IT Security Governance Specialist (NIST SME)

  • $75–$85 Per Hour

Highlights

You will map the organization's practices against the NIST Cybersecurity Framework, identify where formal control plans exist versus where gaps remain, and build the reporting architecture that empowers executives to see and mitigate risk before it becomes an incident. NIST Expertise: Deep Subject Matter Expertise (SME) and strong working knowledge of the NIST Cybersecurity Framework and how it applies to business control plans.

Numbers & Facts

LocationWilmington, DE
Salary$75–$85 Per Hour

Description

Role Overview:
  • This role owns the measurement and reporting layer of the enterprise security program. The incoming leader will be tasked with conducting a comprehensive discovery of our current state and goals, subsequently recommending and driving the required solutions. The primary focus is turning complex security activity into clear metrics, trends, and business risk insight. You will map the organization's practices against the NIST Cybersecurity Framework, identify where formal control plans exist versus where gaps remain, and build the reporting architecture that empowers executives to see and mitigate risk before it becomes an incident.
  • Please note: This is a high-level strategic governance and leadership position. It is a heavy IT Security Governance role and is not a hands-on technical engineering (Network/Cloud) position. We are exclusively seeking a NIST Subject Matter Expert.
  • Commute Requirement: Must reside within a 1 to 2-hour commute of Wilmington, DE (No relocation offered).
Key Responsibilities:
  • Program Leadership: Build and own a security metrics program that tracks control coverage, risk trends, and program maturity over time.
  • Framework Mapping: Map current security practices to the NIST Cybersecurity Framework and clearly document where formal control plans exist and where they do not.
  • Executive Visibility: Design and maintain Power BI dashboards and reports that give leadership ongoing visibility into the organizational security posture.
  • Risk Translation: Translate technical security data into precise business language that executives can easily understand and act upon.
  • Proactive Threat Mitigation: Identify emerging risk trends early and flag them before they develop into security incidents.
  • Strategic Collaboration: Partner with security, IT, and business stakeholders to build remediation and mitigation plans for identified gaps.
  • Reporting Cadence: Establish recurring reporting cadences and deliver executive briefings on overall program health.
  • Performance Tracking: Recommend and track key risk indicators (KRIs) and key performance indicators (KPIs) strictly tied to the security program.
Basic Qualifications:
  • Experience: 10+ years of senior-level experience in security governance, risk, compliance (GRC), or security program management. Candidates must demonstrate a stable career history with proven tenure on long-term, strategic projects (recent local project experience is highly preferred).
  • NIST Expertise: Deep Subject Matter Expertise (SME) and strong working knowledge of the NIST Cybersecurity Framework and how it applies to business control plans.
  • Data & Analytics: Experience building metrics, dashboards, or reporting programs, ideally in Power BI. Must be comfortable working with data pulled from SQL-based sources (understanding data structures is required; writing complex queries is not).
  • Communication: Exceptional executive presentation and communication skills, with the ability to articulate risk and metrics to non-technical leadership in plain business terms.
  • Technical Environment: Prior experience working effectively in a Microsoft-centric IT environment.
Success Looks Like:
  • Executives possess a clear, ongoing view of security risk and trends through robust Power BI reporting.
  • Gaps in control plans are accurately identified and documented against the NIST framework long before they result in incidents.
  • Comprehensive remediation plans are established and actively tracked for every identified risk.
  • The organization successfully shifts from a posture of reactive security reporting to proactive risk prevention.

Similar Jobs

See more jobs