×
Register Here to Apply for Jobs or Post Jobs. X

Program Manager, Cyber Risk

Job in Winchester, Frederick County, Virginia, 22603, USA
Listing for: Valley Health
Full Time, Part Time position
Listed on 2026-09-27
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Salary/Wage Range or Industry Benchmark: 98000 - 154000 USD Yearly USD 98000.00 154000.00 YEAR
Job Description & How to Apply Below
## Program Manager, Cyber Risk Apply:
Winchester, VA:
Full time:
Posted Today:
JR109604
* As one of the
** nation's Top 15 Health Systems, recognized by Premier and Modern Healthcare**, Valley Health is a place where excellence, compassion, and purpose come together. This distinction reflects our commitment to exceptional patient care, clinical quality, and the caregivers who make it all possible.*## DepartmentINFORMATION SYSTEMS - 108231## Worker Sub Type Regular## Work Shift First Shift (United States of America)
** Pay Range**$47.28 - $73.94#
** Job Description*
* ** Onsite work requirements 2-3 days a week at Winchester Medical Center campus.
** The Cyber Risk Program Manager plays a key role in supporting the organization’s information security efforts. This position helps identify and assess potential security risks, working closely with teams to ensure alignment with security policies and the Risk Management Framework (RMF).  Responsibilities and Duties  Monitors the security posture of systems, offering risk-based recommendations, and assisting with reviews and authorizations to operate.  

Leads the vulnerability management program, applying knowledge of applications, operating systems, networks, cloud infrastructure, and cyber threat tactics.  Collaborates with internal teams to remediate vulnerabilities and implement strategies that protect company assets and data.  Oversees the IT audit processes, providing documentation to prove compliance with HIPAA Security Regulations, NIST guidelines, and other governmental regulations. This includes ensuring adherence to organizational security policies and procedures.  

Makes recommendations on security policies as needed to ensure they are current and effective in addressing emerging threats and regulatory requirements.  Serve as backup to the Manager of Information Security, handling escalations and participating in decision-making when higher-level guidance is required. This collaborative support ensures continuity in addressing complex security matters and facilitates informed, timely resolutions across the organization.  
** Education
* * Bachelor’s or postgraduate Degree in Business, Computer Science, Information Security or a related field is required.  
** Experience
* * 7+ years of experience in information technology is required.  5+ years of work experience in cybersecurity, and/or 5+ years of experience in a risk management and/or IT audit role and/or 5+ years of experience with regulatory compliance and information security management frameworks (e.g., HIPAA Security Regulations, Health Information Technology for Economic and Clinical Health Act [HITECH Act], International Organization for Standardization [ISO] 27000, COBIT, National Institute of Standards and Technology [NIST] 800 RMF), is required.

** Certifications & Licensures
** Industry advanced level cybersecurity certification required within 1 year of hire.  
** Qualifications
* * Working knowledge of hospitals and healthcare industry required.  Ability to communicate complex technical concepts to both technical and non-technical audiences, and collaborate effectively with IT teams and stakeholders.  Understanding risk assessment methodologies to identify, evaluate, and prioritize cyber risks based on likelihood and impact.  Understanding the vulnerability management lifecycle to identify, assess, prioritize and remediate vulnerabilities before they can be exploited.  

Understanding of relevant healthcare regulations and data privacy laws that impact cybersecurity practices.  Strong understanding of cyber risk management frameworks (NIST, ISO 27001, etc.).  

Experience with GRC tools, process automation, security metrics and policy management.  Commitment to staying current…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary