Cybersecurity Program Manager GRC
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Project Manager
Position:
Cybersecurity Program Manager - GRC (San Jose, CA)
Job Overview:
We are seeking an experienced Cybersecurity Program Manager to lead the development and execution of enterprise-wide cybersecurity governance, compliance, and risk management initiatives. This role will be responsible for establishing cybersecurity programs, creating security policies and standards from the ground up, driving compliance efforts, and partnering with cross-functional stakeholders to strengthen the organization's security posture. The ideal candidate combines deep cybersecurity expertise with strong program management capabilities and a proven track record of developing security governance frameworks, policies, and procedures in complex enterprise environments.
This is a W2 contract position and is not eligible for C2C or W2 referral candidates.
Key Responsibilities:- Security Governance, Policy & Procedure Development
- Lead the development, documentation, and maintenance of enterprise-wide IT security policies, standards, and procedures.
- Create comprehensive security governance documentation from scratch, ensuring alignment with business objectives and regulatory requirements.
- Collaborate with IT, Security, Compliance, and business stakeholders to identify policy gaps and define security requirements.
- Develop and maintain policies covering areas such as access management, data protection, incident response, risk management, and security operations.
- Establish clear, enforceable standards and implementation guidelines for both technical and non-technical teams.
- Document detailed operational procedures to ensure consistent execution across departments.
- Facilitate policy review cycles, stakeholder approvals, and governance processes.
- Conduct periodic audits of policy compliance and recommend updates based on findings, organizational changes, and emerging threats.
- Cybersecurity Program Management & Strategy
- Develop, implement, and maintain enterprise-wide cybersecurity programs aligned with organizational goals and industry best practices.
- Create and execute multi-year cybersecurity roadmaps and strategic initiatives.
- Define program objectives, success metrics, and key performance indicators (KPIs) to measure effectiveness.
- Monitor emerging cybersecurity threats, vulnerabilities, and industry trends to proactively adjust program strategies.
- Manage cybersecurity program budgets, resources, and project priorities.
- Cross-Functional Leadership & Governance
- Partner with IT, Security Operations, Risk Management, Compliance, Legal, and business leadership teams to drive cybersecurity initiatives.
- Establish governance frameworks, decision-making processes, and accountability structures.
- Coordinate activities with external vendors, consultants, auditors, and third-party service providers.
- Communicate complex cybersecurity concepts to both technical and non-technical audiences.
- Promote a culture of cybersecurity awareness and accountability across the organization.
- Compliance & Risk Management
- Ensure compliance with applicable regulatory and industry frameworks, including CCPA, CPRA, SOC 2, CMMC, and related standards.
- Lead risk assessments, vulnerability management initiatives, and penetration testing programs.
- Develop and maintain risk management processes and security control frameworks.
- Monitor and report on organizational security posture and compliance status.
- Support incident response planning, testing, and coordination during cybersecurity events.
- Security Program Implementation & Optimization
- Oversee the evaluation, implementation, and optimization of security technologies, tools, and controls.
- Conduct security architecture reviews and technology assessments.
- Drive continuous improvement initiatives across cybersecurity programs and processes.
- Maintain comprehensive program documentation, operational procedures, and knowledge repositories.
- Ensure effective documentation management and organizational readiness for audits and assessments.
- Executive Reporting & Stakeholder Management
- Provide executive leadership and key stakeholders with regular updates on cybersecurity initiatives, risks, and program performance.
- Develop dashboards, metrics, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).