Cybersecurity Program & Policy Management Leader
Position Overview
We are seeking an experienced cybersecurity leader to establish, manage, and continuously improve the organization’s enterprise-wide cybersecurity program. This role will be responsible for building security governance, developing comprehensive IT security policies and standards, driving compliance and risk management initiatives, and aligning cybersecurity strategy with business objectives.
The ideal candidate brings a strong combination of cybersecurity expertise, policy development experience, program leadership, risk management, and the ability to communicate effectively with both technical teams and executive stakeholders.
Key Responsibilities
Security Policy, Standards & Procedure Development
- Lead the development, implementation, and maintenance of enterprise-wide IT and cybersecurity policies, standards, and procedures.
- Build comprehensive security documentation from the ground up and identify gaps within existing policies and processes.
- Partner with IT, Security, Risk, Compliance, and business teams to define policy requirements and implementation procedures.
- Develop policies covering critical security domains, including access control, data protection, incident response, vulnerability management, and other key areas.
- Ensure policies and standards align with applicable regulatory requirements, industry frameworks, and cybersecurity best practices.
- Establish clear, practical, and enforceable standards that can be understood and adopted by both technical and non-technical stakeholders.
- Create detailed procedures and implementation guidelines to promote consistent execution across departments.
- Manage policy review cycles, stakeholder feedback, approvals, updates, and ongoing maintenance.
- Conduct periodic reviews and compliance assessments and incorporate audit findings, organizational changes, and emerging threats into policy updates.
Cybersecurity Program Strategy & Management
- Develop, establish, and manage an enterprise-wide cybersecurity program aligned with organizational goals and industry best practices.
- Create and execute multi-year cybersecurity strategies, roadmaps, and improvement plans.
- Define program objectives, milestones, KPIs, and metrics to measure program performance and effectiveness.
- Monitor emerging cybersecurity threats, technology trends, and regulatory developments and adjust program priorities accordingly.
- Manage program budgets, resources, timelines, and priorities to ensure effective execution of strategic initiatives.
- Drive continuous improvement across cybersecurity processes, controls, technologies, and governance practices.
Cross-Functional Leadership & Governance
- Lead collaboration across IT, Security Operations, Risk Management, Compliance, Legal, and business leadership teams.
- Establish cybersecurity governance frameworks, decision-making processes, and accountability structures.
- Coordinate with external vendors, consultants, auditors, and third-party service providers.
- Serve as a bridge between technical and business stakeholders, ensuring cybersecurity priorities and requirements are clearly communicated.
- Promote cybersecurity awareness and help strengthen a security-focused culture across the organization.
Compliance & Risk Management
- Ensure alignment with applicable regulatory and compliance requirements, including CCPA, CPRA, SOC 2, CMMC, and other relevant frameworks.
- Lead and oversee cybersecurity risk assessments, vulnerability assessments, and penetration testing initiatives.
- Evaluate security risks and control effectiveness and develop remediation strategies where necessary.
- Monitor and report on the organization’s overall security posture, compliance status, and key risk areas.
- Provide executive leadership and, when appropriate, the Board with clear visibility into cybersecurity risks, program performance, and compliance initiatives.
- Lead incident response planning and support cross-functional coordination during cybersecurity incidents.
Security Implementation & Optimization
- Oversee the evaluation, design, deployment, and optimization of cybersecurity tools, technologies, and controls.
- Participate in security architecture reviews and technology assessments to ensure alignment with organizational security requirements.
- Identify opportunities to improve operational efficiency, control effectiveness, and overall program maturity.
- Maintain clear documentation for program processes, operational procedures, standards, and knowledge management.
Reporting & Stakeholder Management
- Provide regular updates to executive leadership on cybersecurity program progress, risks, priorities, and achievements.
- Develop and present cybersecurity metrics, dashboards, compliance reports, and risk summaries.
- Clearly communicate regulatory requirements and business implications to relevant stakeholders.
- Identify, elevate, and help resolve critical cybersecurity risks and issues.
- Build strong relationships with internal leadership and external stakeholders to support successful program execution.
Qualifications & Requirements
- 10+ years of experience in cybersecurity, information security, or a related field, including at least 5 years in a cybersecurity program management, governance, or leadership role.
- Proven experience developing and implementing IT security policies, standards, and procedures from the ground up.
- Demonstrated ability to identify policy gaps and partner with technical and business teams to create effective security documentation and governance processes.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field; equivalent experience may be considered.
- Strong knowledge of cybersecurity frameworks and standards, including NIST CSF, ISO 27001, CIS Controls, SOC 2, and CMMC.
- Deep experience in cybersecurity governance, risk management, compliance, and policy development.
- Strong understanding of security controls, threat modeling, vulnerability management, and risk assessment methodologies.
- Experience managing complex, enterprise-wide cybersecurity initiatives and multiple concurrent workstreams.
- Knowledge of program and project management methodologies, including Agile and Waterfall.
- PMP or a comparable project or program management certification is preferred.
- Excellent communication, stakeholder management, leadership, and executive presentation skills.
- Ability to translate complex cybersecurity and compliance requirements into clear, actionable guidance for both technical and non-technical audiences.