1

Cyber Security Governance Jobs (NOW HIRING)

Cybersecurity Program Manager

Alexandria, VA

$118K - $160K/yr

The successful candidate will be responsible for managing cybersecurity strategy, governance, compliance, and program execution while ensuring alignment with federal regulations and industry ...

next page

Showing results 1-20

Cyber Security Governance information

See salary details

$57K

$133K

$186K

How much do cyber security governance jobs pay per year?

As of Jun 17, 2026, the average yearly pay for cyber security governance in the United States is $132,962.00, according to ZipRecruiter salary data. Most workers in this role earn between $111,000.00 and $150,000.00 per year, depending on experience, location, and employer.

What does a cybersecurity governance specialist do?

A cybersecurity governance specialist develops and implements policies, standards, and procedures to ensure an organization’s cybersecurity aligns with legal and regulatory requirements. They oversee risk management, compliance, and security frameworks, often using tools like risk assessments and audits to protect information assets and support organizational security strategies.

Can you make $500,000 a year in cyber security?

Cyber security governance roles, such as Chief Information Security Officer (CISO) or senior security executives, can reach or exceed $500,000 annually with extensive experience, certifications like CISSP, and leadership responsibilities. Most entry- and mid-level cyber security positions typically offer lower salaries, but senior roles in large organizations or with specialized skills can achieve high compensation.

What are the key skills and qualifications needed to thrive in the Cyber Security Governance position, and why are they important?

To thrive in Cyber Security Governance, you need a solid understanding of information security frameworks, risk management, compliance regulations, and policy development, typically backed by a degree in cybersecurity, information technology, or a related field. Experience with GRC (Governance, Risk, and Compliance) tools, and certifications such as CISSP, CISM, or ISO 27001 Lead Implementer are highly valued. Strong communication, analytical thinking, and problem-solving abilities help professionals effectively navigate complex organizational landscapes and drive stakeholder engagement. These skills are vital to ensure organizations not only comply with regulatory standards but also proactively manage information security risks.

What are the key responsibilities of a Cyber Security Governance professional on a daily basis?

As a Cyber Security Governance professional, your daily responsibilities typically involve developing and updating security policies, conducting risk assessments, and ensuring compliance with regulatory frameworks. You may work closely with IT, legal, and management teams to align security strategies with business objectives and to communicate security requirements across the organization. Reviewing audit findings, monitoring for policy violations, and leading awareness training sessions are also common tasks. This role requires a proactive approach to managing evolving security risks and supporting a culture of continuous improvement in information security.

What is the role of governance in cyber security?

In cyber security governance, the Cyber Security Governance professional establishes policies, standards, and procedures to ensure an organization’s security objectives are met. They oversee compliance, risk management, and strategic alignment of security initiatives, often working with frameworks like ISO 27001 or NIST. Effective governance helps organizations manage security risks and maintain regulatory compliance.

What is a Cyber Security Governance job?

A Cyber Security Governance job focuses on establishing and enforcing security policies, frameworks, and compliance requirements to protect an organization's data and systems. Professionals in this role ensure that security practices align with business objectives, industry regulations, and risk management strategies. They collaborate with stakeholders to develop governance structures, assess security risks, and enforce accountability across teams. Their work helps organizations maintain compliance with standards like ISO 27001, NIST, and GDPR. Effective governance improves overall cybersecurity posture while ensuring regulatory adherence.

Is SOC an entry level job?

A Security Operations Center (SOC) analyst role is typically not entry-level and usually requires some experience in cybersecurity, network monitoring, or related fields. Entry-level positions may be labeled as SOC analyst I or junior SOC analyst, but higher-level roles often demand certifications like CompTIA Security+ or CISSP and familiarity with security tools such as SIEM systems. Advancing in SOC roles generally involves gaining hands-on experience and technical skills.
More about Cyber Security Governance jobs
What cities are hiring for Cyber Security Governance jobs? Cities with the most Cyber Security Governance job openings:
What are the most commonly searched types of Cyber Security Governance jobs? The most popular types of Cyber Security Governance jobs are:
What states have the most Cyber Security Governance jobs? States with the most job openings for Cyber Security Governance jobs include:
Infographic showing various Cyber Security Governance job openings in the United States as of June 2026, with employment types broken down into 97% Full Time, and 3% Contract. Highlights an 81% Physical, 8% Hybrid, and 11% Remote job distribution, with an average salary of $132,962 per year, or $63.9 per hour.
Director of Cybersecurity Governance, Risk, and Compliance

Director of Cybersecurity Governance, Risk, and Compliance

Ball Corporation

Westminster, CO

$143K - $225K/yr

Other

Posted 12 days ago


Ball rating

7.7

Company rating: 7.7 out of 10

Based on 22 frontline employees who took The Breakroom Quiz


Job description

At Ball, integrity and trust are the foundation of who we are. Guided by our core values-"We Care. We Work. We Win."-we create a culture where every voice matters and every idea drives progress.  

Together with our global employees, customers, and partners, we're turning bold sustainability goals into reality and shaping a future we can all be proud of. 

Create a new future. Apply Today. 

The Director of Cybersecurity Governance, Risk, and Compliance (GRC) is accountable for designing, building, and leading enterprisewide cyber risk governance, regulatory compliance strategy, and boardlevel risk reporting for Ball Corporation's global manufacturing and supplychaindriven business. This role sets the enterprise cyber risk posture, translates business risk appetite into enforceable governance mechanisms, and ensures cybersecurity risk is measured, reported, and managed as a business risk and not a purely technical concern. The Director serves as Ball's primary authority on cybersecurity risk governance, regulatory compliance and assurance, and acts as a trusted advisor to the CISO, executive leadership, Legal, Internal Audit, and the Board. The role owns and governs all Security GRC subcapabilities: 1) Security Governance & Program Management, 2) Security Risk Management, 3) Security Assessments & Compliance Management, 4) CyberSupply Chain Risk Management, 5) Business Continuity Planning (cyber integration), 6) Security Training & Awareness, 7) Cyber Metrics and Reporting.

Essential Responsible Areas:

  • Establish and maintain the enterprise cybersecurity governance framework, including policies, standards, risk taxonomy, and accountability models, with a focus on building out missing program elements to elevate maturity.
  • Define and operationalize the enterprise cyber risk management program, including risk identification, assessment, prioritization, escalation, and reporting.
  • Own executive and Boardlevel cybersecurity risk & metrics reporting, ensuring alignment to business impact, materiality, and risk tolerance.
  • Lead the global cybersecurity compliance strategy, ensuring alignment with applicable regulatory, legal, and contractual requirements, with an emphasis on establishing rigorous security controls and repeatable compliance processes.
  • Provide senior oversight of cybersecurity audits, assessments, and assurance activities; ensure consistent and defensible outcomes.
  • Govern cyber supplychain and thirdparty risk management, embedding security risk considerations into vendor lifecycle processes.
  • Ensure cybersecurity risk is integrated into business continuity, crisis management, and enterprise resilience planning.
  • Build, lead, develop, and mentor the Security GRC team, establishing clear interfaces with other cybersecurity and business functions.
  • Ensure cybersecurity governance and compliance requirements are appropriately tailored to regional regulatory, legal, and operational realities while maintaining global consistency.
  • Partner with regional business and technology leaders to address localized cyber risk scenarios, including manufacturing, operational technology (OT), and supplychain considerations.
  • Oversee regional regulatory compliance obligations (e.g., data protection, critical infrastructure, export controls) and support regulatory inquiries or audits as required.
  • Enable effective risk communication and escalation between regions and corporate leadership, ensuring timely visibility of material risks.

Required Qualifications:

  • Bachelor's degree in Information Security, Computer Science, Risk Management, Business Administration, or a related field required; Master's degree (e.g., MBA or MS in Information Security/Risk Management) strongly preferred.
  • Minimum of 15 years of progressive experience in cybersecurity, technology risk, or enterprise risk management, including 7+ years leading and building GRC, risk, or compliance functions within complex, preferably global, organizations.
  • Demonstrated experience operating in regulated, assetintensive, or manufacturingcentric environments.
  • Deep knowledge of cybersecurity governance, risk, and compliance frameworks (with experience implementing NIST CSF and ISO 27001), and familiarity with relevant regulations (e.g., SOX ITGC, data protection laws).
  • CISSP or CISM certification required; CRISC, CGEIT, or similar riskfocused certification strongly preferred.

Compensation & Benefits: 

  • Expected Hiring Salary Range:$143,000, - $225,000   (Salary to be determined by the applicant's education, experience, knowledge, skills, and abilities, as well as internal equity and alignment with market data.)  
  • This role will be eligible to participate in the annual incentive compensation plan. 
  • Please visit our "Total Rewards" page to learn more about Ball's comprehensive benefits structure.  
  • Onsite Work Environment:This position is based in [add the location here] and requires regular in-person engagement by working on-site. Travel and local commute between Ball locations and other possible non-Ball locations may be required.  
  • Hybrid On-Site Work Environment: Based in Colorado, this position requires regular in-person engagement by working on-site for four (4) or more days per work week (with core collaboration days of Tuesday, Wednesday, and Thursday). [Travel and local commute between Ball locations and other possible non-Ball locations may be required.] 

When submitting your application to Ball, we encourage you to emphasize your skills, experience, and qualifications that align with the role.  

Ball Corporation is proud to be an Equal Opportunity Employer. We actively encourage applications from everybody. All qualified job applicants will receive consideration without regard to race, color, religion, creed, national origin, aboriginality, genetic information, ancestry, marital status, sex, sexual orientation, gender identity or expression, physical or mental disability, pregnancy, veteran status, age, political affiliation or any other non-merit characteristic. 

Please note the advertised job title might vary from the job title on the contract due to local job title structure and global HR systems. 

  • Under Colorado, California, Connecticut, Minnesota, and Pennsylvania law, you have the right to exclude or redact age-related details-such as your date of birth, school attendance dates, or graduation dates-from your resume, cover letter, CV, or other supporting documents (e.g., transcripts, certificates).  
  • Legal authorization to work in the U.S. We will not sponsor individuals for employment visa, now or in the future, for this job opening. 

* This position will be posted internally for a minimum of 5 days and will remain open until filled or adjusted based on the volume of applicants. 

No agencies please. 

Global Grade 14A


What Ball employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom