IT Compliance Intern
The Office of the Chief Information Security Officer (CISO) is responsible for coordinating and leading IT physical and logical security functions including the strategic planning for the HHS system security program, assessing and managing technology risk, establishing and maintaining security policies, and creating a risk-conscious and security-aware culture.
The Compliance Team is seeking an intern to support Governance, Risk, and Compliance (GRC) analysis and remediation activities. This internship provides hands‑on experience supporting enterprise security compliance efforts by assisting with NIST security control analysis, audit support, assessments, and documentation for HHSC applications. The intern will work under the guidance of experienced security professionals and gain practical exposure to cybersecurity governance, risk management, and regulatory compliance processes within a large public‑sector environment.
The intern will:
● gain practical experience applying NIST security controls to real‑world applications.
● develop foundational knowledge of risk management and compliance processes in an enterprise environment.
● learn how application security requirements are documented, assessed, and remediated.
● build professional skills in security analysis, technical writing, and collaboration with security stakeholders.
Internship Projects and Deliverables:
Review agency NIST control catalog for the state agency in Archer for internal publishing.
Review NIST derived CMS ARC-AMPE control applicable to HHSC information systems for Archer.
Review NIST control submissions for specific systems for quality, relevance and verifying evidence as posted in Archer.
Analyzing and documenting application security controls aligned to NIST security frameworks.
Support risk assessment activities, including identifying control gaps and documenting remediation actions.
Update and maintain security documentation related to application security and compliance requirements.
Assist the Compliance team with remediation tracking and follow‑up activities.
Create an updated and validated IS controls catalog.
Updated and validated CMS ARC-AMPE controls for Archer.
Ensure that security control statements for specific systems are accurate and meet agency needs.
EDUCATIONAL REQUIREMENTS:
High school seniors with completed coursework/certifications in cybersecurity, or who have been accepted into an undergraduate program relating to IT Security or similar fields. High school students will need to provide a letter of recommendation from a recent or current teacher.
Collegiate level students who are currently enrolled in a Computer Science degree program, with an interest in IT/cybersecurity/GRC.
REQUIRED SKILLS:
Ability to collaborate, interact, and communicate professionally with fellow interns and agency staff, and to complete assigned tasks based on checkpoint goals. Demonstrated capacity to work effectively within a team environment, communicate clearly and professionally, and deliver assigned work products according to defined milestones and checkpoint expectations.
The intern must be able to maintain the confidentiality of agency-specific information—including details regarding systems, staff, and internal operations—that they access during their internship duties. Additionally, strict adherence to all agency Acceptable Use Policies (AUP/AUA) and information security requirements governing the use of HHSC systems, data, and resources is required.
Ability and willingness to ask questions and seek clarification when guidance or assistance is needed to complete assigned tasks accurately and securely.
LOCATION AND COMMITMENT
This position is on-site at our Austin State Office location. This internship runs from 10/1/26 to 1/01/27 and requires a commitment of approximately 8 hours per week.
This position is temporary in nature and unpaid.