> Markdown version of [/jobs/ext/3015776-information-security-governance-specialist-dallas-tx](https://www.wearedevelopers.com/jobs/ext/3015776-information-security-governance-specialist-dallas-tx). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Governance Specialist -Dallas, TX - **Company:** PHOTON, LLC - **Location:** Dallas, TX, United States - **Experience:** Expert - **Salary:** $37,000.0 - $132,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Software Engineering, Software Vulnerability Management, Data Classification, Information Technology, Vulnerability Analysis - **Published:** September 20, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e526c6fa98e12c72 ## About the Role * Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field. * 6-10 years of experience in Information Security Governance, Risk Management, Compliance, or Cybersecurity. * Strong knowledge of information security principles, frameworks, and governance practices. * Hands-on experience conducting risk assessments and threat modeling exercises. * Experience implementing and managing data classification programs. * Knowledge of security controls and control testing methodologies. * Experience managing vulnerability assessment and remediation processes. * Strong understanding of compliance and regulatory requirements. * Excellent analytical, documentation, and communication skills. * Ability to present risks and recommendations to technical and non-technical stakeholders. ## Description We are seeking an experienced Information Security Governance Specialist to drive and manage enterprise information security governance, risk, and compliance initiatives. The ideal candidate will possess strong expertise in data classification, threat modeling, security controls, vulnerability management, risk assessment, and audit readiness. This role is responsible for ensuring that security policies, standards, and controls are effectively designed, implemented, monitored, and governed to protect organizational assets while meeting regulatory and compliance requirements. Key Responsibilities * Develop, implement, and maintain information security governance frameworks, policies, standards, and procedures. * Lead enterprise-wide data classification and data protection initiatives. * Conduct threat modeling exercises to identify risks and recommend security controls during system and application design. * Perform security risk assessments and maintain risk registers for technology and business processes. * Coordinate vulnerability management activities, including identification, remediation tracking, and reporting. * Collect, review, and maintain security control evidence to support audits, compliance assessments, and regulatory requirements. * Evaluate the effectiveness of security controls and recommend improvements to strengthen the security posture. * Work closely with infrastructure, application, cloud, and platform teams to ensure security requirements are embedded in solutions. * Facilitate risk mitigation planning and monitor remediation activities. * Support internal and external audits, compliance reviews, and security assessments. * Monitor emerging threats, vulnerabilities, and industry best practices to improve governance processes. * Prepare security dashboards, metrics, and executive-level risk reports. * Promote security awareness and governance best practices across the organization. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [The Avengers Initiative (Practical Ethics for Software Engineers)](https://www.wearedevelopers.com/videos/2070-the-avengers-initiative-practical-ethics-for-software-engineers) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [From APIs to MCP: Enterprise Governance, Registry, and Controls](https://www.wearedevelopers.com/videos/100336-from-apis-to-mcp-enterprise-governance-registry-and-controls) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)