1

Cgrc Jobs in Tennessee (NOW HIRING)

Cgrc information

What is a CGRC professional?

CGRC professionals, or Certified in Governance, Risk and Compliance, are experts who help organizations manage risk, ensure regulatory compliance, and establish effective governance frameworks. They analyze processes, identify potential risks, and develop policies to maintain compliance with laws and industry standards. CGRC certification, previously known as CAP (Certified Authorization Professional), is offered by (ISC)² and validates knowledge in governance, risk management, and compliance best practices. These professionals often work in cybersecurity, IT, or regulatory roles across various industries.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (CGRC) professional?

To thrive as a CGRC professional, you need a solid understanding of cybersecurity frameworks, risk management, and regulatory compliance, typically supported by a relevant degree and certifications such as CISSP, CISA, or CGRC (formerly CAP). Familiarity with GRC platforms like Archer, ServiceNow GRC, or RSA, as well as knowledge of NIST, ISO, or HIPAA standards, is commonly required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across teams. These competencies ensure organizations remain secure and compliant, minimizing risk and avoiding costly penalties.

What are some common challenges CGRC professionals face when managing compliance across multiple frameworks?

CGRC (Cybersecurity Governance, Risk, and Compliance) professionals often encounter the challenge of aligning organizational policies with the requirements of various regulatory frameworks, such as NIST, ISO 27001, and GDPR. This can involve interpreting overlapping or conflicting controls and ensuring consistent documentation and reporting. Additionally, they must facilitate communication and collaboration between IT, legal, and business teams to ensure all stakeholders understand and meet compliance obligations. Keeping up with the evolving regulatory landscape and adapting internal processes accordingly is also a key aspect of the role.

What is the difference between Cgrc vs Compliance Analyst?

AspectCgrcCompliance Analyst
CertificationsCertifications like CFE, CISA, or CMMC often preferredCertifications such as CCEP, CISA, or CIA common
Work EnvironmentTypically in cybersecurity, risk management, or compliance teams within organizationsUsually in corporate compliance departments, auditing firms, or regulatory agencies
Industry UsageUsed in industries like finance, healthcare, and government for cybersecurity and risk managementCommon across various industries for regulatory compliance and risk assessment

The Cgrc (Certified Government Risk Compliance) focuses on government-specific regulations and cybersecurity risk management, while a Compliance Analyst generally handles broader regulatory compliance across industries. Both roles require understanding of compliance frameworks, but Cgrc emphasizes government standards and cybersecurity, making it more specialized in those areas.

Infographic showing various Cgrc job openings in Tennessee as of August 2026, with employment types broken down into 88% Full Time, 8% Part Time, and 4% Contract. Highlights an 70% Physical, 10% Hybrid, and 20% Remote job distribution.

Senior Cyber Security Engineer

Brown and Caldwell

Nashville, TN • On-site

$110K - $151K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 8 days ago


Brown and Caldwell rating

9.4

Company rating: 9.4 out of 10

Based on 7 frontline employees who took The Breakroom Quiz

16th of 450 rated engineering


Job description

The Senior Cyber Security Engineer protects the company's systems and information by designing, building, and supporting complex security solutions while driving the organization's compliance posture against applicable industry frameworks and client requirements. This role tackles ambiguous, high-impact security problems that lack predefined solutions and provides pragmatic, risk-based guidance for new technology initiatives with minimal oversight from the manager. Drawing on deep expertise across security tools, techniques, and processes, the Senior CSE monitors and responds to security alerts, manages incidents, and identifies and remediates vulnerabilities across the environment. The Senior CSE partners with technical teams and business stakeholders to focus on the highest priority risks while enabling the business to deliver client solutions securely. This position focuses on safeguarding valuable information through the establishment, enforcement, and managing of security standards.

Responsibilities

  • Work with BC employees to provide support on complex issues, address security questions, and address concerns/threats.
  • Identify opportunities to improve processes and tasks via automation or efficiency.
  • Perform complex scripting and script debugging for automating security tasks.
  • Anticipate security challenges and implement preventative measures.
  • Make critical decisions balancing risks and opportunities to impact positively the company's overall security.
  • Flexibility to adapt and execute various additional assignments based on evolving need

Additional Focus Areas

Security Engineering & Architecture

  • Design, build, and automate security solutions and tooling to detect, prevent, and manage threats across the environment.
  • Shape the security architecture of cloud and infrastructure environments.
  • Guide new technology initiatives with a security-first lens, providing pragmatic, risk-based recommendations that enable the business rather than block it.
  • Build and tune SIEM ingests, use cases, and alerting to sharpen detection capabilities.

Detection, Response & Access

  • Investigate and respond to alerts, incidents, and vulnerabilities, turning insight into action using established tools and playbooks.
  • Champion zero-trust and least-privilege access through regular access reviews.

Compliance & Risk

  • Drive compliance and control maturity against applicable industry frameworks and contractual security requirements (e.g., SOC2, CMMC), including control implementation, audit preparation, and remediation tracking.
  • Assess risk across supplier and third-party relationships, and support Legal with eDiscovery and preservation requests as needed.

Collaboration & Mentorship

  • Partner closely with technical and business teams to deliver secure, high-quality capabilities, prioritizing the risks that matter most.
  • Keep a pulse on emerging threats and technologies and help shape how the team responds to them.
  • Provide mentorship, guidance, and knowledge-sharing to help less experienced team members develop their skills and grow within their roles.

Skills and Competencies

  • Strong comprehension and demonstratable skills in information and data security principles and practices.
  • Data-driven decision-making ability, with strong analytical and problem-solving skills.
  • Excellent communication skills to effectively provide relevant technical guidance to a broad set of stakeholders and mentor employees.
  • Proven skills in application security, software development security, authentication security, SEIM, automation, incident management, vulnerability management, compliance, and security solution implementation.
  • Strong Microsoft/Azure security skills, including automation.

Experience

  • Typically, a minimum of 8 years of relevant cyber security experience.
  • Experience with incident and vulnerability management and security guidance.

Preferred Experience

  • Relevant governance/compliance certifications (e.g., CISSP, CISA, CRISC, CGRC) preferred.
  • 6+ years of direct cyber security experience, including hands-on compliance or audit-support work.
  • Working knowledge across many of the following domains, with deeper hands-on expertise in at least three or four: identity & access management; communications & network; asset; operations; software development; application; SIEM and detection engineering; automation/scripting; and assessment/compliance/audit support.
  • Working knowledge of AI-specific security considerations (e.g., securing AI/ML systems and evaluating AI-assisted tools for security use), and comfort using AI tools to improve security operations.

Education

  • A relevant degree in computer science, cybersecurity, information systems, or related field or equivalent experience is required.
  • Relevant certifications (CISSP, Security+, etc).

Learn more about our work:

Climate Change and Resilience - Brown and Caldwell

Data Center Water - Brown and Caldwell

Emerging Contaminants and PFAS - Brown and Caldwell

Digital Solutions - Brown and Caldwell

News - Brown and Caldwell

Projects - Brown and Caldwell

Industrial Water - Brown and Caldwell

Salary Range: The anticipated starting pay range for this position is based on the employee’s primary work location and may be more or less depending upon skills, experience, and education.  These ranges may be modified in the future.  

Location A: $129,000 - $177,000
Location B: $142,000 - $194,000
Location C: $155,000 - $212,000

You can view which BC location applies to you here. If you have any questions, please speak with your Recruiter. 

Benefits and Other Compensation:  We provide a comprehensive benefits package that promotes employee health, performance, and success which includes medical, dental, vision, short and long-term disability, life insurance, an employee assistance program, paid time off and parental leave, paid holidays, 401(k) retirement savings plan with employer match, performance-based bonus eligibility, employee referral bonuses, tuition reimbursement, pet insurance and long-term care insurance. Click here to see our full list of benefits. 

About Brown and Caldwell  

Headquartered in Walnut Creek, California, Brown and Caldwell is a full-service environmental engineering and construction services firm with 50 offices and over 2,100 professionals across North America and the Pacific. For more than 75 years, we have created leading-edge environmental solutions for municipalities, private industry, and government agencies. We strive to be the company of choice—to our clients, who benefit from our passion for delivering exceptional quality, and to our employees, present and future, who share our commitment to client service, collaboration, and innovation. Join us, and you will find a home where you can do your best work, reach new levels of expertise, and enjoy exceptional development opportunities. For more information, visit www.brownandcaldwell.com 

This position is subject to a pre-employment background check and a pre-employment drug test.  

Notice to Third Party Agencies: Brown and Caldwell does not accept unsolicited resumes from recruiters or employment agencies. In the event a recruiter or agency submits a resume or candidate without a previously signed agreement and approved engagement request with Brown and Caldwell, Brown and Caldwell reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency.   

Brown and Caldwell is proud to be an EEO/AAP Employer. Brown and Caldwell encourages protected veterans, individuals with disabilities, and applicants from all backgrounds to apply. Brown and Caldwell ensures nondiscrimination in all programs and activities in accordance with Title VI of the Civil Rights Act.


What Brown and Caldwell employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom