Enterprise Cybersecurity Specialist ; GRC; GTA
Listed on 2026-03-01
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, IT Project Manager
Enterprise Cybersecurity Specialist 2 (GRC) (GTA)
Start your career in public service– JOIN OUR TEAM
Georgia Technology Authority (GTA) a
Great Place to Work®
certified!
The Georgia Technology Authority (GTA) is currently seekinga
Enterprise Cybersecurity Specialist 2 – in the
Office of Information Security.
The Georgia Technology Authority (GTA) currently manages the delivery of IT infrastructure services to 89 Executive Branch agencies and managed network services to more than 1,200 state and local government entities.
IT infrastructure services encompass mainframes, servers, service desk, end user computing, disaster recovery and security.
Managed network services include the state’s wide and local area networks, voice, cable and wiring, and conferencing services.
The Enterprise Cybersecurity Specialist 2 supports enterprise-wide cybersecurity governance, risk, and compliance (GRC) initiatives under the direction of the Enterprise Security GRC Director within the Office of Information Security (OIS). This role contributes to the development, implementation, and oversight of security policies, procedures, and programs to ensure alignment with organizational security objectives and regulatory requirements.
The position involves coordinating cross-functional activities to protect organizational assets and support compliance efforts across multiple agencies and locations. It requires collaboration with internal teams, state agencies, managed service providers, and other stakeholders involved in enterprise security functions, including operations, business units, and the Georgia Enterprise Technology Services (GETS) Security Program Office.
The Enterprise Cybersecurity Specialist 2 uses sound judgment to support strategic goals, monitor security risks, and help maintain a strong security posture across the organization.
Responsibilities:- Serves as a subject matter expert in enterprise security governance, risk, compliance, cybersecurity, and risk mitigation.
- Supports the development, implementation, and enforcement of enterprise security policies, procedures, standards, and plans in alignment with federal and Georgia state regulations.
- Communicates cyber risk issues to all levels of management, agency security personnel, and business stakeholders.
- Supports security initiatives and compliance efforts across multiple locations and agencies.
- Ensures security-related goals are met within set priorities, timelines, and resource constraints.
- Reports directly to the Enterprise Security GRC Director and provides strategic support in aligning enterprise-wide security initiatives.
- Manages assigned resources to support IT and cybersecurity goals that reduce organizational risk.
- Conducts and coordinates risk and compliance assessments, continuous monitoring, and reviews to protect information systems and assets.
- Provides expertise in audit and compliance, security training, vulnerability and risk assessments, network and endpoint security, product evaluations, and implementation of security solutions.
- Assists in managing complex security initiatives across diverse technical and business areas.
- Delivers regular status updates and reports to management and stakeholders on cybersecurity projects, risk posture, and compliance using dashboards and other tools.
- Supports third-party risk management by overseeing security compliance of external service providers.
- Maintains working knowledge of cybersecurity contracts and fosters collaboration with IT and security partners.
- Perform other duties as assigned.
- Skilled in identifying, evaluating, and mitigating cybersecurity risks through comprehensive assessments, continuous monitoring, and remediation strategies.
- Ability in developing, implementing, and enforcing enterprise security policies and programs aligned with regulatory requirements and industry standards (e.g., NIST, ISO, HIPAA, PCI-DSS).
- Knowledge of GRC platforms (e.g., Service Now), cloud security tools (AWS, Azure, Google Cloud), and applying frameworks such as NIST CSF, FIPS, and CIS Controls.
- Effectively communicates cybersecurity risks and initiatives to diverse audiences, including executive leadership,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).