> Markdown version of [/jobs/ext/2652504-director-of-security-governance-and-compliance-79912](https://www.wearedevelopers.com/jobs/ext/2652504-director-of-security-governance-and-compliance-79912). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # DIRECTOR OF SECURITY GOVERNANCE AND COMPLIANCE - 79912 - **Company:** Finance - **Location:** Nashville, TN, United States - **Experience:** Expert - **Salary:** $136,236.0 - $217,752.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Leak Prevention, Information Security Management, Data Classification, Information Technology - **Published:** August 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f0e984aac92a1153 ## About the Role * Experience managing cybersecurity compliance programs, audit activities, governance initiatives, or enterprise risk management programs. * Experience interpreting and applying federal and state laws, regulations, contractual obligations, policies, standards, and governance requirements related to information security, privacy, public records, compliance, auditing, risk management, and protection of confidential information. * Knowledge of information security standards and best practices, including NIST Cybersecurity Framework, NIST Special Publication 800-53, ISO 27000, and related governance frameworks. * Knowledge of federal, state, and local laws, regulations, policies, and standards governing information security, privacy, and compliance. * Knowledge of cybersecurity governance, risk management, compliance, auditing, policy development, and control assessment methodologies. * Knowledge of third-party risk management, contract security requirements, and vendor oversight practices. * Knowledge of regulatory guidance related to cybersecurity governance and compliance. * Knowledge of technological trends and developments in the area of information security, governance, risk and compliance management, and data loss prevention. * Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate governance, risk, and compliance concepts to technical and non-technical audiences. * Expert knowledge of strategic planning, organizational leadership, and executive decision-making methodologies. * Expert knowledge of management best practices. * Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and non-technical audiences. * Expert knowledge of strategic decision methodologies. * Expert knowledge of management best practices., * Bachelor's degree in Information Technology, Cybersecurity, Business Administration, Public Administration, Risk Management, Legal Studies, Pre-Law, Juris Doctor (J.D.), or a related field. Relevant professional experience may be substituted for the required degree. * Eight years of progressively responsible experience in cybersecurity governance, information security, risk management, compliance, auditing, information technology, or related fields., * CISSP, CISA, CISM, CRISC, CGRC (formerly CAP), or equivalent professional certification. * Experience implementing or managing NIST SP 800-53-based governance and compliance programs. * Experience managing federal audit, compliance, or regulatory oversight activities. ## Description Reports to the Chief Information Security Officer (CISO) within Strategic Technology Solutions, the Director of Cybersecurity Governance and Compliance is responsible for establishing, directing, and continuously improving the State's cybersecurity governance, policy, compliance, audit, and third-party security oversight programs. This position provides strategic leadership for enterprise cybersecurity governance activities and ensures alignment with state objectives, regulatory requirements, contractual obligations, and industry-recognized security frameworks.The Director serves as the executive lead for cybersecurity policy management, compliance monitoring, audit coordination, vendor security compliance reviews, and framework implementation activities. This position serves as the primary liaison for cybersecurity-related audit and compliance activities involving federal agencies, state agencies, internal audit organizations, and external oversight entities. The Director is responsible for overseeing cybersecurity-related records disclosure reviews and redaction activities to ensure confidential, sensitive, and protected information is appropriately safeguarded in accordance with Tennessee public records requirements, including Tennessee Code Annotated (TCA) §10-7-504, applicable federal regulations, contractual obligations, and state information security policies., * Direct the enterprise cybersecurity governance program, including policies, standards, procedures, compliance monitoring, audit coordination, and governance reporting. * Lead the development, implementation, maintenance, and lifecycle management of enterprise information security policies, standards, and procedures. * Direct the State's transition from an ISO 27000-based policy framework to a NIST SP 800-53-based governance and control framework. * Oversee cybersecurity compliance programs to evaluate adherence to state policies, federal requirements, contractual obligations, and applicable security frameworks. * Provide executive oversight of internal and external cybersecurity audits, assessments, reviews, and examinations. * Coordinate enterprise responses to federal, state, and independent audit requests and ensure timely submission of required evidence and documentation. * Serve as the primary liaison between Strategic Technology Solutions, state agencies, federal oversight organizations, and internal audit entities regarding cybersecurity governance and compliance matters. * Oversee security contract reviews, endorsements and cybersecurity requirements incorporated into procurement and vendor agreements. * Provide executive oversight of cybersecurity-related records review and document redaction activities associated with public records requests, legal requests, audits, and other disclosure requirements. * Ensure confidential, sensitive, and protected information is appropriately identified and redacted in accordance with Tennessee Code Annotated §10-7-504, federal requirements, contractual obligations, and state information security policies. * Establish and maintain policies, standards, procedures, and governance processes related to records review, information classification, disclosure determinations, and redaction activities. * Collaborate with Legal, Records Management, Procurement, Internal Audit, and agency stakeholders to ensure consistent application of statutory exemptions and protection of confidential information. * Direct governance activities associated with third-party security risk management and vendor compliance requirements. * Develop and maintain governance metrics, compliance dashboards, audit reporting, and executive-level risk reporting for senior leadership. * Collaborate with agency leadership, legal counsel, procurement officials, risk management personnel, and business stakeholders to ensure cybersecurity requirements are appropriately implemented and maintained. * Ensure policy controls, compliance requirements, and governance processes remain aligned with regulatory obligations, industry standards, and organizational risk tolerance. * Lead corrective action planning and remediation oversight for audit findings, compliance deficiencies, and governance-related risks. * Provide strategic recommendations to the CISO regarding cybersecurity governance, compliance obligations, audit readiness, and policy modernization initiatives. * Assign responsibilities to staff and empower employees to execute governance, compliance, audit, and policy management programs. * Develop job performance plans for assigned subordinates to communicate responsibilities and expected outcomes of performance in their role. * Review and approve future staffing and skill requirements needed for succession planning and talent management purposes. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)