The Role
Moderna is seeking a Senior Technical Program Manager (TPM) to lead and coordinate cybersecurity remediation initiatives across the organization. We’relooking for someone who brings integrity, sound judgment, strong relationship-building skills, and cybersecurityexpertise, and who can partner effectively across teams to move complex work forward.
The Role
Moderna is seeking a Senior Technical Program Manager (TPM) to lead and coordinate cybersecurity remediation initiatives across the organization. We’relooking for someone who brings integrity, sound judgment, strong relationship-building skills, and cybersecurityexpertise, and who can partner effectively across teams to move complex work forward. In this role, you will helpleadthe end‑to‑end remediation of security findings generated through scans, assessments, audits, incident reviews, investigations, and continuous monitoring. You will bring thoughtful program management, collaboration, and clear communication to a complex, cross‑functional environment where responsiveness, quality, and partnership all matter.
Here’s What You'll Be Doing
Program Ownership
- Lead and coordinate the intake, prioritization, and execution of cybersecurity remediation programs using a structured, data-driven, and risk-based approach.
- Responsible for end‑to‑end delivery of multiple concurrent remediation workstreams across Moderna technology and business teams, from identification through validation and closure.
- Establish and manage a centralized remediation operating model, including governance, prioritization frameworks, SLAs, escalation paths, and execution tracking.
- Define andmonitorprogram metrics, risks, and trends to drive accountability, decisions, and continuous improvement.
Risk and Remediation Management
- Translate findings from vulnerability scans, penetration tests, risk assessments, incidents, audits, and investigations into actionable remediation plans.
- Partner with teams to move remediation items through verification and closure, including management of exceptions and risk acceptance withappropriate sign‑off.
- Own theconsolidatedfindingsregistry,maintaininga single authoritative view of vulnerabilities, risks, audit findings, post‑incident action items, and assessment recommendations.
- Lead executive‑and board‑level reporting on remediation posture, metrics, and systemic trends, translating technical risk into business‑relevant language.
- Identifyrecurring issues and drive longer‑term improvements that strengthen cybersecurity practices and reduce futurerisk.
Partner Engagement and Influence
- Build strong relationships across security, engineering, and business teams to create alignment, navigate blockers, and influence prioritization in a highly matrixed environment.
- Provide clear, concise, and executive‑ready communications on program status, risks, decisions, and tradeoffs.
- Partner with leaders to strengthen secure engineering and operational practices across the organization.
- Actively contribute to creating a more inclusive culture and environment atModerna; endorse, create, andmaintainantiracist policies and processes.
Here’s WhatYou’llNeed (Basic Qualifications)
- Experience: 8+ years in Technical Program Management, Cybersecurity Program Management, or similar roles.
- Proven experience leading complex, cross‑functional remediation programs in cybersecurity, infrastructure, or enterprise IT environments.
- Strong understanding of cybersecurity domains such as vulnerability management, incident response, identity, cloud security, and application security.
- Experience working with findings from audits, risk assessments, penetration tests, and security incidents.
- Strong stakeholder partnership and influencing skills in highly matrixed organizations.
- Excellent written and verbal communication skills, including executive‑level communication.
- Ability to define metrics, track progress, and use data to support clear and informed decision‑making.
- Strong listening skills, sound judgment, and a proactive approach to feedback and problem‑solving.
Here’s WhatYou’llBring To The Table (Preferred Qualifications)
- Experience with GxP environments and regulatory requirements.
- Familiarity with vulnerability management platforms, GRC tools, and security tracking/reporting systems.
- Experience with post‑incident review processes, including root cause analysis (RCA), CAPA management, and lessons‑learned programs.
- Experience implementing or scaling enterprise remediation or risk management programs.
- Background ininfrastructure, cloud, or security engineering.
- Knowledge of security frameworks (e.g., NIST, ISO 27001, CIS).
- Experience driving operational maturity improvements (process, tooling, governance).
- Strong senseof ownership and urgency, with the ability to balance risk,timelyexecution, and business priorities.
- Influential, inclusive, and trusted partner with a collaborative mindset.
Pay & Benefits
At Moderna, we believe that when you feel your best, you can do your best work. That’s why our benefits and well‑being resources are designed to support you—at work, at home, and everywhere in between.
- Competitive healthcare, plus voluntary benefit programs to support your unique needs
- A holistic approach to well‑being, with access to fitness, mindfulness, and mental health support
- Family planning benefits, including fertility, adoption, and surrogacy support
- Generous paid time off, including vacation, volunteer days, sabbatical, global recharge days, and a discretionary year‑end shutdown
- Savings and investments to help you plan for the future
- Location‑specific perks and extras
The salary range for this role is $145,900.00 -