> Markdown version of [/jobs/ext/2543921-security-governance-specialist-nist](https://www.wearedevelopers.com/jobs/ext/2543921-security-governance-specialist-nist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Governance Specialist/NIST - **Company:** Shiftcode Analytics, Inc - **Location:** Wilmington, NC, United States - **Experience:** Expert - **Salary:** $166,400.0 - $208,000.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Data Structures, IT Management, Internet Security, Network Security, Microsoft Software, Power BI, SQL Databases, Information Technology - **Published:** August 20, 2026 - **Apply:** https://www.careerbuilder.com/job-details/security-governance-specialist-nist-wilmington-de--35d92e09-e5ad-449b-8d4f-4f221d03ec2e ## About the Role * 10+ years in security governance, risk, compliance (GRC), or security program management. * Strong working knowledge of the NIST Cybersecurity Framework and how it applies to business control plans. * Experience building metrics, dashboards, or reporting programs, ideally in Power BI. * Comfortable working with data pulled from SQL based sources; does not need to write complex queries, but should understand the data structure. * Strong communication skills, with the ability to present risk and metrics to executive audiences in plain business terms. * Experience working in a Microsoft centric IT environment., Business Plan, Cloud Computing, Communication Skills, Computer Security, Data Structures, IT Governance, Information Technology & Information Systems, Internet Security, Leadership, Metrics, Microsoft Product Family, Network Security, Performance Metrics, Power BI, Presentation/Verbal Skills, Problem Solving Skills, Project/Program Management, Reporting Dashboards, Risk, Risk Analysis, Risk Management, SQL (Structured Query Language), Trend Analysis, U.S. National Institute of Standards and Technology (NIST) ## Description This is a Senior IT Security Governance Specialist (Not network or cloud Security) resource (SME) that will come in and do discovery of their current state and goals and then recommend the required solution. This is a heavy IT Security Governance Position, plus need Someone with Good long tenure and with recent local projects. Candidate must be in under 50 miles distance. No Relocation allowed, This role owns the measurement and reporting layer of the security program. The focus is turning security activity into clear metrics, trends, and business risk insight. The person will map the organization's practices against the NIST Cybersecurity Framework, identify where formal control plans exist versus where gaps remain, and build the reporting that lets executives see risk before it becomes an incident. Key Responsibilities * Build and own a security metrics program that tracks control coverage, risk trends, and program maturity over time. * Map current security practices to the NIST Cybersecurity Framework and clearly document where formal control plans exist and where they do not. * Translate technical security data into business language executives can act on. * Design and maintain Power BI dashboards and reports that give leadership ongoing visibility into security posture. * Identify emerging risk trends early and flag them before they turn into incidents. * Partner with security, IT, and business stakeholders to build remediation and mitigation plans for identified gaps. * Establish recurring reporting cadences and executive briefings on program health. * Recommend and track key risk indicators (KRIs) and key performance indicators (KPIs) tied to the security program., * Executives have a clear, ongoing view of security risk and trends through Power BI reporting. * Gaps in control plans are identified and documented against NIST before they become incidents. * Remediation plans are in place and tracked for every identified risk. The organization shifts from reactive security reporting to proactive risk prevention. ## Related Videos - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [REST, GraphQL, gRPC, and more: A comparison of modern API styles](https://www.wearedevelopers.com/videos/100247-rest-graphql-grpc-and-more-a-comparison-of-modern-api-styles) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 119 - ❤️ === ❤️](https://www.wearedevelopers.com/magazine/454-dev-digest-119) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)