Information Security GRC Analyst/UKHC at University of Kentucky – Lexington, Kentucky
University of Kentucky
Lexington, Kentucky, 40502, United States
Posted on
NewIndustries:Advertising / MarketingJob Function:Safety
New job! Apply early to increase your chances of getting hired.
Explore Related Opportunities
About This Position
University of Kentucky
Equal Employment Opportunity/M/F/disability/protected veteran status.
Posting Details
Posting Specific Questions
Applicant Documents
Required Documents
Equal Employment Opportunity/M/F/disability/protected veteran status.
Posting Details
Posting Details
| Job Title | Information Security GRC Analyst/UKHC |
|---|---|
| Requisition Number | RE53512 |
| Working Title | Information Security Governance, Risk, and Compliance Analyst |
| Department Name | H3997:EVPHA Information Technology |
| Work Location | Lexington, KY |
| Grade Level | 11 |
| Salary Range | $54,080-95,056/year |
| Type of Position | Staff |
| Position Time Status | Full-Time |
| Required Education | BA/BS |
| Click here for more information about equivalencies: | https://hr.uky.edu/employment/working-uk/equivalencies |
| Required Related Experience | 3 yrs |
| Required License/Registration/Certification | None |
| Physical Requirements | The physical requirements of this position include: Mobility to work from several locations depending on business needs; occasionally lifting, pushing, and/or pulling objects up to 50lbs; occasionally standing or walking with objects up to 10lbs; regularly sitting at a computer workstation for extended periods of time with regular repetitive motions (such as typing); occasionally dealing with combative/violent people; and occasional job-related travel. |
| Shift | Primarily Monday through Friday 8am-5pm, with evening, night, and weekend requirements per departmental needs. |
| Job Summary | Responsible for supporting IT governance, risk management, and compliance (GRC) activities across the organization. Provides monitoring, documentation, and reporting to ensure alignment with policies, regulatory requirements, and industry standards. Assists in risk assessments, compliance reviews, and audit preparation. Coordinates with IT teams, business stakeholders, and vendors to support security control implementation. Contributes to process improvements and helps maintain the organization’s overall security posture. Essential Functions: • Supports governance activities by documenting IT policies, procedures, and compliance evidence. • Assists in conducting risk assessments and compliance reviews for systems, applications, and vendors. • Monitors security and compliance metrics, reporting findings to senior analysts or management. • Tracks remediation of identified risks and follows up with stakeholders to ensure timely resolution. • Prepares materials for internal and external audits, supporting audit readiness and evidence collection. • Collaborates with IT and business teams to ensure adherence to regulatory requirements (HIPAA, SOX, PCI-DSS, GDPR, etc.). • Assists in evaluating third-party vendor contracts for security and compliance requirements. • Contributes to security awareness and compliance training efforts for employees and staff. • Participates in continuous improvement of GRC processes and documentation practices. • Performs other duties as assigned. Please note: Effective 7/1/2026, this position will be titled Information Security Governance, Risk, and Compliance Analyst and will report through Information Technology Services in Beyond Blue. |
| Skills / Knowledge / Abilities | |
| Does this position have supervisory responsibilities? | No |
| Preferred Education/Experience | Bachelor’s degree in cybersecurity, computer science, or a related field. |
| Deadline to Apply | 03/15/2026 |
| Our University Community | We value the well-being of each of our employees and are dedicated to creating a healthy place for everyone to work, learn and live. In the interest of maintaining a safe and healthy environment for our students, employees, patients and visitors, the University of Kentucky is a Tobacco & Drug Free campus. The University follows both the federal and state Constitutions as well as all applicable federal and state laws on nondiscrimination. The University provides equal opportunities for qualified persons in all aspects of institutional operations and does not discriminate on the basis of race, color, national origin, ethnic origin, religion, creed, age, physical or mental disability, veteran status, uniformed service, political belief, sex, sexual orientation, gender identity, gender expression, pregnancy, marital status, genetic information or social or economic status. Any candidate offered a position may be required to pass pre-employment screenings as mandated by University of Kentucky Human Resources. These screenings may include a national background check and/or drug screen. |
Posting Specific Questions
Required fields are indicated with an asterisk (*).
- * Describe a time you supported IT governance, risk, or compliance activities (such as a risk assessment, audit preparation, or monitoring security controls). How did your work ensure alignment with policies, regulations, or industry standards?
(Open Ended Question)
Applicant Documents
Required Documents
- Resume
- Cover Letter
Scan to Apply
Just scan this QR code to apply from your phone.
Job Location
Lexington, Kentucky, 40502, United States
Frequently asked questions about this position
Latest Job Openings in Kentucky
Server
The Lafayette
Lexington, KY
Pediatric Occupational Therapist (OT)
H2Health
Paducah, KY
Med Tech
The Neighborhood At Paducah
Paducah, KY
Travel PT - Physical Therapist
Focus Staff
Lexington, KY
Director, Donor Relations and Stewardship, Days
Norton Healthcare
Louisville, KY
Continue to apply
Enter your email to continue. You’ll be redirected to the employer’s application.By clicking Continue, you understand and agree to JobTarget's Terms of Service and Privacy Policy.
Apply Now