DIRECTOR OF SECURITY GOVERNANCE AND COMPLIANCE - 79912

State of Tennessee

  • Nashville, TN
  • 6 days ago
  • $136,236–$177,000 Per Year

Highlights

STS Security & Risk Management Team: Led by the Chief Information Security Officer (CISO) who directly report to STS Chief Information Officer (CIO), the STS Security & Risk Management Team is the statewide provider of various cyber risk management services as well as guidance to all State organizations (agencies, departments, bureaus, commissions, and boards) in support of a shared Enterprise Security Model. Job Overview: Reports to the Chief Information Security Officer (CISO) within Strategic Technology Solutions, the Director of Cybersecurity Governance and Compliance is responsible for establishing, directing, and continuously improving the State's cybersecurity governance, policy, compliance, audit, and third-party security oversight programs.

Numbers & Facts

LocationNashville, TN
Salary$136,236–$177,000 Per Year

Description

Executive Service

DIRECTOR OF SECURITY GOVERNANCE AND COMPLIANCE

Finance and Administration

Strategic Technology Solutions

Nashville, TN

Annual Salary: $136,236.00 - $177,000.00 Annual

Closing Date: 08/24/2026

This position is designed as Hybrid.

Background Check:

FTI / CJIS Fingerprints and Name Based Background Check. This position requires a criminal background check. Therefore, you may be required to provide information about your criminal history in order to be considered for this position. The Department of Finance and Administration will not sponsor applicants for work visas.

Who we are and what we do:

Strategic Technology Solutions (STS):STS serves as the State of Tennessee's central technology organization, delivering secure, reliable, and innovative IT services to state agencies. STS provides enterprise infrastructure, cybersecurity, application development, cloud services, artificial intelligence (AI), and end-user support that enable agencies to effectively serve

Tennesseans. Mission: Strategic Technology Solutions delivers secure, modern, and innovative technology that empowers state agencies to provide exceptional service to the people of Tennessee.

STS Security & Risk Management Team: Led by the Chief Information Security Officer (CISO) who directly report to STS Chief Information Officer (CIO), the STS Security & Risk Management Team is the statewide provider of various cyber risk management services as well as guidance to all State organizations (agencies, departments, bureaus, commissions, and boards) in support of a shared Enterprise Security Model. The Cybersecurity Program includes the following services and key functions:' Cybersecurity Solutions Strategic Planning' Agency Support & Cybersecurity Business Relationships Management' Security Operations' Application and Artificial Intelligence (AI) Security' Vulnerability Management' Governance, Risk, and Compliance' Enterprise Cybersecurity Policies' Business Continuity and Disaster RecoverySTS has transformed Tennessee's cybersecurity operations from a set of decentralized agency level systems into one unified, enterprise-managed security program, establishing statewide policies, standards, and governance.

How you make a difference in this role:

  • Experience managing cybersecurity compliance programs, audit activities, governance initiatives, or enterprise risk management programs.

  • Experience interpreting and applying federal and state laws, regulations, contractual obligations, policies, standards, and governance requirements related to information security, privacy, public records, compliance, auditing, risk management, and protection of confidential information.

  • Knowledge of information security standards and best practices, including NIST Cybersecurity Framework, NIST Special Publication 800-53, ISO 27000, and related governance frameworks.

  • Knowledge of federal, state, and local laws, regulations, policies, and standards governing information security, privacy, and compliance.

  • Knowledge of cybersecurity governance, risk management, compliance, auditing, policy development, and control assessment methodologies.

  • Knowledge of third-party risk management, contract security requirements, and vendor oversight practices.

  • Knowledge of regulatory guidance related to cybersecurity governance and compliance.

  • Knowledge of technological trends and developments in the area of information security, governance, risk and compliance management, and data loss prevention.

  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate governance, risk, and compliance concepts to technical and non-technical audiences.

  • Expert knowledge of strategic planning, organizational leadership, and executive decision-making methodologies.

  • Expert knowledge of management best practices.

  • Excellent written and verbal communication skills, interpersonal and collaborative skills, and the ability to communicate security and risk-related concepts to technical and non-technical audiences.

  • Expert knowledge of strategic decision methodologies.

  • Expert knowledge of management best practices.

Job Overview:

Reports to the Chief Information Security Officer (CISO) within Strategic Technology Solutions, the Director of Cybersecurity Governance and Compliance is responsible for establishing, directing, and continuously improving the State's cybersecurity governance, policy, compliance, audit, and third-party security oversight programs. This position provides strategic leadership for enterprise cybersecurity governance activities and ensures alignment with state objectives, regulatory requirements, contractual obligations, and industry-recognized security frameworks.The Director serves as the executive lead for cybersecurity policy management, compliance monitoring, audit coordination, vendor security compliance reviews, and framework implementation activities. This position serves as the primary liaison for cybersecurity-related audit and compliance activities involving federal agencies, state agencies, internal audit organizations, and external oversight entities. The Director is responsible for overseeing cybersecurity-related records disclosure reviews and redaction activities to ensure confidential, sensitive, and protected information is appropriately safeguarded in accordance with Tennessee public records requirements, including Tennessee Code Annotated (TCA) §10-7-504, applicable federal regulations, contractual obligations, and state information security policies.

Key Responsibilities:

  • Direct the enterprise cybersecurity governance program, including policies, standards, procedures, compliance monitoring, audit coordination, and governance reporting.

  • Lead the development, implementation, maintenance, and lifecycle management of enterprise information security policies, standards, and procedures.

  • Direct the State's transition from an ISO 27000-based policy framework to a NIST SP 800-53-based governance and control framework.

  • Oversee cybersecurity compliance programs to evaluate adherence to state policies, federal requirements, contractual obligations, and applicable security frameworks.

  • Provide executive oversight of internal and external cybersecurity audits, assessments, reviews, and examinations.

  • Coordinate enterprise responses to federal, state, and independent audit requests and ensure timely submission of required evidence and documentation.

  • Serve as the primary liaison between Strategic Technology Solutions, state agencies, federal oversight organizations, and internal audit entities regarding cybersecurity governance and compliance matters.

  • Oversee security contract reviews, endorsements and cybersecurity requirements incorporated into procurement and vendor agreements.

  • Provide executive oversight of cybersecurity-related records review and document redaction activities associated with public records requests, legal requests, audits, and other disclosure requirements.

  • Ensure confidential, sensitive, and protected information is appropriately identified and redacted in accordance with Tennessee Code Annotated §10-7-504, federal requirements, contractual obligations, and state information security policies.

  • Establish and maintain policies, standards, procedures, and governance processes related to records review, information classification, disclosure determinations, and redaction activities.

  • Collaborate with Legal, Records Management, Procurement, Internal Audit, and agency stakeholders to ensure consistent application of statutory exemptions and protection of confidential information.

  • Direct governance activities associated with third-party security risk management and vendor compliance requirements.

  • Develop and maintain governance metrics, compliance dashboards, audit reporting, and executive-level risk reporting for senior leadership.

  • Collaborate with agency leadership, legal counsel, procurement officials, risk management personnel, and business stakeholders to ensure cybersecurity requirements are appropriately implemented and maintained.

  • Ensure policy controls, compliance requirements, and governance processes remain aligned with regulatory obligations, industry standards, and organizational risk tolerance.

  • Lead corrective action planning and remediation oversight for audit findings, compliance deficiencies, and governance-related risks.

  • Provide strategic recommendations to the CISO regarding cybersecurity governance, compliance obligations, audit readiness, and policy modernization initiatives.

  • Assign responsibilities to staff and empower employees to execute governance, compliance, audit, and policy management programs.

  • Develop job performance plans for assigned subordinates to communicate responsibilities and expected outcomes of performance in their role.

  • Review and approve future staffing and skill requirements needed for succession planning and talent management purposes.

Minimum Qualifications:

  • Bachelor's degree in Information Technology, Cybersecurity, Business Administration, Public Administration, Risk Management, Legal Studies, Pre-Law, Juris Doctor (J.D.), or a related field. Relevant professional experience may be substituted for the required degree.

  • Eight years of progressively responsible experience in cybersecurity governance, information security, risk management, compliance, auditing, information technology, or related fields.

Preferred Qualifications:

  • CISSP, CISA, CISM, CRISC, CGRC (formerly CAP), or equivalent professional certification.

  • Experience implementing or managing NIST SP 800-53-based governance and compliance programs.

  • Experience managing federal audit, compliance, or regulatory oversight activities.

Pursuant to the State of Tennessee's Workplace Discrimination and Harassment policy, the State is firmly committed to the principle of fair and equal employment opportunities for its citizens and strives to protect the rights and opportunities of all people to seek, obtain, and hold employment without being subjected to illegal discrimination and harassment in the workplace. It is the State's policy to provide an environment free of discrimination and harassment of an individual because of that person's race, color, national origin, age (40 and over), sex, pregnancy, religion, creed, disability, veteran's status or any other category protected by state and/or federal civil rights laws.

Similar Jobs

Company Name Withheld

Hospital Director of Pharmacy

  • Nashville, TN
30+ days ago
See more jobs