1

Security Governance Jobs (NOW HIRING)

To learn more about CIBC, please visit CIBC.com Overview CIBC is seeking an experienced Consultant, Network Security & Governance to join our dynamic information security team. This role will be ...

$130K - $155K/yr

To learn more about CIBC, please visit CIBC.com Overview CIBC is seeking an experienced Consultant, Network Security & Governance to join our dynamic information security team. This role will be ...

$130K - $155K/yr

To learn more about CIBC, please visit CIBC.com Overview CIBC is seeking an experienced Consultant, Network Security & Governance to join our dynamic information security team. This role will be ...

To learn more about CIBC, please visit CIBC.com Overview CIBC is seeking an experienced Consultant, Network Security & Governance to join our dynamic information security team. This role will be ...

next page

Showing results 1-20

Security Governance information

See salary details

$11

$19

$25

How much do security governance jobs pay per hour?

As of Jul 21, 2026, the average hourly pay for security governance in the United States is $19.03, according to ZipRecruiter salary data. Most workers in this role earn between $15.38 and $18.75 per hour, depending on experience, location, and employer.

What are the main challenges faced by professionals in Security Governance, and how can they be addressed?

Professionals in Security Governance often encounter challenges such as aligning security policies with business objectives, managing compliance with evolving regulations, and fostering a security-conscious culture across diverse teams. Addressing these challenges requires ongoing communication with stakeholders, regular policy reviews, and effective training programs to ensure everyone understands their role in maintaining security. Collaboration with IT, legal, and business units is essential to implement governance frameworks that are both practical and robust, enabling organizations to mitigate risks while supporting operational goals.

What are the key skills and qualifications needed to thrive in Security Governance, and why are they important?

To excel in Security Governance, a strong understanding of information security principles, risk management, and regulatory compliance is essential, often supported by a degree in cybersecurity or a related field. Familiarity with frameworks like ISO 27001, NIST, and certifications such as CISSP or CISM are highly valued, along with experience using governance, risk, and compliance (GRC) tools. Outstanding analytical thinking, attention to detail, and effective communication skills help professionals influence policy and collaborate across teams. These skills are crucial for establishing robust security policies, minimizing organizational risk, and ensuring compliance with industry standards.

What is Security Governance?

Security Governance refers to the framework and processes that ensure an organization's information security strategies are aligned with its business objectives, regulatory requirements, and risk management practices. It involves establishing policies, roles, responsibilities, and oversight mechanisms to protect information assets effectively. Security governance provides direction and accountability, making sure that security initiatives are well-coordinated and that risks are managed at the highest level. This helps organizations maintain trust, comply with laws, and respond effectively to evolving threats.

Can you make $500,000 a year in cyber security?

Security governance roles, such as Chief Information Security Officers or senior security executives, can reach or exceed $500,000 annually with extensive experience, advanced certifications, and leadership responsibilities. Most cybersecurity professionals, including security analysts and engineers, earn lower salaries, but high-level positions in large organizations or consulting firms can offer such compensation. Developing expertise in risk management, compliance, and strategic planning can help achieve these salary levels.

What does security governance do?

Security governance involves establishing policies, procedures, and standards to manage an organization's security risks. It ensures that security strategies align with business objectives and compliance requirements, often requiring skills in risk management, policy development, and security frameworks like ISO 27001 or NIST. Security governance provides oversight and accountability to protect information assets effectively.

What is the highest paying security job?

The highest paying security jobs are often executive roles such as Chief Information Security Officer (CISO) or Security Director, with salaries exceeding $150,000 annually. These positions require extensive experience, leadership skills, and knowledge of security frameworks, risk management, and compliance.

Is SOC an entry level job?

A Security Operations Center (SOC) analyst role is typically not entry-level and often requires some experience in cybersecurity, network monitoring, or related fields. Entry-level positions may be labeled as SOC analyst I or junior SOC analyst, but higher-level roles usually demand certifications like CompTIA Security+ or CISSP and familiarity with security tools such as SIEM systems.

What is the difference between Security Governance vs Security Analyst?

AspectSecurity GovernanceSecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISMCompTIA Security+, CISSP, GIAC Security Essentials
Work EnvironmentStrategic, policy-focused, executive-levelOperational, technical, monitoring security threats
Employer & Industry UsageOrganizations' security leadership, compliance teamsSecurity operations centers, IT departments

Security Governance focuses on establishing policies, frameworks, and strategic oversight to ensure overall security compliance. In contrast, Security Analysts handle day-to-day security monitoring, threat detection, and incident response. Both roles are essential but differ in scope, responsibilities, and focus areas within the cybersecurity landscape.

More about Security Governance jobs
What cities are hiring for Security Governance jobs? Cities with the most Security Governance job openings:
What states have the most Security Governance jobs? States with the most job openings for Security Governance jobs include:
Security Governance Manager (Remote / DC-Metro)

Security Governance Manager (Remote / DC-Metro)

Unison Software, Inc.

Remote

Full-time

Posted 25 days ago


Job description

Overview
About Unison:
Unison's products power the business of government to work smoother and smarter, making critical federal processes and acquisitions simpler and more effective. Trusted by over 200,000 federal employees and government contractors, our AI-infused software and deep domain expertise help contract shops, cost engineers, 1102s, program managers, and budgeting professionals cut through friction, keep compliance airtight, and sharpen decisions. Our federal focus brings efficiency, transparency, and clarity to complex data, regulations, and workflows, empowering agencies and executives to spend more minutes on mission and achieve strategic objectives. Unison is how federal business gets done.
Unison is proud to be recognized as a 2026 Quantum Certified Workplaceâ„¢ in Washington D.C., reflecting our continued focus on building a workplace where people feel supported and teams thrive.
Role Overview:
Unison is hiring a Security Governance Manager to manage key activities supporting our federal authorizations, customer assurance obligations, and compliance operations. Reporting directly to the CISO, you will manage security governance activities supporting our authorizations and certifications, including FedRAMP, DoD Impact Level 4 (IL4), CMMC, and others.
You will work as part of the broader Security team to maintain authorization documentation, strengthen evidence quality, coordinate with control owners, support annual assessments, manage customer and vendor assurance activities, and keep audit and authorization work moving with discipline and clarity.
This is a hands-on leadership role for a GRC practitioner who treats compliance as a way to enable the business and earn trust.
Responsibilities
  • Lead and mature the Security Governance function as part of the broader Security team, covering strategy, processes, ownership, reporting, and continuous improvement.
  • Maintain and strengthen Unison's authorizations and certifications, including FedRAMP, IL4, and CMMC, by managing documentation, SSP updates, evidence quality, control-owner coordination, audit readiness, and annual assessment support.
  • Support FedRAMP continuous monitoring activities, including recurring evidence collection, monthly and annual deliverables, risk documentation, remediation commitments, approvals, and deadlines.
  • Coordinate with agency Authorizing Officials, 3PAOs, agency stakeholders, auditors, and control owners through assessments and ongoing authorization activity.
  • Own the lifecycle of security policies, standards, and procedures, keeping documentation aligned with actual business and technical practice.
  • Manage customer trust and assurance activities, including customer security reviews, questionnaires, RFPs, due-diligence responses, and reusable evidence packages.
  • Communicate governance, compliance, audit, and risk topics clearly to technical teams, customers, auditors, executives, and business stakeholders

Qualifications
  • 6+ years in GRC, security governance, compliance, audit, or risk management.
  • Hands-on FedRAMP experience, including authorization, continuous monitoring, SSP maintenance, evidence management, assessments, annual assessment support, and POA&M coordination.
  • Exposure to other federal authorizations and certifications such as DoD IL4/IL5 or CMMC.
  • Working knowledge of NIST SP 800-53 and the control expectations behind FedRAMP, CMMC, and similar programs, including authorization documentation and audit evidence practices.
  • Proven ability to manage people and vendors and to communicate credibly with auditors, technical teams, customers, and executives.
  • Strong written communication skills, including the ability to produce clear policies, procedures, control narratives, customer responses, risk summaries, and executive-ready updates.

Preferred Qualifications
  • A prior hands-on technical role, such as engineering, security operations, or systems/cloud administration.
  • FedRAMP High, agency ATOs, or multiple federal authorization paths.
  • DoD IL4/IL5, CMMC, or DISA experience.
  • SaaS or GovTech experience serving federal agencies.
  • Certifications such as CGRC, CISM, CRISC, CISA, CISSP, or CCSP.

What We're Looking For
We're looking for someone who treats security governance as a way to move the business forward, not a box to check. You understand that security authorizations are a way to earn customer trust.
You're hands-on. You can set direction and mature the program, but you'll also write policy, chase the evidence, sit with the auditor, and answer the hard question on a customer call. You work credibly across our security compliance requirements and can hold your own with engineers without losing the business view.
You bring structure without bureaucracy. You know which controls and processes matter, where to push, and where to keep it simple.
Clearance:Applicants may need to be the subject of a security investigation and may need to meet eligibility requirements for access to classified information, to include U.S. Citizenship.
Compensation:
Base Salary: $155,000 - $190,000
Final compensation will depend on factors such as geographic location, experience, and qualifications.
In-Person Interview:
Our hiring process requires one in-person meeting, typically the final interview. Travel and accommodation will be provided.
Remote Work:
Though predominantly remote, monthly office visits may be required.
Why Join Unison:
Unison has pioneered the creation of innovative software for federal agencies, program offices, and government contractors worldwide. We believe that there is power in moving in unison. Our culture and values reflect this belief and are central to achieving our mission of powering the business of government. Rather than chasing short-lived tech trends, Unison delivers proven software that simplifies the complexities of federal business. Our technology combines innovative thinking with precise federal know-how, addressing critical details others overlook. Designed with purpose and engineered to endure, our software provides consistent performance, allowing federal agencies and contractors to stay focused on their missions.
Unison provides equal employment opportunities to all employees and applicants for employment without regard to race, color, national origin, sex, gender identity, sexual orientation, religion, disability status, age, genetics, veteran status, or any other characteristic protected by federal, state, or local laws.