> Markdown version of [/jobs/ext/1349357-it-security-program-specialist-07172026-79358](https://www.wearedevelopers.com/jobs/ext/1349357-it-security-program-specialist-07172026-79358). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT SECURITY PROGRAM SPECIALIST - 07172026-79358 - **Company:** Finance - **Location:** Nashville, TN, United States - **Salary:** $67,764.0 - $87,912.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Adobe Acrobat, Cloud Computing Security, CompTIA Network+, CompTIA Security+, Cyber Security, Disaster Recovery, Network Security, Linux System Administration, Microsoft Office, Open Web Application Security, Phishing, Microsoft SharePoint, Software Vulnerability Management, Software Security, Information Technology, Mobile Computing, Servicenow, Vulnerability Analysis - **Published:** July 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=59540d9bc6187df1 ## About the Role Education and Experience: Bachelor's degree in a relevant IT or business discipline and one year of experience in business continuity, disaster recovery, risk management, or information security analysis. Substitution of Education for Experience: Relevant work experience may substitute for education on a year-for-year basis (up to four years)., * Bachelor's degree in a field relevant to Cybersecurity or Information Technology and one year of experience in risk management or information security * Relevant work experience may substitute for education on a year-for-year basis Certifications * CompTIA Security+ preferred, or actively pursuing Security+ or an equivalent entry-level security certification * Other relevant certifications considered include CompTIA Network+, ISC2 Certified in Cybersecurity (CC), or equivalent Technical Skills * Foundational understanding of security concepts including vulnerability management, network security, application security, and common attack types * Familiarity with OWASP Top 10 or equivalent common vulnerability classifications * Basic comfort with Windows and Linux environments * Ability to learn and operate enterprise security tools with training and guidance, 1. Action Oriented 2. Customer Focus 3. Manages Ambiguity 4. Drives Results 5. Tech Savvy, 1. Problem solving and critical thinking 2. Communication and documentation 3. Training and user engagement 4. Vulnerability analysis and threat detection 5. Time management and prioritization Abilities: 1. Analyze and interpret complex security data 2. Adapt to evolving threats and technologies 3. Coordinate with stakeholders across agencies 4. Communicate effectively in high-pressure situations 5. Maintain focus and accuracy during emergencies Tools & Equipment 1. Laptop and mobile computing tools 2. Adobe PDF software 3. Microsoft Office Suite 4. SharePoint and ServiceNow 5. Everbridge and security awareness platforms ## Description The IT Security Program Specialist is an entry-to-mid level individual contributor role within the Enterprise Vulnerability Application & Cloud Security (EVACS) team. This position supports recurring security operations across all four of the team's program areas - Application Security, Cloud Security, Vulnerability Management, and Risk Management - with primary focus on vulnerability scanning operations, application security support, phishing awareness campaigns, and GRC platform support. This role is designed for a candidate who is early in their security career and ready to learn, contribute, and grow. The successful candidate will work alongside experienced Coordinators and the EVACS Manager, developing broad foundational knowledge across enterprise security operations while building toward greater responsibilities. Candidates who demonstrate strong performance, curiosity, and professional growth will find a clear path forward on this team. This is an enterprise-level role supporting all executive state agencies and commissions, as well as supporting some non-executive agencies. The candidate will be embedded within a small, high-performing security team and is expected to take ownership of their assigned responsibilities from an early stage. The team operates with a high degree of independence - routine work is handled without close supervision, and only unexpected or novel situations require escalation. The Specialist role is a deliberate investment in the team's future. Candidates who are curious, growth-oriented, and willing to put in the work to develop their skills will have a clear path toward greater responsibilities within one to two years. Responsibilities Vulnerability Management * Support vulnerability scanning operations across a multi-environment infrastructure including physical and cloud data centers * Handle ad-hoc scan requests received via ticketing, email, or chat-execute scans, communicate results, and document outcomes * Monitor automated weekly scans and flag anomalies or failures for senior staff review * Assist with vulnerability finding interpretation and false positive identification under senior staff guidance * Contribute to vulnerability research look up CVE details, assess applicability to state environments, and summarize findings Risk Management - Product Reviews * Perform product security reviews including third-party threat intelligence research, vendor data residency policy validation, and customer communication * Handle routine product reviews independently and escalate complex or emergency product reviews appropriately * Maintain accurate product review records per team standards Phishing Awareness Campaigns * Support phishing campaign setup and execution ' user list configuration, template selection and coordination, notification drafting * Assist with campaign reporting and documentation following campaign completion * Work toward independently managing campaigns end to end GRC Support * Navigate the state's GRC platform for vulnerability scan result review, exception tracking, and report generation * Assist with data accuracy and record maintenance under senior staff guidance * Support evidence collection and documentation for compliance activities Application Security Support * Assist with application security assessment support tasks including test account coordination, scanner configuration support, and results documentation * Sit in on agency calls and security consultations, contributing to routine communications as familiarity develops * Review completed assessment reports to build familiarity with assessment methodology and finding language, 1. Information security best practices and standards 2. Risk assessment and management principles 3. Security frameworks, policies, and regulatory requirements 4. Disaster recovery and continuity planning processes 5. IT systems and operating environments ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)