Info Security Program Manager

Columbia University

New York (NY)

On-site

USD 120,000 - 145,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Columbia University in New York seeks an Information Security Program Manager to lead enterprise cybersecurity programs and strategic initiatives. You will report to the CISO and drive planning, governance, and execution to strengthen security posture in a regulated academic environment.

The role requires strong leadership, communication, and experience managing complex cross-functional security initiatives.

Qualifications

  • Bachelor's degree or equivalent; 5 years in related roles.
  • 3+ years leading enterprise cybersecurity programs.
  • Experience presenting updates to executive leadership.
  • Healthcare, higher education, or regulated industry experience.

Responsibilities

  • Coordinate planning, execution, governance, and delivery of enterprise cybersecurity programs.
  • Collaborate with the CISO to develop and execute the cybersecurity roadmap.
  • Drive governance, reporting, metrics, and executive dashboards for program health.
  • Coordinate cross-functional teams across CUIMC.
  • Manage scope, budgets, schedules, resources, risks, issues, dependencies, and communications.
  • Participate in cybersecurity governance activities including steering committees.
  • Ensure initiatives comply with policies and regulatory frameworks.
  • Develop program documentation: charters, roadmaps, risk registers, plans.
  • Collaborate to prioritize cybersecurity investments based on risk.
  • Identify opportunities to improve cybersecurity processes and maturity.
  • Serve as InfoSec representative for enterprise transformations.

Skills

Cybersecurity program management
Portfolio management
Executive communication
Stakeholder management
Risk assessment
Analytical thinking

Education

Bachelor's degree or equivalent
Preferred: Information Security / CS / IT / related

Tools

PMP
CISSP
CISM
CRISC

Job description

  • Job Type: Officer of Administration
  • Bargaining Unit:
  • Regular/Temporary: Regular
  • End Date if Temporary:
  • Hours Per Week: 35
  • Standard Work Schedule:
  • Building:
  • Salary Range: $120,000 - $145,000

The salary of the finalist selected for this role will be set based on a variety of factors, including but not limited to departmental budgets, qualifications, experience, education, licenses, specialty, and training. The above hiring range represents the University's good faith and reasonable estimate of the range of possible compensation at the time of posting.

Position Summary

Reporting directly to the Chief Information Security Officer (CISO), the Information Security Program Manager is responsible for leading and coordinating a portfolio of enterprise cybersecurity programs and strategic initiatives that strengthen the organization's overall security posture. This role serves as a trusted advisor to the CISO, driving the planning, governance, execution, and continuous improvement of cybersecurity initiatives while ensuring alignment with organizational priorities, regulatory requirements, and industry best practices.

The successful candidate will possess a strong background in cybersecurity program management, exceptional leadership and communication skills, and demonstrated experience managing complex cross-functional security initiatives within a large healthcare, academic, or similarly regulated environment.

Responsibilities
  • Coordinate the planning, execution, governance, and delivery of a portfolio of enterprise cybersecurity programs and strategic initiatives.
  • Engage with the CISO to develop and execute the organization's cybersecurity roadmap, ensuring alignment with business objectives, regulatory requirements, and risk management priorities.
  • Drive program governance, reporting, metrics, and executive dashboards to communicate program health, milestones, risks, dependencies, and overall security maturity.
  • Coordinate cross-functional teams across CUIMC
  • Manage program scope, budgets, schedules, resources, risks, issues, dependencies, and communications across multiple concurrent initiatives.
  • Third-Party Risk Management
  • Participate in cybersecurity governance activities, including steering committees, executive briefings, status reporting, and program reviews.
  • Ensure cybersecurity initiatives comply with organizational policies and applicable regulatory and industry frameworks.
  • Develop and maintain program documentation, including charters, roadmaps, project plans, risk registers, communication plans, executive presentations, and lessons learned.
  • Collaborate with technology and business leaders to prioritize cybersecurity investments based on organizational risk.
  • Identify opportunities to improve cybersecurity processes, operational efficiency, and program maturity.
  • Serve as the Information Security representative for major enterprise transformation initiatives.
Essential Functions:
Cybersecurity Program Leadership and Delivery – 60%
  • Implement strategic cybersecurity programs from initiation through adoption while ensuring delivery within scope, schedule, budget, and quality expectations.
Cybersecurity Governance and Stakeholder Management – 30%
  • Coordinate governance activities, executive reporting, risk management, and cross-functional collaboration to support enterprise cybersecurity objectives.
Continuous Improvement and Other Duties – 10%
  • Drive continuous improvement of cybersecurity program management processes, reporting, and operational maturity while performing other duties as assigned.
  • Perform other related duties and responsibilities as assigned/requested.
Minimum Qualifications
  • Bachelor's degree or equivalent in education and experience, plus five years of related experience.
Preferred Qualifications
  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, Business, or a related discipline, or equivalent combination of education and experience.
  • Minimum of 3 years of progressively responsible experience managing enterprise cybersecurity programs, security projects, or information security initiatives.
  • Demonstrated experience leading large, cross-functional cybersecurity initiatives from planning through implementation.
  • Experience presenting program updates, risks, and strategic recommendations to executive leadership.
  • Project Management Professional (PMP), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or comparable certification preferred.
  • Experience within healthcare, higher education, or other highly regulated industries.
  • Strong understanding of cybersecurity governance, risk management, and compliance programs.
  • Experience implementing or managing enterprise cybersecurity technologies
  • Experience supporting enterprise risk assessments, security audits, and regulatory compliance initiatives.
  • Working knowledge of cybersecurity frameworks and standards including:
    • NIST Cybersecurity Framework (CSF)
    • NIST 800-53
    • NIST 800-171
    • HITRUST
    • HIPAA/HITECH
    • ISO 27001
    • CIS Controls
Required Competencies
  • Strong cybersecurity program and portfolio management skills.
  • Demonstrated leadership managing multiple concurrent enterprise initiatives.
  • Excellent stakeholder management and executive communication skills.
  • Ability to influence without direct authority across multidisciplinary teams.
  • Strong analytical, organizational, and problem-solving capabilities.
  • Experience developing executive dashboards, KPIs, and program metrics.
  • Ability to identify and proactively mitigate program risks and dependencies.
  • Excellent written communication skills, including executive presentations, governance documentation, and strategic planning materials.
  • Knowledge of Agile, Waterfall, and hybrid delivery methodologies.
Equal Opportunity Employer / Disability / Veteran

Columbia University is committed to the hiring of qualified local residents.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Info Security Program Manager
Info Security Program Manager

Columbia University Irving Medical Center • New York (NY)

On-site
USD 120,000 - 145,000
InfoSec Program Manager: Enterprise Cybersecurity Lead
InfoSec Program Manager: Enterprise Cybersecurity Lead

Columbia University Irving Medical Center • New York (NY)

On-site
USD 120,000 - 145,000
C&IS Portfolio and Program Manager
C&IS Portfolio and Program Manager

P32HS Point32Health Services Inc • Canton (MA)

On-site
USD 155,000 - 233,000
Medical, dental and vision coverage
Retirement plans
Paid time off
+4
Chief Information Security Officer (CISO) | PAM Health Corporate
Chief Information Security Officer (CISO) | PAM Health Corporate

PAM Health • Plano (TX)

Hybrid
USD 150,000 - 200,000
Director of Cyber Security
Director of Cyber Security

UT Medical • Knoxville (TN)

On-site
USD 180,000 - 280,000
C&IS Portfolio and Program Manager
C&IS Portfolio and Program Manager

Point32Health • Town of Canton (NY)

On-site
USD 155,000 - 233,000
Medical, dental & vision coverage
Retirement plans
Paid time off
+4
Manager of Information Security
Manager of Information Security

The Intersect Group • United States

On-site
USD 140,000 - 200,000
Director Chief Information Security Officer
Director Chief Information Security Officer

The Security Executive Council • Montana

On-site
USD 130,000 - 180,000
Program Manager, Data Sciences
Program Manager, Data Sciences

Columbia University Irving Medical Center • New York (NY)

On-site
USD 91,000 - 110,000
Cybersecurity Program Manager
Cybersecurity Program Manager

Carex Consulting Group • Madison (WI)

On-site
USD 125,000 - 170,000