Cybersecurity Program Manager
Listed on 2026-09-07
-
IT/Tech
Cybersecurity
Carex is partnering with a Insurance industry partner to hire a Cybersecurity Program Manager to turn cybersecurity assessment findings into an executable, measurable, and governed transformation program. This role will build the roadmap, metrics, governance, and operating discipline required to manage a complex, multi-workstream cybersecurity transformation within a federally regulated healthcare environment.
The Cybersecurity Program Manager will provide dedicated program management capacity to Enterprise Security leadership, translating identified security gaps into prioritized remediation efforts and ensuring initiatives are sequenced, owned, measured, and aligned with regulatory obligations. The environment operates under federal and healthcare security requirements, including FISMA, NIST SP 800-53, HIPAA, and independent information security program evaluations conducted under Section 912 of the Medicare Prescription Drug, Improvement, and Modernization Act.
Success in this role means establishing a transformation program with a sustainable operating cadence, producing executive and board-grade reporting, improving visibility into maturity and risk reduction, and ultimately transitioning the established program to an internal Project Management Office.
What You'll Do- Own program management for the cybersecurity transformation portfolio, including planning, sequencing, dependency management, milestone tracking, and critical path management.
- Build and maintain a multi-year cybersecurity transformation roadmap, integrated program plan, and RAID log.
- Convert identified cybersecurity assessment gaps into a single, prioritized, owned, and dependency-mapped remediation register.
- Normalize and validate security gaps with named owners and map remediation activities to relevant NIST Cybersecurity Framework, NIST SP 800-53, and applicable Section 912 control areas.
- Design, build, and operate a cybersecurity metrics and reporting framework that measures maturity improvement and risk reduction using available organizational data.
- Produce executive, leadership, and Audit Committee reporting materials, including board-grade cybersecurity transformation reporting.
- Establish and operate lightweight program governance, including forums, agendas, decision capture, accountability mechanisms, and follow-through without creating unnecessary administrative burden.
- Coordinate transformation activities across Enterprise Cyber Resilience functions spanning cyber risk and assurance, business enablement, compliance, trust and architecture, and threat management.
- Align the cybersecurity transformation roadmap with the annual Section 912 audit cycle so remediation activities can be efficiently planned, executed, and evidenced.
- Build a resource and capacity model that supports evidence-based staffing and budget decisions.
- Establish a program charter and sustainable governance model that enables clear ownership, decision-making, and execution.
- Develop and manage a wave-sequenced, multi-year transformation plan that reflects priorities, dependencies, capacity constraints, regulatory obligations, and risk.
- Ensure metrics and reporting operate through repeatable collection and reporting cycles using live data.
- Return meaningful capacity to Enterprise Security leadership by independently driving program operations, coordination, reporting, and follow-through.
- Maintain appropriate separation between transformation program management and operational cybersecurity responsibilities, including audit ownership, security architecture and engineering decisions, incident response, security tool administration, vendor operations, and control approval responsibilities.
- Prepare and execute comprehensive knowledge transfer and transition of the established transformation program to the internal Project Management Office.
- Minimum of 8 years of program or project management experience, including at least 5 years specifically managing cybersecurity programs.
- Demonstrated ownership of at least one cybersecurity transformation or security maturity improvement program from assessment findings and roadmap development through execution.
- Working…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).