Cybersecurity Program Manager GRC

Saigepartners

San Jose, Northern (CA, KY)

Hybrid

USD 117,000 - 131,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Saige Partners in San Jose, CA seeks a experienced Cybersecurity Program Manager to lead governance, policy creation, and risk management across the enterprise. You will drive compliance initiatives and partner with IT, Security, Compliance, Legal, and business stakeholders to strengthen security posture.

This W2 contract role demands 10+ years in cybersecurity with strong program leadership, plus the ability to craft security policies and procedures and coordinate across multiple teams.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field.
  • 10+ years of cybersecurity experience with 5+ years in a program management or leadership role.
  • Proven ability to develop IT security policies, standards, and procedures.
  • Experience documenting enterprise security programs and governance.

Responsibilities

  • Lead security governance, policy, and procedure development for enterprise IT.
  • Develop and execute multi-year cybersecurity roadmaps and KPIs.
  • Collaborate with IT, Security, Compliance, Legal, and business leaders.
  • Manage compliance programs for frameworks like NIST CSF, ISO 27001, SOC 2, CMMC.
  • Support audits, risk assessments, and incident response planning.

Skills

Program management leadership
Executive communication
Cybersecurity governance
Policy & standards development
Cross-functional collaboration
NIST CSF
ISO 27001
SOC 2
CMMC
Threat & vulnerability management

Education

Bachelor's degree in Computer Science / Cybersecurity

Job description

Position: Cybersecurity Program Manager - GRC (San Jose, CA)

Job Overview: We are seeking an experienced Cybersecurity Program Manager to lead the development and execution of enterprise-wide cybersecurity governance, compliance, and risk management initiatives. This role will be responsible for establishing cybersecurity programs, creating security policies and standards from the ground up, driving compliance efforts, and partnering with cross-functional stakeholders to strengthen the organization's security posture. The ideal candidate combines deep cybersecurity expertise with strong program management capabilities and a proven track record of developing security governance frameworks, policies, and procedures in complex enterprise environments.

This is a W2 contract position and is not eligible for C2C or W2 referral candidates.

Key Responsibilities:
  • Security Governance, Policy & Procedure Development
    • Lead the development, documentation, and maintenance of enterprise-wide IT security policies, standards, and procedures.
    • Create comprehensive security governance documentation from scratch, ensuring alignment with business objectives and regulatory requirements.
    • Collaborate with IT, Security, Compliance, and business stakeholders to identify policy gaps and define security requirements.
    • Develop and maintain policies covering areas such as access management, data protection, incident response, risk management, and security operations.
    • Establish clear, enforceable standards and implementation guidelines for both technical and non-technical teams.
    • Document detailed operational procedures to ensure consistent execution across departments.
    • Facilitate policy review cycles, stakeholder approvals, and governance processes.
    • Conduct periodic audits of policy compliance and recommend updates based on findings, organizational changes, and emerging threats.
  • Cybersecurity Program Management & Strategy
    • Develop, implement, and maintain enterprise-wide cybersecurity programs aligned with organizational goals and industry best practices.
    • Create and execute multi-year cybersecurity roadmaps and strategic initiatives.
    • Define program objectives, success metrics, and key performance indicators (KPIs) to measure effectiveness.
    • Monitor emerging cybersecurity threats, vulnerabilities, and industry trends to proactively adjust program strategies.
    • Manage cybersecurity program budgets, resources, and project priorities.
  • Cross-Functional Leadership & Governance
    • Partner with IT, Security Operations, Risk Management, Compliance, Legal, and business leadership teams to drive cybersecurity initiatives.
    • Establish governance frameworks, decision-making processes, and accountability structures.
    • Coordinate activities with external vendors, consultants, auditors, and third-party service providers.
    • Communicate complex cybersecurity concepts to both technical and non-technical audiences.
    • Promote a culture of cybersecurity awareness and accountability across the organization.
  • Compliance & Risk Management
    • Ensure compliance with applicable regulatory and industry frameworks, including CCPA, CPRA, SOC 2, CMMC, and related standards.
    • Lead risk assessments, vulnerability management initiatives, and penetration testing programs.
    • Develop and maintain risk management processes and security control frameworks.
    • Monitor and report on organizational security posture and compliance status.
    • Support incident response planning, testing, and coordination during cybersecurity events.
  • Security Program Implementation & Optimization
    • Oversee the evaluation, implementation, and optimization of security technologies, tools, and controls.
    • Conduct security architecture reviews and technology assessments.
    • Drive continuous improvement initiatives across cybersecurity programs and processes.
    • Maintain comprehensive program documentation, operational procedures, and knowledge repositories.
    • Ensure effective documentation management and organizational readiness for audits and assessments.
  • Executive Reporting & Stakeholder Management
    • Provide executive leadership and key stakeholders with regular updates on cybersecurity initiatives, risks, and program performance.
    • Develop dashboards, metrics, and reports to communicate compliance and security effectiveness.
    • Present cybersecurity strategies, findings, and recommendations to senior management and executive leadership.
    • Escalate critical risks, compliance issues, and security concerns as appropriate.
Qualifications:
  • Required
    • Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field.
    • 10+ years of cybersecurity experience, including at least 5 years in a program management, governance, or leadership role.
    • Proven experience developing and implementing IT security policies, standards, and procedures from the ground up.
    • Demonstrated success collaborating with cross-functional teams to create and maintain enterprise security documentation.
    • Strong knowledge of cybersecurity frameworks and standards, including NIST CSF, ISO 27001, CIS Controls, SOC 2, and CMMC.
    • Experience with security governance, compliance management, and risk assessment methodologies.
    • Deep understanding of security controls, threat management, vulnerability management, and security operations.
    • Experience managing complex, enterprise-wide cybersecurity programs and initiatives.
    • Strong project and program management skills with the ability to manage multiple priorities simultaneously.
    • Excellent written, verbal, and executive-level communication skills.
  • Preferred
    • PMP (Project Management Professional) certification or equivalent program management certification.
    • Professional cybersecurity certifications such as CISSP, CISM, CRISC, or similar.
    • Experience supporting highly regulated industries and compliance-driven environments.
    • Familiarity with Agile, Waterfall, and hybrid project management methodologies.
Key Competencies:
  • Cybersecurity Governance
  • Policy & Procedure Development
  • Regulatory Compliance
  • Risk Management
  • Program & Portfolio Management
  • Security Frameworks (NIST, ISO 27001, CIS, SOC 2, CMMC)
  • Executive Communication
  • Cross-Functional Leadership
  • Vendor & Stakeholder Management

Hours you will be work: Monday through Friday; 8 am - 5 pm PST

Compensation you will receive: $85-$95 per hour

Saige Partners, one of the fastest growing technology and talent companies in the Midwest, believes in people with a passion to help them succeed. We are in the business of helping professionals Build Careers, Not Jobs. Saige Partners believes employees are the most valuable asset to building a thriving and successful company culture, which is why we offer a benefit package and convenient weekly payment solutions that helps our employees stay healthy and maintain a positive work/life balance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Enterprise Cybersecurity GRC Program Lead
Enterprise Cybersecurity GRC Program Lead

Saigepartners • San Jose (CA), Northern (KY)

Hybrid
USD 117,000 - 131,000
Cybersecurity Governance Program Manager
Cybersecurity Governance Program Manager

ManpowerGroup Global, Inc. • Charlotte (NC)

On-site
USD 120,000 - 150,000
Manager of Cybersecurity GRC
Manager of Cybersecurity GRC

Kforce Inc • West Valley City (UT)

On-site
USD 130,000 - 180,000
Medical Insurance
Dental Insurance
Vision Insurance
+6
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 54,000 - 90,000
Hybrid work model
Relocation assistance
Certifications support
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Manager, Cybersecurity Risk and Compliance
Manager, Cybersecurity Risk and Compliance

The Judge Group • Trenton (NJ)

Hybrid
USD 140,000 - 170,000
Health benefits and insurance
PTO
401k
Cyber Security Program Manager
Cyber Security Program Manager

Compunnel, Inc. • Durham (NC)

On-site
USD 100,000 - 130,000
IT Security GRC Analyst
IT Security GRC Analyst

The Phoenix Group • Charlotte (NC)

On-site
USD 85,000 - 120,000
Sr. Cybersecurity GRC Analyst (Remote)
Sr. Cybersecurity GRC Analyst (Remote)

TPx • United States

On-site
USD 105,000 - 145,000
Cybersecurity Governance Manager
Cybersecurity Governance Manager

CalNonprofits Insurance Services (CNIS) • United States

Hybrid
USD 120,000 - 160,000