Job description
The State Universities Retirement System of Illinois (SURS) is one of the five state-funded retirement plans that provide retirement, survivor, death and disability benefits on behalf of approximately 245,000 members from 61 employers in Illinois, including state universities, community colleges and state agencies. As of June 30, 2022, SURS defined benefit plan was valued at approximately $22.6 billion while SURS RSP and DCP defined contribution plans were valued at approximately $3.5 billion and $8.5 million, respectively.
The IT Governance, Risk, and Compliance (GRC) Analyst is responsible for the assessing and documenting of the organization’s compliance and risk posture as they relate to its information assets. The purpose of this position is to provide skilled technical expertise for development and implementation of the SURS IT GRC program. The GRC Analyst reports to the Chief Technology Officer.
Position: IT GRC Analyst
Main Duties
Leadership
- Perform other duties as assigned to ensure the smooth functioning of the IT department and maintain the reputation of the organization as a value-added business partner.
- Recommend programmatic and technical directions and operate with a high degree of independence in matters relating to the investigation, impact, and analysis of security policies, decisions regarding risk, and measures for computer and network system governance.
- Operate with a high degree of independence regarding project management activities, including development of project plans and budget/resource estimates
Risk
- Champion the development and implementation of the system-wide risk management function of the information security program to ensure information security risks are identified and monitored.
- Internally assess, evaluate, and make recommendations to management regarding the adequacy of the security controls for SURS’ information systems.
Policy/Compliance
- Lead the system-wide information security compliance program, ensuring IT activities, processes, and procedures meet defined requirements, policies, and regulations.
- Develop and implement effective and reasonable policies and practices to secure protected and sensitive data and ensure information security and compliance with relevant legislation and legal interpretation.
- Execute strategy for dealing with increasing number of audits, compliance checks and external assessment processes for internal/external auditors.
Outreach/Awareness
- Interacts in both oral and written communications with all levels of SURS staff including IT staff, general counsel, auditors, and all SURS staff and technology vendors and contractors, in matters related to information security and security awareness materials.
Audit
- Work with Internal Audit and outside consultants/auditors as appropriate.
- Coordinate and track all information technology and security related audits including scope of audits, systems involved, timelines, auditing agencies and outcomes.
Required Qualifications
- High school diploma or equivalent.
- Any one or any combination totaling two (2) years (24 months) from the following categories:
- College coursework which includes Information Technology (IT), IT Management, Programming, IT systems, or a closely related discipline, as measured by the following conversion table or its proportional equivalent:
- 30 semester hours equals one (1) year (12 months)
- Associate’s Degree (60 semester hours) equals eighteen months (18 months)
- 90 semester hours equals two (2) years (24 months)
- Bachelor’s Degree (120 semester hours) equals three (3) years (36 months)
- Work experience in IT-related functions, such as hardware/software support, programming, network design, network engineering, IT systems integration, or closely related field.
- College coursework which includes Information Technology (IT), IT Management, Programming, IT systems, or a closely related discipline, as measured by the following conversion table or its proportional equivalent:
- Based on position requirements, additional education, training, and/or work experience in the area of specialization inherent to the position may be required.
Knowledge of the systems and operations used within the areas and departments of responsibility.- Excellent verbal and written communication skills.
- Ability to oversee and coordinate activities of user groups.
- Ability to effectively communicate with other colleagues, supervisors, administrative staff, and other IT users.
- Ability to identify and resolve technical problems.
- Ability to effectively communicate and professionally interact with all staff levels.
Preferred Qualifications
- Two (2) to five (5) years of advanced IT skills
- Knowledge of information security risk management frameworks and compliance practices
- Knowledge of securing network technologies, client, and server operating systems
- Ability to develop security standards and guidelines based on best practices and industry standards
- Experience responding to, analyzing, and communicating information technology-related items
- Excellent interpersonal, communication, and presentation skills, including formal report writing experience
- Understanding of common security standards and regulations (e.g., PCI DSS, SOX IT General Controls, NIST 800-53, ISO2700x, etc.)
Location
- Out-of-state residents must establish Illinois residency within 180 calendar days of the start date for this position. Illinois residency requires proof of a valid Illinois Driver's License or state of Illinois ID Card. Failure to produce the required documentation within 180 calendar days will result in immediate termination of employment.
- This is a hybrid position, a combination of remote workdays and in office workdays, based in Champaign, IL.
Benefits
- Insurance benefits, including medical, vision and dental
- Participation in SURS retirement plan
- Paid vacation, sick leave and 11 paid holidays
- Paid Parental Leave after six months of employment
- Casual/business casual attire (dependent on job duties)
- Flexible work environment
Application Process