Information Security Program Manager

Mainstay Technologies

Manchester (NH)

On-site

USD 120,000 - 180,000

Full time

8 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health Insurance
401(k) with match
Employee Stock Ownership Plan (ESOP)

Job summary

Mainstay Technologies is seeking an Information Security Program Manager to serve as strategic security advisor and governance lead for assigned clients in the New England area, focusing on CMMC, NIST, risk management, and policy development.

You'll work with clients, technical teams, security operations, assessors, and executives to ensure security programs align with business goals and compliance requirements, delivering measurable outcomes.

Qualifications

  • Experience supporting CMMC readiness initiatives.
  • Experience assisting clients through audits or certification assessments.
  • Experience in consulting or managed services environments.
  • Experience presenting to executive leadership teams.
  • Preferred Certifications: CISA, CISM, CCP, CISSP.

Responsibilities

  • Lead client governance meetings and security program reviews.
  • Develop and manage client security roadmaps and strategic initiatives.
  • Provide security guidance to executives and stakeholders.
  • Track program goals, milestones, and initiatives.
  • Coordinate activities between clients, technical teams, security operations, and partners.

Skills

CMMC readiness experience
Audit and certification readiness
Executive leadership communication
Consulting/Managed services experience
Security governance & risk management

Education

CISA
CISM
CMMC Certified Professional (CCP)
CISSP

Job description

The Information Security Program Manager (ISPM) serves as a strategic security advisor and primary governance lead for assigned clients.The ISPM is responsible for developing, managing, and maturing client information security programs with a strong emphasis on Cybersecurity Maturity Model Certification (CMMC), NIST compliance, risk management, governance, policy development, and assessment readiness.

This position works closely with clients, technical teams, Security Operations personnel, external assessors, and executive leadership to ensure security programs align with business objectives, compliance obligations, and industry best practices.The ISPM serves as a trusted advisor to client leadership and is accountable for the successful execution of security governance activities, compliance initiatives, risk management processes, and security program outcomes.

What You’ll Do
Security Program Leadership & Governance

Serve as the primary advisor and governance lead for assigned clients.

Responsibilities
  • Lead client governance meetings and security program reviews.
  • Develop and manage client security roadmaps and strategic initiatives.
  • Provide security guidance to executive leadership and key stakeholders.
  • Track program goals, projects, milestones, and security initiatives.
  • Coordinate activities between clients, technical teams, security operations, and third-party partners.
  • Present security posture, compliance status, risks, and recommendations to client leadership.
  • Drive continuous improvement of client security programs.
CMMC, Compliance & Assessment Management

Lead compliance initiatives with a focus on CMMC readiness and regulatory alignment.

Responsibilities
  • Serve as a subject matter expert on CMMC, NIST 800-171, HIPAA, and related security frameworks.
  • Conduct compliance assessments, gap analyses, and readiness reviews.
  • Interpret security, regulatory, and contractual requirements.
  • Develop remediation plans to address compliance gaps.
  • Guide clients through CMMC assessment preparation and readiness activities.
  • Coordinate evidence collection, assessment planning, and audit support.
  • Stay current on evolving compliance requirements and industry best practices.
  • Provide compliance recommendations and implementation guidance.
Risk Management & Security Advisory

Lead risk management and security improvement initiatives.

Responsibilities
  • Conduct security risk assessments and program reviews.
  • Maintain oversight of client risk registers and remediation activities.
  • Identify, evaluate, and prioritize business, operational, and security risks.
  • Develop risk treatment and mitigation recommendations.
  • Facilitate risk review discussions and risk acceptance decisions.
  • Provide strategic recommendations to improve security maturity and resilience.
  • Support vulnerability, application, vendor, and operational risk review activities.
Security Program Documentation & Control Management

Ensure security programs are properly documented, maintained, and aligned with requirements.

Responsibilities
  • Develop and maintain:
    • System Security Plans (SSP)
    • Written Information Security Programs (WISP)
    • Plans of Action & Milestones (POA&M)
    • Policies, Procedures, and Standards
    • Governance and assessment documentation
  • Align documentation with implemented controls and compliance requirements.
  • Maintain traceability between requirements, risks, controls, findings, and remediation activities.
  • Review and update documentation based on regulatory, business, and technology changes.
  • Support standardization and continuous improvement of security program documentation.
Security Operations Support, Training & Incident Management

Support and strengthen ongoing client security operations and preparedness.

Responsibilities
  • Lead security awareness and compliance training initiatives.
  • Facilitate tabletop exercises and security program testing.
  • Oversee incident response planning and program readiness.
  • Participate in significant security incidents as an advisor and coordinator.
  • Conduct post-incident reviews and lessons-learned activities.
  • Ensure incidents, findings, and corrective actions are incorporated into risk management and governance processes.
  • Support application security reviews, vendor risk reviews, and continuous monitoring initiatives.
  • Promote security best practices across client organizations.
Your Background
  • Experience supporting CMMC readiness initiatives.
  • Experience assisting clients through audits or certification assessments.
  • Experience in consulting or managed services environments.
  • Experience presenting to executive leadership teams.
  • Preferred Certifications:
    • CISA
    • CISM
    • CMMC Certified Professional (CCP)
    • CISSP
Skills for Success
  • Creative problem-solving skills with the ability to take multiple components and pull them together into recommendations
  • Strong decision-making skills and comfortable in situations where there is no “right” answer
  • Strong organization and project management skills
  • Business acumen—understanding business process, data flows, and system application use in a variety of business settings
  • Technical aptitude— the ability to understand technical concepts, tools, and the IT landscape
  • Strong written and oral communication skills with the ability to coordinate and run successful meetings
  • Life-long learner with a growth mindset that enjoys the pursuit of knowledge and is eager to stay updated in security policies and skill
Physical Requirements
  • Prolonged periods of sitting at a desk and working on a computer.
  • Must be able to lift 15 pounds at times.
  • Travel between offices and to client sites
About Mainstay

Mainstay Technologies - IT you trust from a team you enjoy. Mainstay Technologies provides a full IT and Information Security department to small and medium size businesses in the northern New England area. As a company in the Best Companies to Work For Hall of Fame, we believe in using the power of technology and of business to help people flourish. This translates to a culture of caring, high-ownership teammates who work hard, enjoy each other immensely, and turn off the work at the end of the workday, to focus on what matters more than work.

It is our commitment to people that makes us who we are. We love what we do, and we love who we do it with. We are driven by our mission: to give more than we get. People are always the ends, never the means. In addition to being a Best Company to Work For, we have also been recognized for Coolest Companies for Young Professionals, “Best of Business” for Managed IT Services, and theTorch Award for Marketplace Ethics. We have made theInc. 500 | 5000 Listfor fastest growing small businesses 5 times.

Benefits
  • A flexible and fun work environment with events, lunch+ learns, ping pong, snacks, games, and books
  • 3 weeks of PTO (4 weeks after 2 years) per year
  • A 2-week sabbatical at 5 years and a 5-week sabbatical at 10 years
  • Health, Dental, and Vision Insurance
  • Disability Insurance
  • Group and Supplemental Life Insurance
  • Paid Family Leave
  • 401(k) with 3% match
  • ESOP!
  • Team Profit Sharing
  • Training program (including paid certifications, tuition reimbursement, and bonuses on achieving certs)
  • Paid Volunteer Time Off
Location

We believe in Work-from-Anywhere and in the value of in-person relationships. We offer strong flexibility to work remotely, while also recognizing the importance of face-to-face connection through team meetings, all-staff gatherings, and in-person client meetings.

We maintain a beautiful office in Manchester, NH, as well as a satellite office in Laconia, and we encourage each team member to choose the mix of home and in-office work that best supports their wellbeing and effectiveness. While coming into the office weekly is encouraged, it is not required.

Because this role includes regular in-person client meetings, applicants must live within driving distance of our clients, offices, and team events to support client relationships, onboarding, and ongoing collaboration.

This description cannot encompass all tasks and could change at any time. Other duties as assigned may be required to achieve Mainstay’s vision, mission, and core values.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior InfoSec Program Manager: CMMC & Compliance (Remote)
Senior InfoSec Program Manager: CMMC & Compliance (Remote)

Mainstay Technologies • Manchester (NH)

Hybrid
USD 120,000 - 180,000
Health Insurance
401(k) with match
Employee Stock Ownership Plan (ESOP)
C&IS Portfolio and Program Manager
C&IS Portfolio and Program Manager

Point32Health • Town of Canton (NY)

On-site
USD 155,000 - 233,000
Medical, dental & vision coverage
Retirement plans
Paid time off
+4
Technical Program Manager
Technical Program Manager

ComputerCare • Stockton (CA)

On-site
USD 105,000 - 125,000
Medical
Dental
Vision
+7
Security and Compliance Engineer, IT - CMMC/NIST SP 800-171
Security and Compliance Engineer, IT - CMMC/NIST SP 800-171

Technical Support International • Massachusetts

On-site
USD 120,000 - 150,000
Health and dental
Life Insurance
Paid time off
+2
IT Support Services Program Manager (Contract Contingent)
IT Support Services Program Manager (Contract Contingent)

ProSidian Consulting, LLC • Maryland

On-site
USD 100,000 - 130,000
Group Health Insurance
401(k) Retirement Savings Plan
Paid Time Off (PTO)
+2
Client Success Manger
Client Success Manger

Sourcepass • Connecticut

Hybrid
USD 70,000 - 100,000
C&IS Portfolio and Program Manager
C&IS Portfolio and Program Manager

P32HS Point32Health Services Inc • Canton (MA)

On-site
USD 155,000 - 233,000
Medical, dental and vision coverage
Retirement plans
Paid time off
+4
Program Security Manager
Program Security Manager

Metrea • Washington

On-site
USD 150,000 - 210,000
Comprehensive medical plan options
HSA/FSA accounts
Dental and vision coverage
+8
Cybersecurity, AVP - Technical Delivery Manager
Cybersecurity, AVP - Technical Delivery Manager

State Street • Quincy (MA)

Hybrid
USD 90,000 - 158,000
401K with company match
Medical insurance
Dental insurance
+2
IT Consultant (Boston) Boston, Massachusetts, United States
IT Consultant (Boston) Boston, Massachusetts, United States

Pliancy • Boston (MA), Northern (KY)

Hybrid
USD 75,000 - 85,000
Healthcare premiums 100% for employees
Dependent coverage option
Unlimited PTO
+4