
Senior Project Manager - Data Center Construction Jobot
- $150,000–$200,000 Per Year
| Location | Nashville, TN |
| Salary | $103,440–$134,244 Per Year |
Executive Service
IT SECURITY DIRECTOR
Finance and Administration
Strategic Technology Solutions
Nashville, TN
Minimum Annual Salary: $103,440.00 - $134,244.00
Closing Date: 10/01/2026
This position is designation as Hybrid
Background Check:
This position requires a criminal background check and CJIS/FTI Fingerprints. Therefore, you may be required to provide information about your criminal history in order to be considered for this position.
How you make a difference in this role:
The IT Security Director leads security, audit, risk, and compliance for the Tennessee Department of Human Services (DHS) within the Strategic Technology Solutions(STS) organization. The position works under the Agency CIO's leadership and coordinates with cybersecurity partners, program leaders, application teams, infrastructure teams, auditors, and vendors to protect agency systems and sensitive information. The primary focus is to lead and strengthen the agency's security and compliance work, maintain audit readiness, and ensure risks and corrective actions are addressed. The role oversees audit responses, security policies, identity and access management platform and services, vulnerability remediation, and vendor security performance. It also builds security into technology planning, procurement, architecture, and releases. The successful candidate must be able to guide staff, interpret audit and control requirements, communicate risk in plain language, and hold teams and vendors accountable. The director will support modernization, cloud, data, AI, and automation initiatives while helping the agency maintain reliable, secure, and compliant services.
Key Responsibilities:
Lead the agency's security, audit, risk, and compliance work, setting priorities and establishing clear responsibilities across DHS, STS partners, program teams, and vendors.
Coordinate federal and internal audit and assessment activities, ensuring accurate responses, timely submissions, and follow through on findings and corrective actions.
Manage audit intake, evidence collection, response preparation, control walkthroughs, follow-up questions, and submissions.
Review evidence and responses for accuracy, completeness, and consistency before submission.
Guide staff in interpreting auditor requests, identifying supporting evidence, and preparing for auditor discussions.
Maintain organized evidence and records that support repeatable audit readiness.
Maintain a prioritized security and compliance backlog, including audit findings, vulnerabilities, control gaps, and corrective actions.
Assign owners, track deadlines, verify remediation, and escalate overdue or high-risk items.
Oversee required corrective action plans and recurring reporting, including quarterly requests.
Coordinate with responsible teams to address findings and reduce repeat issues.
Oversee the identity and access management (IAM) platform and related processes across the DHS application portfolio, including access approval, onboarding, role changes, periodic access reviews, and timely offboarding.
Coordinate vulnerability identification, prioritization, remediation, and validation with application, infrastructure, STS cybersecurity, and vendor teams, using risk and service impact to guide priorities.
Develop and maintain agency security policies, standards, and procedures in coordination with STS and agency leadership.
Translate requirements into practical guidance for technical and program teams.
Integrate security and compliance reviews into project planning, procurement, architecture, development, and releases so that issues are identified and addressed early.
Review vendor security requirements, evidence, remediation commitments, and performance in partnership with procurement, contract owners, and STS cybersecurity partners.
Coordinate agency security incident response with STS cybersecurity and operational teams, including escalation, agency communications, corrective actions, and lessons learned, consistent with established responsibilities.
Assess security and privacy risks associated with cloud, data sharing, AI, and automation.
Help establish appropriate access, data protection, monitoring, and oversight requirements.
Maintain measurable service expectations and reporting for audit response timeliness, evidence quality, corrective action closure, repeat findings, access management, vulnerability remediation, and security review turnaround.
Present security risks, control gaps, remediation options, and resource needs to agency leadership.
Route risk acceptance and exceptions to the appropriate decision makers and document approved decisions.
Lead and develop assigned staff, strengthen internal knowledge, and improve repeatable processes.
Use automation where practical to support evidence collection, request routing, access reviews, and reporting.
Partner with continuity and recovery owners to ensure security requirements and incident lessons are reflected in service recovery planning and exercises.
Minimum Qualifications:
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Management Information Systems, or a related field is preferred. Relevant education, professional credentials, and experience leading security, audit, risk, or compliance work will be considered together.
Progressively responsible experience in information security, technology risk, IT audit, or compliance is required, including experience leading staff or complex security and compliance programs.
Candidates should have experience coordinating audits, evaluating controls and evidence, managing corrective actions, overseeing access controls, and working across technical and business teams.
Experience with government or health and human services systems, IRS or SSA security requirements, IAM platforms, vendor security oversight, and enterprise vulnerability management is preferred.
Relevant credentials such as CISSP, CISM, CISA, or CRISC are also preferred.
SKILLS
Ability to lead security and compliance work across organizational boundaries, establish accountability, and resolve competing priorities.
Strong knowledge of security controls, IT audit practices, evidence requirements, risk assessment, corrective action planning, and policy development.
Working knowledge of identity and access management, least privilege, separation of duties, privileged access, and access lifecycle controls.
Ability to prioritize vulnerabilities and control gaps based on risk, coordinate remediation, and confirm that corrective actions address the underlying issue.
Broad understanding of application, infrastructure, cloud, data, and vendor security, including security considerations for AI and automation.
Ability to translate technical findings and compliance requirements into clear decisions, practical actions, and concise executive reporting.
Strong staff leadership, coaching, facilitation, and relationship-building skills, including the ability to prepare staff for audit reviews and control walkthroughs.
Strong organization and follow-through, with the ability to manage concurrent audits, deadlines, evidence requests, and remediation commitments. Sound judgment, discretion with sensitive information, and the ability to remain composed during audits, incidents, and other high-pressure situations.
Pursuant to the State of Tennessee's Workplace Discrimination and Harassment policy, the State is firmly committed to the principle of fair and equal employment opportunities for its citizens and strives to protect the rights and opportunities of all people to seek, obtain, and hold employment without being subjected to illegal discrimination and harassment in the workplace. It is the State's policy to provide an environment free of discrimination and harassment of an individual because of that person's race, color, national origin, age (40 and over), sex, pregnancy, religion, creed, disability, veteran's status or any other category protected by state and/or federal civil rights laws.

