Project Manager
2 days ago
Rochester
Must be local to Rochester, NY and work Hybrid No C to C or Sponsorship Program Manager / Project Manager – Information Security Position Summary We are seeking an experienced Project/Program Manager to support the continued maturity of an enterprise Information Security organization. This role will work closely with Security Leadership, Architecture, the PMO, and cross-functional technology teams to establish stronger processes, governance, documentation, reporting, risk management, and operational practices across the Information Security organization. The ideal candidate will bring strong project/program management experience combined with an understanding of Information Security operations and governance. This person will assess current processes, identify improvement opportunities, establish repeatable procedures, create visibility into security initiatives and outcomes, and help drive strategic priorities through execution. This is a highly collaborative role requiring someone who can operate effectively with security leadership, technical teams, architects, and business stakeholders while bringing structure and accountability to complex initiatives. Key Responsibilities • Assess current Information Security processes, procedures, tools, documentation, and operating practices to identify gaps and opportunities for improvement., • Develop and maintain a comprehensive roadmap of Information Security improvement initiatives and work with Security Leadership to prioritize and establish plans for execution., • Establish consistent project and program management practices across Information Security initiatives, including scope, milestones, dependencies, risks, issues, decisions, and deliverables., • Develop and improve Information Security documentation standards, repositories, processes, and governance practices., • Establish a consistent communication and reporting framework, including defining:, • Required reporting, • Reporting formats, • Reporting locations and repositories, • Distribution and stakeholder requirements, • Access controls, • Reporting frequency, • Improve Information Security risk management processes, including identification, documentation, assessment, mitigation, escalation, and ongoing monitoring., • Develop and formalize change management processes for Information Security activities, including documenting changes, review and approval, deployment, validation, and verification of successful outcomes., • Establish traceability between Information Security initiatives, activities, and strategic objectives., • Document how Information Security activities are managed across security towers and develop methods to measure and monitor outcomes., • Partner with Information Security leadership to establish meaningful metrics, KPIs, dashboards, and reporting mechanisms that demonstrate progress, risk reduction, and operational maturity., • Support the continued maturity of Access and Identity Management (AIM) initiatives, including Zero Trust-related efforts., • Coordinate and track initiatives related to emerging security priorities, including Post-Quantum Readiness., • Help evaluate and improve patch management procedures to increase efficiency, consistency, and accountability., • Work with security teams to identify required policies, procedures, and controls across various Information Security towers., • Establish processes and repositories for tracking policy compliance and ensuring required documentation remains current., • Coordinate across Information Security, Architecture, Infrastructure, Application Development, Risk, Compliance, and other technology teams as appropriate., • Gain an understanding of the organization's existing security tools and systems and establish appropriate repositories and processes for managing program information., • Facilitate working sessions with technical and security teams to document current-state processes, identify gaps, and develop future-state processes., • Prepare recommendations and improvement opportunities for review with Security Leadership., • Establish a sustainable cadence for reviewing, updating, and measuring Information Security processes and improvement initiatives., • Provide regular status reporting to Security Leadership and PMO leadership, including progress, risks, issues, dependencies, decisions, and recommended actions., • Drive initiatives from assessment and planning through implementation, adoption, and ongoing measurement. Key Information Security Focus Areas The initial areas of focus are expected to include: • Information Security documentation and governance, • Communication management and reporting, • Risk management, • Change management, • Security strategy traceability, • Security activity management and measurement, • Access and Identity Management (AIM), • Zero Trust, • Post-Quantum Readiness, • Patch management process improvement, • Information Security policies and procedures, • Compliance and policy tracking, • Security operational maturity Qualifications • 7+ years of project or program management experience, preferably within Information Technology or Information Security., • Experience managing complex, cross-functional technology or cybersecurity programs., • Strong understanding of Information Security processes, governance, risk management, and operational practices., • Demonstrated experience assessing current-state processes and developing future-state processes and procedures., • Experience establishing governance frameworks, documentation standards, reporting structures, and operating procedures., • Strong risk and change management experience., • Experience developing roadmaps, identifying improvement opportunities, prioritizing initiatives, and driving execution., • Ability to work effectively with CISOs, Security Leadership, Architects, PMO leadership, engineers, and technical subject matter experts., • Strong written and verbal communication skills, with the ability to translate technical information into clear executive-level reporting., • Experience developing KPIs, metrics, dashboards, and reporting mechanisms to measure program performance and outcomes., • Strong organizational skills and ability to manage multiple initiatives, priorities, dependencies, and stakeholders., • Experience working in an environment where processes and governance are still being established or matured., • Proficiency with standard project management and collaboration tools. Preferred Qualifications • Experience working directly within an Information Security or Cybersecurity organization., • Experience with Security Governance, Risk & Compliance (GRC)., • Familiarity with Identity and Access Management and Zero Trust., • Experience with vulnerability and patch management programs., • Exposure to security architecture and enterprise security strategy., • Experience with policy and compliance management., • Experience with post-quantum cryptography/readiness initiatives., • PMP, CISM, CISSP, or similar certification., • Experience working within banking, financial services, healthcare, or another highly regulated environment. What We're Looking For The successful candidate will be someone who can bring structure to an evolving Information Security organization. This is not simply a project tracking position. The person will need to assess how security work is currently being performed, identify gaps, establish repeatable processes, create documentation and governance, and work with Security Leadership to turn improvement opportunities into an actionable roadmap. The ideal candidate is comfortable operating at both the programmatic and operational level—able to have strategic conversations with security leadership while also working with technical teams to document processes, establish controls, track deliverables, and drive execution. Key traits: structured, analytical, proactive, highly organized, strong communicator, comfortable with ambiguity, process-oriented, and capable of influencing without direct authority.