Security Project Manager – CISO Portfolio Management; Information Security
Listed on 2026-09-04
-
IT/Tech
Cybersecurity, IT Project Manager, IT Consultant
Location(s) P&C-Butterfield Road-Downers Grove-IL-AAC Details Kemper is one of the nation’s leading specialized insurers. Our success is a direct reflection of the talented and diverse people who make a positive difference in the lives of our customers every day. We believe a high-performing culture, valuable opportunities for personal development and professional challenge, and a healthy work-life balance can be highly motivating and productive.
Kemper’s products and services are making a real difference to our customers, who have unique and evolving needs. By joining our team, you are helping to provide an experience to our stakeholders that delivers on our promises.
Leads complex cybersecurity and information security initiatives from strategy through implementation and operational acceptance within the company's Agile/SAFe operating model. This is a security delivery leadership role, the incumbent must combine disciplined Agile/SAFe program execution with credible cybersecurity fluency, risk and control judgment, and the ability to drive accountable decisions across technical, business, risk, and third-party stakeholders.
Position ResponsibilitiesDirect end-to-end delivery of enterprise cybersecurity programs such as identity security, GRC, SOC, vulnerability/exposure management, application security, cloud security, and data protection initiatives. Develop and manage integrated Agile/SAFe delivery plans that connect architecture, engineering, control, testing, change, vendor, and operational-readiness activities; manage cross-team dependencies, Program Increment commitments, milestones, and readiness criteria rather than treating the program as a schedule-only exercise. Identify and drive resolution of security, technical, control, regulatory, resource, and operational dependencies;
escalating and managing the risks with clear decision options. Establish and operate governance forums, decision rights, Agile/SAFe ceremonies, risk/issue management, financial controls, delivery metrics, and executive reporting appropriate to Director-level accountability. Translate between engineers, security specialists, risk and control teams, vendors, and business leaders to maintain technically accurate decisions and commitments. Lead vendor delivery, implementation milestones, readiness, cutover, transition, and operational acceptance in partnership with Procurement and technology owners.
Drive continuous improvement in security delivery practices, portfolio transparency, and benefits realization.
10+ years of progressive technology/security program delivery experience, including substantial experience leading complex cybersecurity or highly technical risk programs at enterprise scale and demonstrated delivery within Agile/SAFe environments. Equivalent depth of experience will be considered. Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, Business, Risk Management, or a related discipline, or equivalent relevant professional experience. Deep working knowledge of multiple cybersecurity domains and the technical dependencies that shape security implementations.
Required hands-on experience operating in Agile/SAFe environments, including Program Increment planning, backlog and dependency management, Agile ceremonies, cross-team coordination, delivery metrics, and iterative value delivery. Demonstrated delivery of complex security or highly technical risk programs. Strong knowledge of cybersecurity risk, security control objectives, technology implementation risk, and control-readiness concepts. Experience managing programs with regulatory, audit, control, or operational-resilience implications. Strong command of program/project governance, integrated planning, dependency management, RAID management, financial tracking, vendor management, change management, testing, and operational transition.
Understanding of common security frameworks and control environments sufficient to manage security program dependencies and evidence requirements. Ability to translate technical security conditions into business impact, risk decisions, priorities, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).