IT SECURITY PROGRAM SPECIALIST - 07172026-79358

Finance
Nashville, TN, United States
24 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
1 year minimum
Compensation
$67,764.0 - $87,912.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Adobe Acrobat Cloud Computing Security CompTIA Network+ CompTIA Security+ Cyber Security Disaster Recovery Network Security Linux System Administration Microsoft Office Open Web Application Security Phishing
+7 more
Microsoft SharePoint Software Vulnerability Management Software Security Information Technology Mobile Computing Servicenow Vulnerability Analysis

Job description

The IT Security Program Specialist is an entry-to-mid level individual contributor role within the Enterprise Vulnerability Application & Cloud Security (EVACS) team. This position supports recurring security operations across all four of the team’s program areas - Application Security, Cloud Security, Vulnerability Management, and Risk Management - with primary focus on vulnerability scanning operations, application security support, phishing awareness campaigns, and GRC platform support.

This role is designed for a candidate who is early in their security career and ready to learn, contribute, and grow. The successful candidate will work alongside experienced Coordinators and the EVACS Manager, developing broad foundational knowledge across enterprise security operations while building toward greater responsibilities. Candidates who demonstrate strong performance, curiosity, and professional growth will find a clear path forward on this team.

This is an enterprise-level role supporting all executive state agencies and commissions, as well as supporting some non-executive agencies. The candidate will be embedded within a small, high-performing security team and is expected to take ownership of their assigned responsibilities from an early stage. The team operates with a high degree of independence - routine work is handled without close supervision, and only unexpected or novel situations require escalation.

The Specialist role is a deliberate investment in the team’s future. Candidates who are curious, growth-oriented, and willing to put in the work to develop their skills will have a clear path toward greater responsibilities within one to two years.

Responsibilities

Vulnerability Management

  • Support vulnerability scanning operations across a multi-environment infrastructure including physical and cloud data centers
  • Handle ad-hoc scan requests received via ticketing, email, or chat-execute scans, communicate results, and document outcomes
  • Monitor automated weekly scans and flag anomalies or failures for senior staff review
  • Assist with vulnerability finding interpretation and false positive identification under senior staff guidance
  • Contribute to vulnerability research look up CVE details, assess applicability to state environments, and summarize findings

Risk Management - Product Reviews

  • Perform product security reviews including third-party threat intelligence research, vendor data residency policy validation, and customer communication
  • Handle routine product reviews independently and escalate complex or emergency product reviews appropriately
  • Maintain accurate product review records per team standards

Phishing Awareness Campaigns

  • Support phishing campaign setup and execution ‘ user list configuration, template selection and coordination, notification drafting
  • Assist with campaign reporting and documentation following campaign completion
  • Work toward independently managing campaigns end to end

GRC Support

  • Navigate the state’s GRC platform for vulnerability scan result review, exception tracking, and report generation
  • Assist with data accuracy and record maintenance under senior staff guidance
  • Support evidence collection and documentation for compliance activities

Application Security Support

  • Assist with application security assessment support tasks including test account coordination, scanner configuration support, and results documentation
  • Sit in on agency calls and security consultations, contributing to routine communications as familiarity develops
  • Review completed assessment reports to build familiarity with assessment methodology and finding language, 1. Information security best practices and standards 2. Risk assessment and management principles 3. Security frameworks, policies, and regulatory requirements 4. Disaster recovery and continuity planning processes 5. IT systems and operating environments

Requirements

Education and Experience: Bachelor’s degree in a relevant IT or business discipline and one year of experience in business continuity, disaster recovery, risk management, or information security analysis.

Substitution of Education for Experience: Relevant work experience may substitute for education on a year-for-year basis (up to four years)., * Bachelor’s degree in a field relevant to Cybersecurity or Information Technology and one year of experience in risk management or information security

  • Relevant work experience may substitute for education on a year-for-year basis

Certifications

  • CompTIA Security+ preferred, or actively pursuing Security+ or an equivalent entry-level security certification
  • Other relevant certifications considered include CompTIA Network+, ISC2 Certified in Cybersecurity (CC), or equivalent

Technical Skills

  • Foundational understanding of security concepts including vulnerability management, network security, application security, and common attack types
  • Familiarity with OWASP Top 10 or equivalent common vulnerability classifications
  • Basic comfort with Windows and Linux environments
  • Ability to learn and operate enterprise security tools with training and guidance, 1. Action Oriented 2. Customer Focus 3. Manages Ambiguity 4. Drives Results 5. Tech Savvy, 1. Problem solving and critical thinking 2. Communication and documentation 3. Training and user engagement 4. Vulnerability analysis and threat detection 5. Time management and prioritization

Abilities:

  1. Analyze and interpret complex security data
  2. Adapt to evolving threats and technologies
  3. Coordinate with stakeholders across agencies
  4. Communicate effectively in high-pressure situations
  5. Maintain focus and accuracy during emergencies

Tools & Equipment

  1. Laptop and mobile computing tools
  2. Adobe PDF software
  3. Microsoft Office Suite
  4. SharePoint and ServiceNow
  5. Everbridge and security awareness platforms

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · WWC 2025

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · WWC Europe 2026

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all