Job Details
Job Title: Senior IT Governance, Risk, and Compliance (GRC) Analyst
Location: Kennesaw, Georgia
Regular/Temporary: Regular
Full/Part Time: Full-Time
Job ID: 303701
About Us
Are you ready to transform lives through academic excellence, innovative research, strong community partnerships and economic opportunity? Kennesaw State University is one of the 50 largest public institutions in the country. With growing enrollment and global reach, we continue to expand our institutional influence and prominence beyond the state of Georgia. We offer more than 190 undergraduate, graduate, and doctoral degrees to empower over 50,000 students to become thought leaders, lifelong learners, and informed global citizens. Our entrepreneurial spirit, high-impact research, and Division I athletics draw students from throughout the region and from more than 100 countries across the globe. Our university's vibrant culture, career opportunities, rich benefits, and values of respect, integrity, collaboration, inclusivity, and accountability make us an employer of choice. We are part of the University System of Georgia. We are searching for talented people to join Kennesaw State University in our vision. Come Take Flight at KSU!
Location
(Primary Location for Job Responsibilities) Our Kennesaw campus is located at 1000 Chastain Road NW, Kennesaw, GA 30144.
Our Marietta campus is located at 1100 South Marietta Parkway, Marietta, GA 30060.
Job Summary
The position leads enterprise cybersecurity governance, risk management, compliance, and third-party risk activities while supporting alignment with institutional, state, and federal requirements. This position serves as a senior subject matter expert, providing strategic guidance, leading complex assessments, and promoting risk-informed decision-making across the university.
Responsibilities
KEY RESPONSIBILITIES:
- Leads enterprise IT and cybersecurity risk assessments using NIST, CIS, and institutional frameworks, evaluating compensating controls and contextual risk to support informed decision-making.
- Maintains and enhances the enterprise IT risk register, ensuring accurate risk documentation, ownership assignment, remediation tracking, and risk acceptance processes.
- Leads third-party vendor risk assessments, analyzing SOC reports, HECVATs, security questionnaires, and supporting documentation to evaluate organizational risk.
- Coordinates audit readiness activities, evidence collection, stakeholder engagement, response tracking, and remediation efforts related to cybersecurity and regulatory audits.
- Assesses and validates technical, administrative, and operational controls against GLBA, HIPAA, FERPA, PCI-DSS, NIST, and related compliance requirements.
- Supports the University's data privacy program, including Records of Processing Activities (RoPA), data privacy consultations and assessments, data privacy requests, privacy risk identification and mitigation, and the development and implementation of data privacy awareness and training initiatives.
- Develops, reviews, and maintains cybersecurity policies, standards, procedures, and governance documentation to support compliance and operational maturity.
- Collaborates with internal stakeholders to evaluate, validate, and reassess IT controls, identify control gaps and risks, and support the development and implementation of appropriate remediation strategies.
- Collaborates with the Office of Research, faculty, and other key stakeholders to support the governance, compliance, risk management, and security and privacy requirements associated with sponsored research, controlled information, and regulated research environments.
- Partners with business, academic, and technology stakeholders to identify risks, recommend mitigation strategies, and support implementation of corrective actions.
- Develops metrics, dashboards, and executive reports that communicate cybersecurity risk, compliance status, trends, and program effectiveness to leadership.
Required Qualifications
Educational Requirements
Bachelor's degree from an accredited institution of higher education or an equivalent combination of relevant education and/or experience.
Required Experience
Five (5) years of professional experience supporting governance, risk, compliance, audit, legal, cybersecurity, or related functions and disciplines.
Preferred Qualifications
Additional Preferred Qualifications
Relevant certifications such as CISSP, CISA, CRISC, CGRC, CISM, Security+, or ITIL Foundation
Preferred Educational Qualifications
An advanced degree from an accredited institution of higher education in a related field such as Information Technology, Cybersecurity, Information Systems, Business Administration, or Risk Management
Preferred Experience
Experience in higher education or regulated environments (FERPA, GLBA, HIPAA, PCI-DSS, NIST 800-171, CMMC)
Experience with GRC platforms such as ServiceNow GRC, RSA Archer, OneTrust, Apptega, or similar systems
Knowledge, Skills, & Abilities
ABILITIES
Ability to interpret regulatory, contractual, and institutional compliance requirements
Ability to develop governance documentation, policies, standards, and procedures
Ability to communicate technical and risk-related concepts to technical and non-technical audiences
Ability to prepare executive-level reports, metrics, and recommendations
Strong analytical and problem-solving skills with the ability to evaluate complex risk scenarios
Able to handle multiple tasks or projects at one time, meeting assigned deadlines
KNOWLEDGE
Advanced knowledge of cybersecurity governance, risk management, compliance, and privacy principles and frameworks
Knowledge of cybersecurity frameworks including NIST, RMF, CIS, ISO 27001, and related standards
Knowledge of research security principles and applicable requirements governing federally sponsored research, controlled information, and regulated research environments.
Experience leading IT risk assessments and evaluating compensating controls and contextual risk
Experience with GRC tools, dashboards, and compliance tracking systems
Strong understanding of vendor risk management and third-party security assessment practices
SKILLS
Excellent interpersonal, initiative, teamwork, problem-solving, independent judgment, organization, communication (verbal and written), time management, project management, and presentation skills
Proficient with computer applications and programs associated with the position (i.e., Microsoft Office suite)
Strong attention to detail and follow-up skills
Strong customer service skills and phone and e-mail etiquette
USG Core Values
The University System of Georgia is comprised of our 25 institutions of higher education and learning as well as the System Office. Our USG Statement of Core Values are Integrity, Excellence, Accountability, and Respect. These values serve as the foundation for all that we do as an organization, and each USG community member is responsible for demonstrating and upholding these standards. More details on the USG Statement of Core Values and Code of Conduct are available in USG Board Policy 8.2.18.1.2 and can be found on-line at https://www.usg.edu/policymanual/section8/C224/#p8.2.18_personnel_conduct.
Additionally, USG supports Freedom of Expression as stated in Board Policy 6.5 Freedom of Expression and Academic Freedom found on-line at https://www.usg.edu/policymanual/section6/C2653.
Equal Employment Opportunity
Kennesaw State University is an Equal Employment Opportunity Employer. The University is committed to maintaining a fair and respectful environment for living, work and study. To that end, and in accordance with federal and state law, Board of Regents policy, and University policy, the University prohibits harassment of or discrimination against any person because of race, color, sex (including sexual harassment, pregnancy, and medical conditions related to pregnancy), sexual orientation, gender identity, gender expression, ethnicity or national origin, religion, age, genetic information, disability, or veteran or military status by any member of the KSU Community on campus, in connection with a University program or activity, or in a manner that creates a hostile environment for members of the KSU community.
For additional information on this policy, or to file a complaint under the provisions of this policy, students, employees, applicants for employment or admission or other third parties should contact the Office of Institutional Equity at English Building, Suite 225, eeo@kennesaw.edu.
Other Information
This is not a supervisory position.
This position does not have any financial responsibilities.
This position will not be required to drive.
This role is considered a position of trust.
This position does not require a purchasing card (P-Card).
This position may travel 1% - 24% of the time
This position does not require security clearance.
Background Check
- Standard Enhanced
- Education
Per the University System of Georgia background check policy, all final candidates will be required to consent to a criminal background investigation. Final candidates may be asked to disclose criminal record history during the initial screening process and prior to a conditional offer of employment. Applicants for positions of trust with screening results which confirm a disqualifying criminal history will be immediately disqualified from employment eligibility
All applicants are required to include professional references as part of their application process. Some positions may require additional job-based screenings such as motor vehicle report, credit check, pre-employment drug screening and/or verification of academic credentials.
https://www.usg.edu/hr/assets/hr/hrap_manual/HRAP_Background_Investigation_Employment.pdf
Organization
Founded in 1963, Kennesaw State University (KSU) is the third-largest in the University System of Georgia with more than 22,500 undergraduate and graduate students representing 142 countries.
KSU is located just northwest of Atlanta in Cobb County near historic Kennesaw Mountain, allowing students to experience the best of Atlanta while enjoying the serenity of a 384-acre, beautifully landscaped pedestrian-friendly campus.
Accredited by the Southern Association of Colleges and Schools (SACS), KSU offers 70 bachelor's, master's and doctorate degree programs including undergraduate degrees in education, health, business, the humanities, the arts, science and math and graduate degree programs in nursing, business, information systems, conflict management, public administration, education and professional writing. The university's expanding doctoral programs currently offer a Doctorate of Education in Leadership for Learning, Doctorate of Business Administration and Doctorate of Nursing.
Additionally, nursing students from Kennesaw State have one of the highest passing rates on the statewide licensing exam and are highly sought-after in the medical community, while the College of Education is the second-largest preparer of teachers in the state. The Executive MBA program, housed in the Coles College of Business, is the second-largest program in the country and has been recognized by BusinessWeek.
KSU's national reputation has gained steam and has been recognized by U.S. News & World Report for the past two years as an "Up-and-Coming Masters University in the South," ranking among the top ten (8th) in the 2010 issue of "America's Best Colleges." In addition, the university's First-Year Experience has been named an "Academic Program to Look For" by U.S.News for seven consecutive years and was named one of 12 founding institutions in a project called "Foundations of Excellence in the First Year of College."
The university has committed itself to expanding the global experience of students, faculty and staff through its Quality Enhancement Plan (QEP), known as the "Global Learning for Engaged Citizenship" initiative, which began in 2007. This program focuses on increasing opportunities for international learning experiences. In spring 2009, KSU awarded its first Global Engagement Certification to graduate and undergraduate students. This certification recognizes students' achievements in learning global perspectives and developing intercultural skills.
As a destination campus, KSU offers students plenty of opportunities to experience campus life by participating in more than 150 student groups and organizations, including student government, sororities and fraternities, club and intramural sports, social and special-interest organizations, student publications and honor societies.
In 2009, the Kennesaw State Owls completed a reclassification from NCAA Division II to NCAA Division I, competing in the Atlantic Sun Conference. During the transition from 2005-2009, KSU teams have won six Atlantic Sun Conference tournaments in five sports, including men's indoor and outdoor track, women's soccer, softball and cross-country.
Kennesaw State University has been recognized as one of the top universities in the country by the Chronicle of Higher Education's "2009 Great Colleges to Work For." KSU was recognized among the top 10 schools in six categories – confidence in senior leadership, teaching environment, collaborative governance, professional/career development programs, physical work space conditions and post-retirement benefits.
Kennesaw State was originally established by the University System of Georgia as Kennesaw Junior College serving 1,000 students. The college became a four-year institution in 1976 and was named Kennesaw College in 1977. In 1988, on its 25th anniversary, it was named Kennesaw State College and in 1996 became Kennesaw State University.
Company info
Telephone: 470-578-6000
Location: 1000 Chastain Road, Kennesaw, GA 30144, United States
This is a Preview Listing…
You must sign in to see the full job description, and to apply.
Manage / Upgrade this job to a Full Job Listing.
Find Your Best Opportunity
Tell them AcademicJobs.com sent you!

