Information Security Governance Specialist -Dallas, TX
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are seeking an experienced Information Security Governance Specialist to drive and manage enterprise information security governance, risk, and compliance initiatives. The ideal candidate will possess strong expertise in data classification, threat modeling, security controls, vulnerability management, risk assessment, and audit readiness.
This role is responsible for ensuring that security policies, standards, and controls are effectively designed, implemented, monitored, and governed to protect organizational assets while meeting regulatory and compliance requirements. Key Responsibilities
- Develop, implement, and maintain information security governance frameworks, policies, standards, and procedures.
- Lead enterprise-wide data classification and data protection initiatives.
- Conduct threat modeling exercises to identify risks and recommend security controls during system and application design.
- Perform security risk assessments and maintain risk registers for technology and business processes.
- Coordinate vulnerability management activities, including identification, remediation tracking, and reporting.
- Collect, review, and maintain security control evidence to support audits, compliance assessments, and regulatory requirements.
- Evaluate the effectiveness of security controls and recommend improvements to strengthen the security posture.
- Work closely with infrastructure, application, cloud, and platform teams to ensure security requirements are embedded in solutions.
- Facilitate risk mitigation planning and monitor remediation activities.
- Support internal and external audits, compliance reviews, and security assessments.
- Monitor emerging threats, vulnerabilities, and industry best practices to improve governance processes.
- Prepare security dashboards, metrics, and executive-level risk reports.
- Promote security awareness and governance best practices across the organization.
Requirements
- Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field.
- 6-10 years of experience in Information Security Governance, Risk Management, Compliance, or Cybersecurity.
- Strong knowledge of information security principles, frameworks, and governance practices.
- Hands-on experience conducting risk assessments and threat modeling exercises.
- Experience implementing and managing data classification programs.
- Knowledge of security controls and control testing methodologies.
- Experience managing vulnerability assessment and remediation processes.
- Strong understanding of compliance and regulatory requirements.
- Excellent analytical, documentation, and communication skills.
- Ability to present risks and recommendations to technical and non-technical stakeholders.
Benefits & conditions
Minimum Compensation: USD 37,000 Maximum Compensation: USD 132,000 Compensation is based on actual experience and qualifications of the candidate. The above is a reasonable and a good faith estimate for the role. Medical, vision, and dental benefits, 401k retirement plan, variable pay/incentives, paid time off, and paid holidays are available for full-time employees. This position is not available for independent contractors No applications will be considered if received more than 120 days after the date of this post
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
9 Ways to Make Money Hacking
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.