Role: Security Project Manager
Location: Marlborough, MA
Job Description
Must Have Technical/Functional Skills
- Cybersecurity Program Manager / Security Assurance Lead / Enterprise Security Risk & Governance Lead. candidate needs a blend of deep cybersecurity knowledge, risk management expertise, and strong program management capabilities.
Roles & Responsibilities
Core Responsibilities
- Lead and operate an enterprise security program focused on the security posture of applications, technology platforms, data, integrations, tools, and third-party services.
- Build and maintain a risk-based view of the enterprise attack surface, including customer/member applications, team-member tools, SAP and enterprise platforms, infrastructure, data flows, APIs, SaaS products, AI-enabled capabilities, and vendor-managed services.
- Coordinate security assessments and assurance activities across Infrastructure, Cybersecurity, Penetration Testing, application teams, SAP/enterprise platforms, Data and AI, Architecture, Privacy, Legal, Compliance, Internal Audit, Procurement, and third parties.
- Ensure the appropriate specialists are engaged for each priority initiative or exposure, including architecture review, threat modeling, vulnerability assessment, penetration testing, data/privacy review, access review, application/API security review, and vendor due diligence.
- Translate technical findings into clear business risk statements, priorities, remediation plans, and executive decisions.
- Drive remediation of material security gaps by aligning accountable owners, milestones, funding needs, dependencies, and escalation paths.
- Develop and manage the program charter, integrated plan, timeline, governance model, and meeting cadence.
- Maintain an active RAID log—risks, assumptions, issues, and dependencies—and escalate material items promptly.
- Produce clear weekly program reporting and executive dashboards covering progress, security posture, assessment coverage, material risks, remediation status, decisions needed, and overall program health.
- Partner with technology and business leaders to prioritize security investments based on enterprise exposure, member/customer impact, business value, operational resilience, regulatory requirements, and risk tolerance.
- Build productive relationships with vendors and service providers; ensure technical, operational, and contractual security obligations are assessed and monitored.