Position: Program Administrator
Assignment: Cyber Security Governance and Policy Analyst
Wage/Hour Status: Exempt
Reports to:Director of Network, Infrastructure, and Cyber Security
Pay Grade: TN450/240 days
Dept./School: Technology
Date Revised: Fall 2026
Primary Purpose:
The Cyber Security Governance & Policy Analyst is responsible for developing, implementing, and maintaining the district’s cyber security governance framework, policies, standards, procedures, and risk management practices. This role focuses on the strategic and administrative aspects of cyber security rather than operational security engineering.
The analyst will coordinate district-wide cyber security governance initiatives, facilitate compliance and risk management activities, support incident response planning and tabletop exercises, and help establish governance for emerging technologies including Artificial Intelligence (AI). This position serves as a bridge between technology, legal, instructional, operational, and executive stakeholders to ensure cyber security practices align with district goals, regulatory requirements, and industry best practices.
Qualifications:
Minimum Education/Certification:
· Bachelor’s degree in Cyber Security, Information Technology, Information Assurance, Public Administration, Business Administration, Risk Management, or related field preferred.
· Equivalent combination of education and relevant experience may be considered.
Special Knowledge/Skills/Experience:
· Minimum of 3 years of experience in cyber security governance, IT governance, risk management, compliance, policy development, audit support, or related field.
· One or more of the following certifications preferred:
o Certified Information Systems Security Professional (CISSP)
o Certified in Risk and Information Systems Control (CRISC)
o Certified Information Security Manager (CISM)
o Certified in Governance of Enterprise IT (CGEIT)
o GIAC Information Security Fundamentals (GISF)
o Certified Data Privacy Solutions Engineer (CDPSE)
· Experience developing policies, procedures, standards, or governance documentation required.
· Experience in K-12 education, higher education, government, or large public-sector environments preferred.
· Experience with AI governance, data governance, or privacy governance preferred.
· Knowledge of cyber security governance principles and industry frameworks such as Texas Cybersecurity Framework (TCF), NIST Cybersecurity Framework (CSF), CIS Controls, ISO 27001, or similar standards.
· Understanding of regulatory and privacy considerations relevant to K-12 education.
· Strong written communication and documentation skills.
· Ability to translate technical security concepts into business and educational language.
· Strong organizational and project coordination skills.
· Ability to facilitate meetings, workshops, and tabletop exercises.
· Ability to build collaborative relationships across technical and non-technical departments.
· Ability to manage multiple priorities and deadlines effectively.
· Knowledge of emerging cyber security and AI governance trends.
Major Responsibilities and Duties:
· Develop, maintain, and organize district cyber security policies, standards, procedures, and guidelines.
· Establish and maintain a formal cyber security governance framework aligned to the Texas Cybersecurity Framework (TCF).
· Coordinate periodic policy reviews and updates with district leadership, legal counsel, and technology teams.
· Create documentation standards and governance processes for cyber security initiatives.
· Assist departments with interpreting and applying cyber security policies and procedures.
· Facilitate district cyber security risk assessments and risk tracking processes.
· Identify governance gaps and recommend corrective actions or policy improvements.
· Support compliance efforts related to FERPA, COPPA, CIPA, Texas privacy laws (if applicable), data governance requirements, and other applicable regulations.
· Maintain cyber security risk registers, exception tracking, and remediation documentation.
· Assist with vendor security reviews and third-party risk management processes.
· Coordinate cyber incident response planning activities with technology leadership and district stakeholders.
· Develop and facilitate tabletop exercises and after-action reviews.
· Assist in the development and maintenance of business continuity and disaster recovery governance documentation.
· Document lessons learned from security incidents and track improvement initiatives.
· Assist in developing governance frameworks, standards, and acceptable use guidance for Artificial Intelligence technologies.
· Collaborate with instructional, legal, and technology teams to evaluate AI-related risks and governance needs.
· Support development of AI usage policies addressing data privacy, student safety, ethical use, and regulatory considerations.
· Monitor emerging trends, regulations, and best practices related to AI governance in K-12 education.
· Coordinate governance-related projects and initiatives across departments.
· Maintain inventories of policies, standards, procedures, and governance documentation.
· Support audit preparation and evidence collection activities.
· Track governance program metrics and maturity improvements.
Mental Demands/Physical Demands/Environmental Factors:
· Computers, network troubleshooting tools (i.e., cable testers, protocol analyzers, spectrum analyzers, etc.), punch down tools, labelers.
· Hand tools and test instruments for electronic repairs and cable installations; personal computers and peripherals
· Prolonged sitting; regular kneeling/squatting, bending/stooping, pushing/pulling, twisting
· Climbing, lifting, hearing, reaching, seeing, speaking, standing, walking.
· Repetitive hand motion; frequent keyboarding and use of mouse; regular walking, grasping/squeezing, wrist flexion/extension, reaching
· Moderate lifting and carrying (up to 44 pounds)
· Occasional prolonged and irregular hours; occasional districtwide travel; May be required to be on-call 24 hours a day.
· Work with frequent interruptions; maintain emotional control under stress
OTHER:All employees are to follow district safety protocols and emergency procedures.
The foregoing statements describe the general purpose and responsibilities assigned to this job and are not an exhaustive list of all responsibilities and duties that may be assigned or skills that may be required. This position is an in-person job and is to be performed at the location specified. It does not qualify for remote work or work from home status.
Pay: $345.14 - $419.31 per day
Benefits:
- Dental insurance
- Employee assistance program
- Flexible spending account
- Health insurance
- Health savings account
- Life insurance
- Paid time off
- Retirement plan
- Vision insurance
Work Location: In person