Security Governance Specialist/NIST

Connvertex Technologies Inc.
Wilmington, DE, United States
about 1 month ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours

Tech stack

Cyber Security Data Structures Power BI SQL Databases

Job description

Build and own a security metrics program that tracks control coverage, risk trends, and program maturity over time. Map current security practices to the NIST Cybersecurity Framework and clearly document where formal control plans exist and where they do not. Translate technical security data into business language executives can act on. Design and maintain Power BI dashboards and reports that give leadership ongoing visibility into security posture. Identify emerging risk trends early and flag them before they turn into incidents. Partner with security, IT, and business stakeholders to build remediation and mitigation plans for identified gaps. Establish recurring reporting cadences and executive briefings on program health. Recommend and track key risk indicators (KRIs) and key performance indicators (KPIs) tied to the security program., Executives have a clear, ongoing view of security risk and trends through Power BI reporting. Gaps in control plans are identified and documented against NIST before they become incidents. Remediation plans are in place and tracked for every identified risk. The organization shifts from reactive security reporting to proactive risk prevention.

Requirements

CANDIDATES WILL NEED TO BE ONSITE IN WILMINGTON, DE EITHER 2-3 TIMES A WEEK OR EVEN ONCE A WEEK IF THEY LIVE A LITTLE FARTHER AWAY CANDIDATES MUST BE WITHIN A ONE- OR TWO-HOUR COMMUTE TO WILMINGTON, DE AND BE WILLING TO DO OCCASIONAL TRAVEL. CANDIDATES MUST HAVE GOOD TENURE AND/OR LONG PROJECTS. CANDIDATES WITH VERY RECENT LOCAL PROJECTS REQUIRED. NO RELOCATION This role owns the measurement and reporting layer of the security program. The focus is turning security activity into clear metrics, trends, and business risk insight. The person will map the organization’s practices against the NIST Cybersecurity Framework, identify where formal control plans exist versus where gaps remain, and build the reporting that lets executives see risk before it becomes an incident., 10+ years in security governance, risk, compliance (GRC), or security program management. Strong working knowledge of the NIST Cybersecurity Framework and how it applies to business control plans. Experience building metrics, dashboards, or reporting programs, ideally in Power BI. Comfortable working with data pulled from SQL based sources; does not need to write complex queries, but should understand the data structure. Strong communication skills, with the ability to present risk and metrics to executive audiences in plain business terms. Experience working in a Microsoft centric IT environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:14 min

Evolution of distributed SQL database architectures

Wei Hu Wei Hu · World Congress 2024

1:24 min

Moving the semantic layer upstream to avoid vendor lock-in

Piotr Menclewicz Piotr Menclewicz · Europe 2026 Virtual

1:33 min

Recapping vital capability shifts across security and enterprise infrastructure

Sergej Reznik Sergej Reznik · Europe 2026 Virtual

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all