Director, Cyber Security Risk Management, Infrastructure Protection at CHS
Franklin, TN
—
Jul 21, 2026
Franklin, TN
Jul 23, 2026
What this job asks for AI summary
A senior leadership role responsible for directing an enterprise-wide infrastructure protection program covering network, endpoint, and cloud security domains. The position oversees a team of managers and engineers, drives strategy and delivery across a broad set of security technologies, and reports to the CISO. It suits an experienced cybersecurity leader with a background in managing large-scale programs, risk assessments, and cross-functional stakeholder relationships.
Principal level · 8+ years · Bachelor's required · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Rare in this occupation — lead with these, and say what you built with them.
What the occupation pays Median $178,991 (middle half $141,096–$225,584).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 29, 2026. It is a model, not a headcount.
Why we read it this way (8)
No work location is specified in the posting; CBSA/state fields are left blank. The role requires occasional travel and on-call availability, suggesting an on-site or hybrid expectation rather than fully remote.
This is a Director-level people-management role reporting to the CISO, overseeing managers and engineers across multiple cybersecurity programs — classified as 11-3021 (Computer and Information Systems Managers). 15-1212 is noted as a runner-up given the deep security domain focus, but the primary day-to-day work is leading and managing teams and programs.
Seniority is assessed as Principal: this is a Director reporting directly to the CISO, sitting on the Senior Cybersecurity Leadership Team with org-wide strategic authority — well above a typical Senior manager scope.
The infrastructure technology areas (Network Firewalls, EDR, CSPM, etc.) are drawn from the role's stated scope of responsibility in the job body rather than a formal 'Required Skills' section. They are marked required because the JD explicitly states the Director 'leads all facets of the program' and has 'oversight of planning, build, implementation, and operation' across these specific platforms.
NIST/ISO 27001 are listed under Knowledge, Skills and Abilities with 'expert knowledge' language — treated as a hard gate; ISO 27001 is captured as an alternative since the JD presents them together as a framework category.
All certifications (CISSP, CISM, GSEC, GIAC, Security+, SSCP, OSCP, ITIL) are explicitly listed as preferred; grouped into one preferred skill entry with alternatives.
Master's degree is explicitly preferred, not required; minimum hard requirement is a Bachelor's degree.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Cloud Security Posture Management.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.