on IT controls audits and assessments and/or controls readiness assessments.
  • Excellent knowledge of technology infrastructure environments including Windows, Mac, Linux, virtual, and cloud.
  • Experience in an incident response-related role, or a participant in an incident response team.
  • Experience with the following cybersecurity tools: Splunk, CrowdStrike, Tenable.io, Axonious.
  • Detail oriented; Exceptional oral and written communication and presentation skills.
  • Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM) or equivalent certification.

Travel Requirements

<10% travel

Education and Length of Experience

Levels 4+5

This position vacancy is an open-rank announcement. The final job offer will be dependent on candidate qualifications in alignment with Research Faculty Extension Professional ranks as outlined in section 3.2.1 of the Georgia Tech Faculty Handbook

  • 9 years of related experience with a Bachelor’s degree in Cybersecurity, Information Security, Information Assurance, Cybersecurity Engineering, Computer Science, or related field.
  • 7 years of related experience with a Masters’ degree in Cybersecurity, Information Security, Information Assurance, Cybersecurity Engineering, Computer Science, or related field.
  • 4 years of related experience with a Ph.D. in Cybersecurity, Information Security, Information Assurance, Cybersecurity Engineering, Computer Science, or related field.

U.S. Citizenship Requirements

Due to our research contracts with the U.S. federal government, candidates for this position must be U.S. Citizens.

Clearance Type Required

Candidates must be able to obtain and maintain an active security clearance.

Benefits at GTRI

Comprehensive information on currently offered GTRI benefits, including Health & Welfare, Retirement Plans, Tuition Reimbursement, Time Off, and Professional Development, can be found through this link: https://benefits.hr.gatech.edu/.

Equal Employment Opportunity

The Georgia Institute of Technology (Georgia Tech) is an Equal Employment Opportunity Employer. The University is committed to maintaining a fair and respectful environment for all. To that end, and in accordance with federal and state law, Board of Regents policy, and University policy, Georgia Tech provides equal opportunity to all faculty, staff, students, and all other members of the Georgia Tech community, including applicants for admission and/or employment, contractors, volunteers, and participants in institutional programs, activities, or services.  Georgia Tech complies with all applicable laws and regulations governing equal opportunity in the workplace and in educational activities.

Georgia Tech prohibits discrimination, including discriminatory harassment, on the basis of race, ethnicity, ancestry, color, religion, sex (including pregnancy), sexual orientation, gender identity, gender expression, national origin, age, disability, genetics, or veteran status in its programs, activities, employment, and admissions.  This prohibition applies to faculty, staff, students, and all other members of the Georgia Tech community, including affiliates, invitees, and guests. Further, Georgia Tech prohibits citizenship status, immigration status, and national origin discrimination in hiring, firing, and recruitment, except where such restrictions are required in order to comply with law, regulation, executive order, or Attorney General directive, or where they are required by Federal, State, or local government contract.

USG Core Values Statement

The University System of Georgia is comprised of our 26 institutions of higher education and learning as well as the System Office. Our USG Statement of Core Values are Integrity, Excellence, Accountability, and Respect. These values serve as the foundation for all that we do as an organization, and each USG community member is responsible for demonstrating and upholding these standards. More details on the USG Statement of Core Values and Code of Conduct are available in USG Board Policy 8.2.18.1.2 and can be found on-line at https://www.usg.edu/policymanual/section8/C224/#p8.2.18_personnel_conduct.

Additionally, USG supports Freedom of Expression as stated in Board Policy 6.5 Freedom of Expression and Academic Freedom found on-line at https://www.usg.edu/policymanual/section6/C2653.

 

Apply now Apply later
  • Share this job via
  • 𝕏
  • or

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: Analytics Audits CASP+ CISA CISM CISSP Clearance Cloud CMMC Compliance CompTIA Computer Science CrowdStrike DFARS EDR GIAC Governance GSLC HIPAA Incident response Linux NIST NIST 800-53 NIST Frameworks Nonprofit Privacy Security Clearance SIEM Splunk Vulnerabilities Vulnerability management Windows

Perks/benefits: Career development Health care

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.