Job Information
Opening Date/Time
07/17/2026 12:00AM Central Time
Closing Date/Time
07/30/2026 11:59PM Central Time
Salary (Monthly)
$5,647.00 - $7,326.00
Salary (Annually)
$67,764.00 - $87,912.00
City, State Location
Nashville, TN
Department
Finance and Administration
LOCATION OF (1) POSITION(S) TO BE FILLED: DEPARTMENT OF FINANCE & ADMINISTRATION, DAVIDSON COUNTY
The Department of Finance and Administration will not sponsor applicants for work visas.
This position is designed as Hybrid.
FTI and CJIS Fingerprints and Name Based Background Check. This position requires a criminal background check. Therefore, you may be required to provide information about your criminal history in order to be considered for this position.
Qualifications
Education and Experience: Bachelor's degree in a relevant IT or business discipline and one year of experience in business continuity, disaster recovery, risk management, or information security analysis.
Substitution of Education for Experience: Relevant work experience may substitute for education on a year-for-year basis (up to four years).
Necessary Special Qualifications: None
Examination Method: Education and Experience, 100%
Overview
The IT Security Program Specialist is an entry-to-mid level individual contributor role within the Enterprise Vulnerability Application & Cloud Security (EVACS) team. This position supports recurring security operations across all four of the team's program areas - Application Security, Cloud Security, Vulnerability Management, and Risk Management - with primary focus on vulnerability scanning operations, application security support, phishing awareness campaigns, and GRC platform support.
This role is designed for a candidate who is early in their security career and ready to learn, contribute, and grow. The successful candidate will work alongside experienced Coordinators and the EVACS Manager, developing broad foundational knowledge across enterprise security operations while building toward greater responsibilities. Candidates who demonstrate strong performance, curiosity, and professional growth will find a clear path forward on this team.
This is an enterprise-level role supporting all executive state agencies and commissions, as well as supporting some non-executive agencies. The candidate will be embedded within a small, high-performing security team and is expected to take ownership of their assigned responsibilities from an early stage. The team operates with a high degree of independence - routine work is handled without close supervision, and only unexpected or novel situations require escalation.
The Specialist role is a deliberate investment in the team's future. Candidates who are curious, growth-oriented, and willing to put in the work to develop their skills will have a clear path toward greater responsibilities within one to two years.
Responsibilities
Vulnerability Management
-
Support vulnerability scanning operations across a multi-environment infrastructure including physical and cloud data centers
-
Handle ad-hoc scan requests received via ticketing, email, or chat-execute scans, communicate results, and document outcomes
-
Monitor automated weekly scans and flag anomalies or failures for senior staff review
-
Assist with vulnerability finding interpretation and false positive identification under senior staff guidance
-
Contribute to vulnerability research look up CVE details, assess applicability to state environments, and summarize findings
Risk Management - Product Reviews
-
Perform product security reviews including third-party threat intelligence research, vendor data residency policy validation, and customer communication
-
Handle routine product reviews independently and escalate complex or emergency product reviews appropriately
-
Maintain accurate product review records per team standards
Phishing Awareness Campaigns
-
Support phishing campaign setup and execution ' user list configuration, template selection and coordination, notification drafting
-
Assist with campaign reporting and documentation following campaign completion
-
Work toward independently managing campaigns end to end
GRC Support
-
Navigate the state's GRC platform for vulnerability scan result review, exception tracking, and report generation
-
Assist with data accuracy and record maintenance under senior staff guidance
-
Support evidence collection and documentation for compliance activities
Application Security Support
-
Assist with application security assessment support tasks including test account coordination, scanner configuration support, and results documentation
-
Sit in on agency calls and security consultations, contributing to routine communications as familiarity develops
-
Review completed assessment reports to build familiarity with assessment methodology and finding language
Preferred Qualification
Experience and Education
-
Bachelor's degree in a field relevant to Cybersecurity or Information Technology and one year of experience in risk management or information security
-
Relevant work experience may substitute for education on a year-for-year basis
Certifications
-
CompTIA Security+ preferred, or actively pursuing Security+ or an equivalent entry-level security certification
-
Other relevant certifications considered include CompTIA Network+, ISC2 Certified in Cybersecurity (CC), or equivalent
Technical Skills
-
Foundational understanding of security concepts including vulnerability management, network security, application security, and common attack types
-
Familiarity with OWASP Top 10 or equivalent common vulnerability classifications
-
Basic comfort with Windows and Linux environments
-
Ability to learn and operate enterprise security tools with training and guidance
Competencies (KSA's)
Competencies:
1. Action Oriented
2. Customer Focus
3. Manages Ambiguity
4. Drives Results
5. Tech Savvy
Knowledges:
1. Information security best practices and standards
2. Risk assessment and management principles
3. Security frameworks, policies, and regulatory requirements
4. Disaster recovery and continuity planning processes
5. IT systems and operating environments
Skills:
1. Problem solving and critical thinking
2. Communication and documentation
3. Training and user engagement
4. Vulnerability analysis and threat detection
5. Time management and prioritization
Abilities:
1. Analyze and interpret complex security data
2. Adapt to evolving threats and technologies
3. Coordinate with stakeholders across agencies
4. Communicate effectively in high-pressure situations
5. Maintain focus and accuracy during emergencies
Tools & Equipment
1. Laptop and mobile computing tools
2. Adobe PDF software
3. Microsoft Office Suite
4. SharePoint and ServiceNow
5. Everbridge and security awareness platforms