Senior Cybersecurity Program Manager (No C2C)

Spanidea

San Jose (CA)

On-site

USD 180,000 - 240,000

Full time

4 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Spanidea is seeking a Cybersecurity Program & Policy Management Leader to establish and continuously improve enterprise-wide cybersecurity programs. You will build governance, develop policies and standards, and drive risk management in collaboration with IT, Risk, Compliance and business teams.

The role requires extensive leadership, policy development experience, and the ability to communicate complex security concepts to technical staff and executives alike.

Qualifications

  • 10+ years in cybersecurity, info security, or related field with leadership in programs.
  • Experience building IT security policies, standards, and procedures from ground up.
  • Ability to translate complex security and compliance requirements for diverse audiences.

Responsibilities

  • Lead enterprise-wide cybersecurity program alignment with business goals.
  • Develop, implement, and maintain security policies, standards, and procedures.
  • Establish governance frameworks, risk management, and regulatory compliance (CCPA, SOC 2, CMMC).
  • Communicate cybersecurity risk and program status to executives and the Board.

Skills

Communication
Leadership
Stakeholder management
Executive presentation

Education

Bachelor's degree in Computer Science, Cybersecurity, Information Technology

Job description

Cybersecurity Program & Policy Management Leader
Position Overview

We are seeking an experienced cybersecurity leader to establish, manage, and continuously improve the organization’s enterprise-wide cybersecurity program. This role will be responsible for building security governance, developing comprehensive IT security policies and standards, driving compliance and risk management initiatives, and aligning cybersecurity strategy with business objectives.

The ideal candidate brings a strong combination of cybersecurity expertise, policy development experience, program leadership, risk management, and the ability to communicate effectively with both technical teams and executive stakeholders.

Key Responsibilities
Security Policy, Standards & Procedure Development
  • Lead the development, implementation, and maintenance of enterprise-wide IT and cybersecurity policies, standards, and procedures.
  • Build comprehensive security documentation from the ground up and identify gaps within existing policies and processes.
  • Partner with IT, Security, Risk, Compliance, and business teams to define policy requirements and implementation procedures.
  • Develop policies covering critical security domains, including access control, data protection, incident response, vulnerability management, and other key areas.
  • Ensure policies and standards align with applicable regulatory requirements, industry frameworks, and cybersecurity best practices.
  • Establish clear, practical, and enforceable standards that can be understood and adopted by both technical and non-technical stakeholders.
  • Create detailed procedures and implementation guidelines to promote consistent execution across departments.
  • Manage policy review cycles, stakeholder feedback, approvals, updates, and ongoing maintenance.
  • Conduct periodic reviews and compliance assessments and incorporate audit findings, organizational changes, and emerging threats into policy updates.
Cybersecurity Program Strategy & Management
  • Develop, establish, and manage an enterprise-wide cybersecurity program aligned with organizational goals and industry best practices.
  • Create and execute multi-year cybersecurity strategies, roadmaps, and improvement plans.
  • Define program objectives, milestones, KPIs, and metrics to measure program performance and effectiveness.
  • Monitor emerging cybersecurity threats, technology trends, and regulatory developments and adjust program priorities accordingly.
  • Manage program budgets, resources, timelines, and priorities to ensure effective execution of strategic initiatives.
  • Drive continuous improvement across cybersecurity processes, controls, technologies, and governance practices.
Cross-Functional Leadership & Governance
  • Lead collaboration across IT, Security Operations, Risk Management, Compliance, Legal, and business leadership teams.
  • Establish cybersecurity governance frameworks, decision-making processes, and accountability structures.
  • Coordinate with external vendors, consultants, auditors, and third-party service providers.
  • Serve as a bridge between technical and business stakeholders, ensuring cybersecurity priorities and requirements are clearly communicated.
  • Promote cybersecurity awareness and help strengthen a security-focused culture across the organization.
Compliance & Risk Management
  • Ensure alignment with applicable regulatory and compliance requirements, including CCPA, CPRA, SOC 2, CMMC, and other relevant frameworks.
  • Lead and oversee cybersecurity risk assessments, vulnerability assessments, and penetration testing initiatives.
  • Evaluate security risks and control effectiveness and develop remediation strategies where necessary.
  • Monitor and report on the organization’s overall security posture, compliance status, and key risk areas.
  • Provide executive leadership and, when appropriate, the Board with clear visibility into cybersecurity risks, program performance, and compliance initiatives.
  • Lead incident response planning and support cross-functional coordination during cybersecurity incidents.
Security Implementation & Optimization
  • Oversee the evaluation, design, deployment, and optimization of cybersecurity tools, technologies, and controls.
  • Participate in security architecture reviews and technology assessments to ensure alignment with organizational security requirements.
  • Identify opportunities to improve operational efficiency, control effectiveness, and overall program maturity.
  • Maintain clear documentation for program processes, operational procedures, standards, and knowledge management.
Reporting & Stakeholder Management
  • Provide regular updates to executive leadership on cybersecurity program progress, risks, priorities, and achievements.
  • Develop and present cybersecurity metrics, dashboards, compliance reports, and risk summaries.
  • Clearly communicate regulatory requirements and business implications to relevant stakeholders.
  • Identify, elevate, and help resolve critical cybersecurity risks and issues.
  • Build strong relationships with internal leadership and external stakeholders to support successful program execution.
Qualifications & Requirements
  • 10+ years of experience in cybersecurity, information security, or a related field, including at least 5 years in a cybersecurity program management, governance, or leadership role.
  • Proven experience developing and implementing IT security policies, standards, and procedures from the ground up.
  • Demonstrated ability to identify policy gaps and partner with technical and business teams to create effective security documentation and governance processes.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field; equivalent experience may be considered.
  • Strong knowledge of cybersecurity frameworks and standards, including NIST CSF, ISO 27001, CIS Controls, SOC 2, and CMMC.
  • Deep experience in cybersecurity governance, risk management, compliance, and policy development.
  • Strong understanding of security controls, threat modeling, vulnerability management, and risk assessment methodologies.
  • Experience managing complex, enterprise-wide cybersecurity initiatives and multiple concurrent workstreams.
  • Knowledge of program and project management methodologies, including Agile and Waterfall.
  • PMP or a comparable project or program management certification is preferred.
  • Excellent communication, stakeholder management, leadership, and executive presentation skills.
  • Ability to translate complex cybersecurity and compliance requirements into clear, actionable guidance for both technical and non-technical audiences.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Program Manager
Cyber Security Program Manager

Compunnel, Inc. • Durham (NC)

On-site
USD 100,000 - 130,000
Cybersecurity Manager
Cybersecurity Manager

BMA Group Global • Guaynabo (PR)

On-site
USD 120,000 - 190,000
Cybersecurity Program Manager
Cybersecurity Program Manager

Crest Security Assurance • United States

On-site
USD 120,000 - 165,000
Senior Director, Information Security (Relocation eligible)
Senior Director, Information Security (Relocation eligible)

Solving IT • Nashville (TN)

On-site
USD 180,000 - 260,000
Manager, Cybersecurity
Manager, Cybersecurity

Carey International Group, LLC • Orlando (FL)

On-site
USD 130,000 - 190,000
Director, Cyber Security
Director, Cyber Security

Ziply Fiber • Kirkland (WA)

On-site
USD 180,000 - 230,000
Medical
dental
vision
+9
Product Cybersecurity Program Management Lead
Product Cybersecurity Program Management Lead

Jobtailor • Plano (TX)

On-site
USD 120,000 - 190,000
Cybersecurity Director
Cybersecurity Director

10xTalents • Newark (NJ)

On-site
USD 140,000 - 180,000
Cybersecurity Program Manager
Cybersecurity Program Manager

Insight Global • Rosemead (CA)

On-site
USD 83,000 - 96,000
Medical insurance
Dental insurance
Vision insurance
+5
Cybersecurity Program Manager GRC
Cybersecurity Program Manager GRC

Saigepartners • San Jose (CA), Northern (KY)

Hybrid
USD 117,000 - 131,000