TENNCARE DEPUTY SECURITY OFFICER - 79398

State of Tennessee

  • Nashville, TN
  • 4 days ago
  • $103,440 Per Year

Highlights

Maintain relationships with TennCare stakeholders to establish and facilitate security and risk management processes, including the reporting and oversight of remediation efforts to address negative findings; identify acceptable levels of risk; and establish roles and responsibilities regarding information classification and protection. The State of Tennessee Division of TennCare is seeking a Deputy Chief Information Security Officer to assist the Chief Information Security Officer in establishing and implementing the information security governance structure and strategies, priorities, and directives consistent with the mission of TennCare.

Numbers & Facts

LocationNashville, TN

Description

Executive Service

TENNCARE DEPUTY SECURITY OFFICER

Division of TennCare

Information Systems (IS)

Nashville, TN

Minimum Annual Salary: $103,440.00

Closing Date: 08/17/2026

Background Check:

This position requires a criminal background check. Therefore, you may be required to provide information about your criminal history in order to be considered for this position.

Who we are and what we do:

TennCare is Tennessee's Medicaid managed care program, serving over 1.4 million Tennesseans, including children, pregnant women, older adults, and individuals with disabilities. With an annual budget exceeding $19.2 billion, TennCare operates under the oversight of the Centers for Medicare and Medicaid Services (CMS). Our mission is to provide high-quality, cost-effective care that improves the health and lives of our members.

TennCare's mission is to improve the lives of Tennesseans by providing high-quality, cost-effective care. At TennCare, we are driven by purpose. Our team is committed to improving outcomes for Tennessee's most vulnerable populations through innovation, integrity, and collaboration. Employees at TennCare report a deep sense of impact and satisfaction in their work. We prioritize people and process equally to create a workplace that values meaningful service, professional development, and shared success.

Job Overview:

TennCare compensation is equitable and will be based on education and experience for a qualified candidate in accordance with Department of Human Resources (DOHR) policy.

The Division of TennCare is dedicated to providing our employees with a hybrid work environment. All TennCare positions have a combination of work from home and work in the office, which varies by position, department, and business need. You may review the specific expectations with our hiring team.

The State of Tennessee Division of TennCare is seeking a Deputy Chief Information Security Officer to assist the Chief Information Security Officer in establishing and implementing the information security governance structure and strategies, priorities, and directives consistent with the mission of TennCare. The position will assist with the maintenance and continuous evolution of the TennCare enterprise-wide cybersecurity program following federal and state regulatory requirements and information security best practices. This position will oversee the responsibilities of the Security Operations; Security Architecture; Governance, Risk, and Compliance (GRC); and Identity & Access Management (IAM) teams who work in partnerships to ensure TennCare's overall security posture and regulatory compliance. This position will report to the Chief Information Security Officer.

Key Responsibilities:

  • Assist the CISO in formulating and executing the organization's overall cybersecurity strategy and provide recommendations on information security standards and best practices.

  • Partner with business and technology leaders and assist the CISO in representing the security team in executive discussions to align security with business goals.

  • Work with the CISO to ensure there is appropriate allocation of resources so that the highest priority projects have sufficient support to be completed in a timely and efficient manner.

  • Assist the CISO in implementing a risk management program, focusing on risk identification, prioritization, mitigation, training, and communication.

  • Support the CISO in security incident response management to protect TennCare IT assets and investigate security breaches.

  • Support TennCare leadership in overseeing and enhancing the secure implementation of an Artificial Intelligence governance program, encompassing strategic planning, risk management, and cybersecurity measures to safeguard against potential threats and vulnerabilities.

  • Oversee TennCare's vulnerability management program including, but not limited to, maintaining a centralized scanning environment, identifying scan targets, and working with owners to review and remediate identified vulnerabilities.

  • Oversee security architecture to aid in bridging the gap between technical design with enterprise-level execution.

  • Collaborate with TennCare stakeholders in the development and implementation of policies, standards, procedures, and awareness.

  • Maintain relationships with TennCare stakeholders to establish and facilitate security and risk management processes, including the reporting and oversight of remediation efforts to address negative findings; identify acceptable levels of risk; and establish roles and responsibilities regarding information classification and protection.

  • Assist in the development of metrics to measure the efficiency and effectiveness of the security program.

  • Build, mentor, and develop high-performing security teams by assigning responsibilities and developing appropriate performance plans for staff.

Minimum Qualifications:

  • 5+ years of experience in the field of information security and technology.

  • 3+ years of experience as a technical lead or technical management position, managing cross-functional multidisciplinary teams within information security programs.

  • Bachelor's degree or higher in information technology-related discipline, or equivalent experience. Time spent pursuing a post-graduate degree will count towards job experience.

Or

  • an equivalent combination of education and work experience may be considered.

Desirable Qualifications:

  • Proficiency in cybersecurity frameworks and standards, including NIST CSF, NIST 800-53, ISO 27001, HIPAA, or ARC-AMPE.

  • Professional certifications, such as CISSP, CISM, CISA, or CRISC.

  • Experience working in highly governed or regulated environments, with strong understanding of audit, compliance, and public-sector accountability requirements.

  • Deep understanding of modern enterprise architectures, cloud-native environments, application security, and Identity and Access Management.

  • Proven ability to translate complex security risks into clear, understandable business terms for executive leadership.

  • Demonstrated ability to lead incident response and resilience efforts, coordinating across technical teams, executives, legal, privacy, and communications during high-pressure situations.

Pursuant to the State of Tennessee's Workplace Discrimination and Harassment policy, the State is firmly committed to the principle of fair and equal employment opportunities for its citizens and strives to protect the rights and opportunities of all people to seek, obtain, and hold employment without being subjected to illegal discrimination and harassment in the workplace. It is the State's policy to provide an environment free of discrimination and harassment of an individual because of that person's race, color, national origin, age (40 and over), sex, pregnancy, religion, creed, disability, veteran's status or any other category protected by state and/or federal civil rights laws.

Similar Jobs

See more jobs