Cybersecurity Program Manager

Carex Consulting Group

Madison (WI)

On-site

USD 125,000 - 170,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Carex Consulting Group is seeking a Cybersecurity Program Manager to transform assessment findings into an executable, governed program. You will lead a multi-workstream transformation aligned with federal healthcare requirements.

You will build roadmaps, governance, and reporting to executives, manage dependencies, and coordinate across cyber resilience functions, audits, and compliance efforts. The role aims to mature security and prepare handoff to an internal PMO.

Qualifications

  • Minimum of 8 years of program or project management experience, including at least 5 years in cybersecurity programs.

Responsibilities

  • Own program management for the cybersecurity transformation portfolio, including planning, sequencing, dependency management, milestone tracking, and critical path management.
  • Build and maintain a multi-year cybersecurity transformation roadmap, integrated program plan, and RAID log.
  • Convert identified cybersecurity assessment gaps into a prioritized remediation register.
  • Normalize and validate security gaps with named owners and map remediation activities to NIST CSF, NIST SP 800-53, and Section 912 controls.
  • Design and operate a cybersecurity metrics and reporting framework showing maturity and risk reduction.
  • Produce executive and board-grade transformation reporting materials.
  • Establish lightweight program governance with forums, agendas, and decision capture.
  • Coordinate transformation activities across Enterprise Cyber Resilience functions.
  • Align roadmap with annual Section 912 audit cycle for efficient planning and execution.
  • Build a capacity model to support evidence-based staffing and budget decisions.
  • Create a sustainable governance model with clear ownership and decision rights.
  • Develop a wave-sequenced, multi-year plan reflecting priorities and constraints.
  • Ensure metrics and reporting use live data across cycles.
  • Return capacity to Enterprise Security leadership by driving program operations and follow-through.

Skills

Program management
Cybersecurity governance
NIST CSF
FISMA/HIPAA
Audits & reporting

Job description

Carex is partnering with a Insuranceindustry partner to hire a Cybersecurity Program Manager to turn cybersecurity assessment findings into an executable, measurable, and governed transformation program. This role will build the roadmap, metrics, governance, and operating discipline required to manage a complex, multi-workstream cybersecurity transformation within a federally regulated healthcare environment.

The Cybersecurity Program Manager will provide dedicated program management capacity to Enterprise Security leadership, translating identified security gaps into prioritized remediation efforts and ensuring initiatives are sequenced, owned, measured, and aligned with regulatory obligations. The environment operates under federal and healthcare security requirements, including FISMA, NIST SP 800-53, HIPAA, and independent information security program evaluations conducted under Section 912 of the Medicare Prescription Drug, Improvement, and Modernization Act.

Success in this role means establishing a transformation program with a sustainable operating cadence, producing executive and board-grade reporting, improving visibility into maturity and risk reduction, and ultimately transitioning the established program to an internal Project Management Office.

What You'll Do
  • Own program management for the cybersecurity transformation portfolio, including planning, sequencing, dependency management, milestone tracking, and critical path management.
  • Build and maintain a multi-year cybersecurity transformation roadmap, integrated program plan, and RAID log.
  • Convert identified cybersecurity assessment gaps into a single, prioritized, owned, and dependency-mapped remediation register.
  • Normalize and validate security gaps with named owners and map remediation activities to relevant NIST Cybersecurity Framework, NIST SP 800-53, and applicable Section 912 control areas.
  • Design, build, and operate a cybersecurity metrics and reporting framework that measures maturity improvement and risk reduction using available organizational data.
  • Produce executive, leadership, and Audit Committee reporting materials, including board-grade cybersecurity transformation reporting.
  • Establish and operate lightweight program governance, including forums, agendas, decision capture, accountability mechanisms, and follow-through without creating unnecessary administrative burden.
  • Coordinate transformation activities across Enterprise Cyber Resilience functions spanning cyber risk and assurance, business enablement, compliance, trust and architecture, and threat management.
  • Align the cybersecurity transformation roadmap with the annual Section 912 audit cycle so remediation activities can be efficiently planned, executed, and evidenced.
  • Build a resource and capacity model that supports evidence-based staffing and budget decisions.
  • Establish a program charter and sustainable governance model that enables clear ownership, decision-making, and execution.
  • Develop and manage a wave-sequenced, multi-year transformation plan that reflects priorities, dependencies, capacity constraints, regulatory obligations, and risk.
  • Ensure metrics and reporting operate through repeatable collection and reporting cycles using live data.
  • Return meaningful capacity to Enterprise Security leadership by independently driving program operations, coordination, reporting, and follow-through.
  • Maintain appropriate separation between transformation program management and operational cybersecurity responsibilities, including audit ownership, security architecture and engineering decisions, incident response, security tool administration, vendor operations, and control approval responsibilities.
  • Prepare and execute comprehensive knowledge transfer and transition of the established transformation program to the internal Project Management Office.
What You'll Bring
  • Minimum of 8 years of program or project management experience, including at least 5 years specifically managing cybersecurity programs.
  • Demonstrated ownership of at least one cybersecurity transformation or security maturity improvement program from assessment findings and roadmap development through execution.
  • Working fluency in the NIST Cybersecurity Framework and NIST SP 800-53, including the ability to independently interpret security control findings.
  • Experience operating within FISMA, HIPAA, federal healthcare, or similarly regulated security environments.
  • Experience building cybersecurity metrics, Key Risk Indicator (KRI) frameworks, and related measurement programs and operating them through repeated reporting cycles.
  • Demonstrated experience producing cybersecurity or transformation reporting consumed by executive committees, Audit Committees, boards, or comparable senior leadership groups.
  • Experience delivering complex programs in regulated environments subject to external audits and assessments.
  • Strong program governance, risk management, dependency orchestration, critical path management, and change control capabilities.
  • Ability to translate cybersecurity assessment findings into structured, prioritized, measurable, and actionable transformation initiatives.
  • Excellent communication, stakeholder management, and negotiation skills across technical, business, executive, and compliance audiences.
  • Experience leading complex transformation initiatives through ambiguity and competing priorities.
  • Experience transitioning an established program to an internal PMO or similar delivery organization.
  • Direct experience supporting a Medicare Administrative Contractor, federal healthcare contractor, or another FISMA-regulated organization is preferred.
  • Familiarity with CMS information security requirements and the MMA Section 912 evaluation process is preferred.
  • Familiarity with CMMC is preferred.
  • CISSP, CISM, or CRISC certification is preferred.
  • Proficiency across multiple execution methodologies, including Agile, with familiarity with scaled delivery frameworks preferred.
  • PMP, CSM, SAFe, LeSS, PgMP, and/or PfMP certification is preferred.

Carex Consulting Group is an equal opportunity employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender identity, or Veteran status.#LI-WR1

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Strategic Cybersecurity Transformation Lead
Strategic Cybersecurity Transformation Lead

Carex Consulting Group • Madison (WI)

On-site
USD 125,000 - 170,000
Cyber Security Program Manager
Cyber Security Program Manager

Compunnel, Inc. • Durham (NC)

On-site
USD 100,000 - 130,000
Program Manager
Program Manager

ECS • Richmond (VA)

Hybrid
USD 190,000 - 210,000
Cybersecurity Program Manager – Controls Testing
Cybersecurity Program Manager – Controls Testing

Kaizen Lab Inc. • Richmond (VA)

On-site
USD 140,000 - 190,000
Chief Information Security Officer (CISO) | PAM Health Corporate
Chief Information Security Officer (CISO) | PAM Health Corporate

PAM Health • Plano (TX)

Hybrid
USD 150,000 - 200,000
Project Manager
Project Manager

Compunnel, Inc. • Philadelphia

On-site
USD 90,000 - 120,000
Cybersecurity Program Manager GRC
Cybersecurity Program Manager GRC

Saigepartners • San Jose (CA), Northern (KY)

Hybrid
USD 117,000 - 131,000
Cybersecurity Project Manager
Cybersecurity Project Manager

Brooksource • United States

On-site
USD 140,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+3
Senior Project Manager
Senior Project Manager

Concero • Missouri

On-site
USD 90,000 - 150,000
Cybersecurity Manager
Cybersecurity Manager

BMA Group Global • Guaynabo (PR)

On-site
USD 120,000 - 190,000