Technical Program Manager
Listed on 2025-12-28
-
IT/Tech
Cybersecurity, IT Project Manager, Information Security, IT Consultant
We’re looking for a technically skilled TPM who can lead cybersecurity compliance initiatives, with a primary focus on implementing a CMMC Level 2–equivalent program and strengthening alignment with additional frameworks such as NIST SP 800-171, ISO 27001, and similar standards. This role goes beyond coordination and documentation—you’ll actively participate in building and validating security controls, drafting technical policies, and ensuring that compliance requirements translate into practical engineering outcomes.
You’ll manage cross-functional efforts, maintain program structure, and coordinate stakeholders, while also contributing directly to technical deliverables. The TPM in this position will play a key part in elevating the organization’s security posture and will work closely with teams across engineering, IT, operations, and compliance. The role reports to security leadership and emphasizes measurable, hands‑on impact.
Key ResponsibilitiesLead CMMC Program Execution: Oversee the full lifecycle of a CMMC-style compliance initiative, from scoping and gap analysis through control rollout, assessments, and audit readiness. Support requirements related to protecting sensitive information.
Manage Broader Framework Alignment: Coordinate compliance across multiple cybersecurity standards—including NIST, CIS Controls, or industry‑specific frameworks to maintain a unified and consistent security program.
Produce Technical Security Artifacts: Write and review technical documentation such as system security plans, policies, procedures, POA&Ms, and architectural diagrams. Participate in testing activities, vulnerability assessments, and remediation work to ensure controls are realistically implemented.
Program & Project Management: Build and maintain roadmaps, timelines, and resource plans. Track progress using common project management tools and run stakeholder syncs, risk reviews, and status updates.
Cross‑Functional Coordination: Partner with engineering, IT, legal, and external assessors to address technical challenges, clarify requirements, and cultivate a strong security culture. Provide hands‑on technical support where needed.
Risk & Issue Management: Identify compliance and security risks, prioritize mitigation steps, and conduct periodic assessments or simulations to validate that controls remain effective.
Continuous Enhancement: Monitor evolving cybersecurity regulations and best practices. Recommend and drive improvements in processes, tooling, and program structure.
Reporting & Metrics: Prepare leadership‑level summaries of program status, security performance metrics, and compliance KPIs to enable data‑driven decision‑making.
This position includes some administrative activities (meeting facilitation, notes, scheduling), but the core focus is on technical execution and direct contribution—not just oversight.
Required QualificationsEducation: Degree in computer science, information security, or a related field. Certifications such as CCP, CISSP, CISM, or PMP are strong advantages.
Experience: 5+ years in technical program management, including at least 3 years working with cybersecurity frameworks like CMMC, NIST, or similar. Experience contributing hands‑on to security implementation and developing technical documentation.
Technical Knowledge: Strong familiarity with cybersecurity domains such as access control, encryption, incident response, and network defense. Proficiency with documentation and project management tools (e.g., Confluence, Visio, Jira).
Communication & Leadership: Able to explain technical requirements clearly, work effectively with diverse teams, and operate both independently and collaboratively in a fast‑moving environment.
Additional Requirements: Ability to work with sensitive information and pass background checks. Experience in regulated sectors (government, defense, critical infrastructure, etc.) is beneficial.
Understanding of cloud security concepts (AWS, Azure) and Dev Sec Ops practices
Experience with automation or scripting to support compliance validation or monitoring
Participation in third‑party audits or assessments for CMMC or similar certifications
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).