2

Entry Level Cybersecurity Governance Jobs (NOW HIRING)

Introduction About IBM Cybersecurity IBM Cybersecurity brings together consultants, architects ... Governance, Risk, and Compliance. In this role, you'll work alongside experienced consultants on ...

Showing results 41-60

Entry Level Cybersecurity Governance information

See salary details

$43K

$99.4K

$150K

How much do entry level cybersecurity governance jobs pay per year?

As of Sep 1, 2026, the average yearly pay for entry level cybersecurity governance in the United States is $99,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,500.00 and $115,500.00 per year, depending on experience, location, and employer.

What is entry level cybersecurity governance?

Entry level cybersecurity governance refers to roles focused on helping organizations develop, implement, and maintain policies, procedures, and standards that protect digital information and systems. These positions typically involve supporting compliance efforts, conducting risk assessments, and ensuring that security controls align with legal and regulatory requirements. Entry level professionals often assist in organizing security awareness programs, monitoring policy adherence, and preparing documentation for audits. This role is a great starting point for those interested in the broader field of cybersecurity management and compliance.

What are the key skills and qualifications needed to thrive as an entry level cybersecurity governance professional?

To thrive in Entry Level Cybersecurity Governance, you need a basic understanding of information security principles, risk management, and compliance frameworks, often supported by a relevant degree or certifications such as CompTIA Security+ or ISO/IEC 27001 Foundations. Familiarity with governance, risk, and compliance (GRC) tools, security policies, and regulatory standards like GDPR or NIST is typically required. Strong analytical thinking, attention to detail, and effective communication are important soft skills for managing documentation and collaborating with cross-functional teams. These skills ensure that organizations maintain robust security postures and comply with legal and regulatory requirements.

What are some common challenges faced by entry level cybersecurity governance professionals, and how can they overcome them?

Entry-level professionals in cybersecurity governance often face challenges such as understanding complex regulatory requirements, staying updated with evolving compliance standards, and effectively communicating risks to non-technical stakeholders. To overcome these challenges, it is helpful to proactively seek mentorship, participate in regular training, and engage with cross-functional teams to better understand business processes. Building strong documentation and organizational skills will also help you manage policies and audits more efficiently, setting a solid foundation for career growth.

What is the difference between Entry Level Cybersecurity Governance vs Entry Level Cybersecurity Compliance?

AspectEntry Level Cybersecurity GovernanceEntry Level Cybersecurity Compliance
CertificationsCompTIA Security+, CISSP (entry-level), CISA (entry-level)CompTIA Security+, CISA, CISSP (entry-level)
Work EnvironmentDevelops policies, risk management, strategic planningEnsures adherence to policies, audits, regulatory requirements
Employer & Industry UsageOrganizations establishing cybersecurity frameworksOrganizations maintaining regulatory compliance
Search & Comparison IntentUnderstanding governance roles in cybersecurityUnderstanding compliance and audit roles

Entry Level Cybersecurity Governance focuses on creating policies, managing risks, and establishing cybersecurity frameworks. In contrast, Entry Level Cybersecurity Compliance emphasizes ensuring adherence to regulations, conducting audits, and maintaining compliance standards. Both roles are essential in a cybersecurity team but differ in their primary focus and responsibilities.

What are some entry-level cybersecurity governance jobs?

Entry-level cybersecurity governance jobs include roles such as Security Analyst, Compliance Analyst, or Governance Associate. These positions typically involve supporting security policies, risk assessments, and regulatory compliance, often requiring knowledge of frameworks like NIST or ISO and familiarity with security tools. They serve as a foundation for careers in cybersecurity management and policy development.
More about Entry Level Cybersecurity Governance jobs

What cities are hiring for Entry Level Cybersecurity Governance jobs?

Cities with the most Entry Level Cybersecurity Governance job openings:

What are the most commonly searched types of Cybersecurity Governance jobs?

The most popular types of Cybersecurity Governance jobs are:

What states have the most Entry Level Cybersecurity Governance jobs?

States with the most job openings for Entry Level Cybersecurity Governance jobs include:

Infographic showing various Entry Level Cybersecurity Governance job openings in the United States as of August 2026, with employment types broken down into 83% Full Time, and 17% Contract. Highlights an 100% In-person job distribution, with an average salary of $99,400 per year, or $47.8 per hour.

Cybersecurity Systems Engineer (Entry Level to SME) TS/SCI with with Security Clearance

CGI

Arlington, VA • On-site

$66 - $81/hr

Other

Re-posted 10 days ago


CGI rating

7.1

Company rating: 7.1 out of 10

Based on 19 frontline employees who took The Breakroom Quiz

149th of 226 rated it services


Job description

Position Description: CGI Federal has an exciting opportunity for Cybersecurity Systems Engineers within our Intel sector advancing the national security mission through cutting edge technology. You must have a passion for keeping pace with rapidly evolving technology advancements and leveraging your knowledge on a highly collaborative team to deliver state-of-the-art capabilities. The Cybersecurity Systems Engineer supports senior staff in maintaining and securing an organization's IT infrastructure. They assist in configuring security controls, monitoring for threats, and documenting system policies, acting as a foundational builder of daily cyber defenses. CGI Federal is growing its high-performance team whose members share a passion for building high-quality, scalable, advanced IT solutions in a collaborative, fast-paced, outcome-driven mission. This position is located in our Arlington office; however, a hybrid working model is acceptable. Your future duties and responsibilities: Key Responsibilities (Entry Level)
• System Maintenance: Assist in maintaining and upgrading basic security software (e.g., antivirus, firewalls, endpoint protection).
• Monitoring: Help monitor networks and servers for unusual activity or policy violations.
• Vulnerability Management: Run routine vulnerability scans and help patch outdated software.
• Documentation: Write and organize technical reports, standard operating procedures, and security system documentation.
• Incident Support: Assist senior engineers during security investigations by gathering logs and basic data. Key Responsibilities (Junior Level)
• Security Administration: Assist in the operation, configuration, and maintenance of host-based, network-based, and cloud-based security systems.
• System Hardening: Implement and maintain hardware and software configuration management processes to ensure systems are secured per industry best practices (e.g., DISA STIGs if applicable).
• Monitoring & Triage: Monitor security logs, analyze event alerts, and manage ticket queues for system and security issues.
• Vulnerability Management: Perform vulnerability assessments and risk analyses to identify weaknesses and prioritize patches or remediation.
• Documentation & Compliance: Help maintain technical security documentation, support Assessment and Authorization (A&A) activities, and track compliance.
• Incident Response: Participate in the tactical execution of the Cyber Incident Response Team (CIRT) by investigating suspicious activity on servers and securing system boundaries. Key Responsibilities (Mid-Level)
Systems Engineering & Secure Architecture
• Design, implement, and maintain Commercial-off-the-Shelf (COTS) and custom security products, including firewalls, SIEM tools, and identity management systems.
• Deploy and secure software applications within virtualized infrastructures and highly distributed cloud computing environments.
• Manage and secure endpoint baselines across operating systems like Linux (Red Hat, Ubuntu) and Windows.
• Participate in Agile/DevSecOps teams to automate security testing and integrate security controls into CI/CD pipelines.
Security Operations & Threat Management
• Conduct static and dynamic source code analysis (SAST/DAST) and manage application vulnerabilities as technical debt within backlogs.
• Perform root cause analysis on security incidents and proactively recommend mitigations to strengthen the overall security posture.
• Coordinate vulnerability scanning, patch management, and threat hunting across enterprise and operational environments.
Governance, Risk, and Compliance (GRC) • Implement and audit technical controls against rigorous compliance frameworks such as NIST SP 800-53, NIST 800-171, or CMMC Level 2.
• Prepare and execute testing procedures for assessing conformance with DoD, Federal Civilian, or Intelligence Community requirements.
• Draft and maintain essential systems engineering documentation, including System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), and Interface Control Documents (ICDs). Key Responsibilities (Senior Level)
• Advanced Architecture: Architect, implement, and validate integrated hardware/software/firmware security solutions for highly complex environments (e.g., aerospace, cloud, or enterprise).
• Attack Surface Analysis (ASA): Perform attack surface analyses and decompose system-level security controls into technical performance requirements across disciplines like Anti-Tamper and cryptography.
• Cloud & DevOps Security: Design zero-trust environments, implement Infrastructure as Code (IaC) via Terraform, and securely deploy Mission Unique Software (MUS) in highly virtualized clouds.
• Risk Management Framework (RMF): Lead the RMF process from system categorization to continuous monitoring (ConMon), ensuring compliance with strict federal or commercial controls.
• Vulnerability & Flaw Remediation: Triage findings from Static Code Analysis (SCA) and establish technical debt in the software backlog.
• Continuous Monitoring: Utilize tools like ACAS to conduct comprehensive vulnerability scanning, patch management, and assess deviation mitigations.
• Incident Response & Ethical Hacking: Design and deploy security systems like SIEM, EDR, and XDR. Support tactical execution during critical incidents or cyber test & evaluation.
• Automation: Automate repetitive security tasks and identity workflows. Experience with scripting in Python or PowerShell is strongly required. Key Responsibilities (SME Level)
• Security Architecture & Design: Architect enterprise-wide cyber systems and embed security into the design of hardware, software, and network components across OSI layers.
• Risk & Compliance: Manage Risk Management Framework (RMF) activities, including Attack Surface Analyses (ASA), Security Control Traceability Matrices (SCTM), and Plans of Action & Milestones (POA&Ms).
• Vulnerability & Threat Management: Conduct advanced risk assessments, threat modeling, static code analysis (SCA) triaging, and flaw remediation.
• Incident Response & Forensics: Lead tactical Cyber Incident Response Team (CIRT) operations, perform forensic preservation, and resolve non-standard vulnerabilities.
• Leadership & Mentorship: Act as the technical point of contact, lead design reviews with stakeholders, and mentor junior or mid-level engineering staff. Required qualifications to be successful in this role: All levels require an active TS/SCI with Poly Entry Level:
• Education: o High School Diploma/GED with 4 years of relevant experience,
o Associates Degree with 2 years of relevant experience, o or Bachelor's Degree with 0 years of relevant experience
• Certifications: Foundational certifications such as CompTIA Security+, Network+, or similar vendor-specific badges.
• Skills: Basic understanding of networking protocols, operating systems (Windows/Linux), and fundamental security concepts. Junior Level/Moderate:
• Education: o High School Diploma/GED with 6 years of relevant experience,
o Associates Degree with 4 years of relevant experience, o Bachelor's Degree with 2 years of relevant experience, o or Masters Degree with 0 years of relevant experience
• Technical Knowledge: Understanding of operating systems (Windows/Linux), network protocols (TCP/IP), and security platforms like SIEM, EDR, or firewalls.
• Certifications: Foundational certifications such as CompTIA Security+, Network+, or similar vendor-specific credentials (e.g., Cisco CCNA, AWS/Azure certifications) are highly valued. Mid-Level/Complex:
• Education: o High School Diploma/GED with 8 years of relevant experience,
o Associates Degree with 6 years of relevant experience, o Bachelor's Degree with 4 years of relevant experience, o or Masters Degree with 2 years of relevant experience,
o or PhD with 0 years of relevant experience
• Technical Skills: Hands-on experience with configuration management tools, scripting or automation (e.g., Python, Bash, PowerShell), and cloud ecosystems (AWS, Azure).
• Compliance: Working knowledge of risk management frameworks (e.g., NIST, RMF, ISO 27001).
• Soft Skills: Strong technical writing, effective communication with non-technical stakeholders, and the ability to balance operational support with long-term architectural initiatives. Senior Level/Exceptionally Complex:
• Education: o High School Diploma/GED with 10 years of relevant experience,
o Associates Degree with 8 years of relevant experience, o Bachelor's Degree with 6 years of relevant experience, o or Masters Degree with 4 years of relevant experience,
o or PhD with 2 years of relevant experience
• Certifications: DoD 8570.01-M compliance (IAM/IASAE Level III) or a CISSP. SME Level/Exceptionally Complex:
• Education: o High School Diploma/GED with 12 years of relevant experience,
o Associates Degree with 10 years of relevant experience, o Bachelor's Degree with 8 years of relevant experience, o or Masters Degree with 6 years of relevant experience,
o or PhD with 4 years of relevant experience
• Certifications: Advanced DoD 8570/8140 baseline certifications (e.g., CISSP, CISM, CASP+ CE).
• Frameworks: Deep, practical command of regulatory frameworks like NIST SP 800-53, JSIG, CNSSI 1253, and NERC CIP.
• Technical Skills: Proficiency in COTS/GOTS security products, OS hardening (Linux/Windows), hypervisors/cloud deployment, and industrial protocols (if applied to OT/ICS). CGI is required by law in some jurisdictions to include a reasonable estimate of the compensation range for this role. The determination of this range includes various factors not limited to skill set, level, experience, relevant training, and licensure and certifications. To support the ability to reward for merit-based performance, CGI typically does not hire individuals at or near the top of the range for their role. Compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range for this role in the U.S. is $

What CGI employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom