Featured Job

Senior Program Manager

Quincy, MA Full-time Hybrid 09/17/2026 Job ID: 000236
Apply Now
Program / Delivery Management Cloud Security Vulnerability Management Identity and Access Management (IAM) Security Operations

Summary

What you’ll impact

The Senior Program Manager, Cloud Security & Vulnerability Management leads enterprise-wide security programs across multi‑cloud environments, driving risk reduction, security posture improvement, and strategic initiatives. This role oversees cross‑functional teams, manages budgets and vendors, and reports to executive leadership to align security outcomes with business objectives.

Responsibilities

What you'll do

  • Lead enterprise-wide cloud security and vulnerability management programs across AWS, Azure, and Google Cloud environments.
  • Develop and execute multi-year security roadmaps aligned with organizational security, technology, and business goals.
  • Establish governance, prioritization, funding, resourcing, and execution models for security initiatives.
  • Drive executive-level reporting and communication regarding security posture, risk reduction, delivery performance, and key decisions.
  • Manage a portfolio of complex security projects involving multiple workstreams, vendors, geographies, and stakeholder groups.
  • Lead initiatives focused on cloud security architecture, governance, control implementation, and operational excellence.
  • Partner with Cloud Engineering, Infrastructure, Platform Engineering, Architecture, and DevOps teams to implement security controls and leading practices.
  • Drive adoption of Zero Trust, Cloud Security Posture Management (CSPM), Cloud Workload Protection Platforms (CWPP), and security automation solutions.
  • Ensure security-by-design principles are embedded within cloud migration, modernization, and platform engineering programs.
  • Establish and mature the enterprise vulnerability management strategy, operating model, governance, and remediation practices.
  • Develop risk-based prioritization models that consider severity, exploitability, asset criticality, exposure, and business impact.
  • Track the vulnerability lifecycle from discovery and triage through remediation, exception management, validation, and closure.
  • Collaborate with infrastructure, application, cloud, and product teams to reduce critical and high-risk security findings.
  • Monitor remediation service-level agreement performance and drive continuous improvement in remediation effectiveness.
  • Facilitate security governance forums, risk reviews, decision-making sessions, and executive steering committees.
  • Monitor program risks, issues, assumptions, dependencies, decisions, and mitigation activities.
  • Align security programs with applicable frameworks and requirements, including NIST, ISO 27001, CIS Controls, and organizational policies.
  • Support audit readiness, control assessments, regulatory commitments, and remediation of audit findings.
  • Promote consistent, risk-based decision-making across security programs and technology organizations.
  • Serve as the primary program liaison among security leadership, technology teams, business stakeholders, risk partners, auditors, and external providers.
  • Present program status, risk trends, vulnerability metrics, investment needs, and strategic recommendations to executive leadership.
  • Build effective partnerships across engineering, operations, architecture, application, compliance, and business organizations.
  • Manage program budgets, forecasts, resource plans, financial performance, and investment tracking.
  • Evaluate and oversee third-party security vendors, managed service providers, consulting partners, and technology suppliers.
  • Ensure effective utilization of security investments, licenses, services, and program resources.
  • Develop and maintain executive dashboards and key performance indicators covering vulnerability remediation, cloud security posture, compliance, risk reduction, control effectiveness, program health, and audit readiness.
  • Translate complex technical findings into clear business risk, decision points, ownership, and actionable remediation plans.
  • Use data-driven insights to identify systemic issues, remediation bottlenecks, recurring control gaps, and improvement opportunities.

Requirements

What you’ll bring

  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Engineering, Business, or a related field.
  • Master's degree preferred.
  • 10+ years of program or portfolio management experience leading large-scale technology initiatives.
  • 5+ years managing enterprise cybersecurity, cloud security, vulnerability management, or risk remediation programs.
  • Experience working in a large, complex, and preferably regulated organization.
  • Demonstrated success leading cross-functional initiatives involving multiple stakeholders and executive sponsors.
  • Experience managing significant technology or security budgets, vendors, and delivery commitments.
  • Strong understanding of cloud security across AWS, Azure, and Google Cloud.
  • Working knowledge of vulnerability management platforms, security operations, identity and access management, DevSecOps, secure software development, infrastructure security, security architecture, incident response, and regulatory compliance.
  • Experience with NIST Cybersecurity Framework, NIST SP 800-53, ISO 27001, CIS Controls, Zero Trust Architecture, and relevant regulatory or industry requirements such as SOC 2, PCI DSS, SOX, or HIPAA, as applicable.
  • Program / Delivery Management certification.
  • Cybersecurity / Cloud certification.
  • PMP or PgMP.
  • CISSP, CISM, CCSP, or CRISC.
  • SAFe, Agile, or Scrum certification.
  • AWS Security Specialty or Microsoft Azure security certification.
  • Executive presence.
  • Organizational change management.
  • Strategic thinking.
  • Vendor and partner management.
  • Risk-based decision-making.
  • Problem-solving and analytical thinking.
  • Influencing without authority.
  • Conflict resolution.
  • Cross-functional leadership.
  • Financial and budget management.

Ready to Move Forward?

Apply now and our recruiting team will reach out with next steps, interview guidance, and client insights tailored to this role.