6-10 Years
Job TitleInformation Security Governance Specialist
Job SummaryWe are seeking an experienced Information Security Governance Specialist to drive and manage enterprise information security governance, risk, and compliance initiatives. The ideal candidate will possess strong expertise in data classification, threat modeling, security controls, vulnerability management, risk assessment, and audit readiness.
This role is responsible for ensuring that security policies, standards, and controls are effectively designed, implemented, monitored, and governed to protect organizational assets while meeting regulatory and compliance requirements.
Key Responsibilities- Develop, implement, and maintain information security governance frameworks, policies, standards, and procedures.
- Lead enterprise-wide data classification and data protection initiatives.
- Conduct threat modeling exercises to identify risks and recommend security controls during system and application design.
- Perform security risk assessments and maintain risk registers for technology and business processes.
- Coordinate vulnerability management activities, including identification, remediation tracking, and reporting.
- Collect, review, and maintain security control evidence to support audits, compliance assessments, and regulatory requirements.
- Evaluate the effectiveness of security controls and recommend improvements to strengthen the security posture.
- Work closely with infrastructure, application, cloud, and platform teams to ensure security requirements are embedded in solutions.
- Facilitate risk mitigation planning and monitor remediation activities.
- Support internal and external audits, compliance reviews, and security assessments.
- Monitor emerging threats, vulnerabilities, and industry best practices to improve governance processes.
- Prepare security dashboards, metrics, and executive-level risk reports.
- Promote security awareness and governance best practices across the organization.
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field.
- 6-10 years of experience in Information Security Governance, Risk Management, Compliance, or Cybersecurity.
- Strong knowledge of information security principles, frameworks, and governance practices.
- Hands-on experience conducting risk assessments and threat modeling exercises.
- Experience implementing and managing data classification programs.
- Knowledge of security controls and control testing methodologies.
- Experience managing vulnerability assessment and remediation processes.
- Strong understanding of compliance and regulatory requirements.
- Excellent analytical, documentation, and communication skills.
- Ability to present risks and recommendations to technical and non-technical stakeholders.
Minimum Compensation: USD 37,000
Maximum Compensation: USD 132,000
Compensation is based on actual experience and qualifications of the candidate. The above is a reasonable and a good faith estimate for the role.
Medical, vision, and dental benefits, 401k retirement plan, variable pay/incentives, paid time off, and paid holidays are available for full-time employees.
This position is not available for independent contractors
No applications will be considered if received more than 120 days after the date of this post
Skills Required
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field
- 6-10 years of experience in Information Security Governance, Risk Management, Compliance, or Cybersecurity
- Strong knowledge of information security principles, frameworks, and governance practices
- Hands-on experience conducting risk assessments and threat modeling exercises
- Experience implementing and managing data classification programs
- Knowledge of security controls and control testing methodologies
- Experience managing vulnerability assessment and remediation processes
- Strong understanding of compliance and regulatory requirements
- Excellent analytical, documentation, and communication skills
- Ability to present risks and recommendations to technical and non-technical stakeholders
What We Do
Photon.com has emerged as one of the world’s largest and fastest-growing Digital Agencies. We work with 40% of the Fortune 100 on their Digital initiatives and are known for our ability to integrate Strategy Consulting, Creative Design, and Technology at scale. Please visit www.photon.com to learn more about us, how we work, and our customer case studies. Digital Transformation Starts Here.








