xelys jobs xelys jobs

Sr. InfoSec Program Manager

Jobgether

full-remoteseniorpermanentproduct-managementsecurity United States Yesterday via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Information SecurityProgram ManagementSecurity ComplianceSOC 2ISO 27001PCI-DSSNIST CSFAudit ReadinessVulnerability ManagementIncident Response

About the role

Role Overview

Sr. InfoSec Program Manager to operationalize a growing information security program. You’ll coordinate initiatives across security, IT, engineering, legal, and compliance, turning security efforts into measurable business outcomes through metrics, reporting, and audit/regulatory readiness.

Responsibilities

  • Own execution of the security program roadmap: coordinate initiatives, track milestones, identify blockers, and ensure progress across security functions.
  • Manage cross-functional dependencies with Engineering, IT, Legal, Compliance, and other stakeholders.
  • Build and maintain security metrics frameworks, dashboards, and reporting (e.g., vulnerability management, incident response, audit findings, security awareness).
  • Translate technical/operational data into executive-ready narratives for leadership, board reporting, customer security reviews, and audit committees.
  • Coordinate audit readiness: evidence collection, documentation management, and remediation tracking for SOC 2, ISO 27001, and PCI-DSS.
  • Manage security policy lifecycle: reviews, approvals, version control, and accessibility.
  • Support security awareness: phishing simulations, training programs, vendor administration, and MSSP relationship coordination.
  • Improve operational efficiency by creating repeatable processes, increasing program visibility, and reducing administrative burden on security leadership.

Requirements

  • 5–8 years of experience in information security, IT program management, security operations coordination, or related.
  • Strong knowledge of cybersecurity/compliance frameworks and standards, including NIST CSF, SOC 2, ISO 27001, and PCI-DSS.
  • Experience managing cross-functional programs in regulated/compliance-driven environments.
  • Experience coordinating security audits, evidence collection, and remediation tracking.
  • Excellent written and verbal communication for executive-level reporting.
  • Ability to manage multiple initiatives and priorities independently.
  • Experience working with security tools, vendors, compliance teams, and internal stakeholders.

Preferred

  • Experience in financial services, fintech, SaaS, or other regulated industries.
  • Familiarity with GDPR, NIS2, DORA, SEC cybersecurity disclosures, or public-company audit processes.
  • Certifications: PMP, CISM, CISSP.

Scraped 7/25/2026