1

Information Security Program Manager Jobs (NOW HIRING)

The Security Program Manager provides leadership and administrative management to teammates ... Proactively communicate key information and developments within the healthcare facility and ...

The Security Program Manager provides leadership and administrative management to teammates ... Proactively communicate key information and developments within the healthcare facility and ...

The Security Program Manager provides leadership and administrative management to teammates ... Proactively communicate key information and developments within the healthcare facility and ...

The Security Program Manager provides leadership and administrative management to teammates ... Proactively communicate key information and developments within the healthcare facility and ...

Security Program Manager

Vienna, VA · Remote

$132K - $160K/yr

Technical Program Manager Location: Vienna, VA Type: Contract Compensation: 80/hr W2 Work Model ... genetic information, veteran status, marital status, or any other characteristic protected by ...

Information Security Manager

Boulder, CO · On-site

$120K - $155K/yr

In this role, you will manage our information security program end-to-end: setting policy, driving compliance, managing risk, and operating the technical controls that will further improve our ...

next page

Showing results 1-20

Information Security Program Manager information

See salary details

$54.5K

$149K

$167K

How much do information security program manager jobs pay per year?

As of Jul 26, 2026, the average yearly pay for information security program manager in the United States is $149,013.00, according to ZipRecruiter salary data. Most workers in this role earn between $129,000.00 and $157,000.00 per year, depending on experience, location, and employer.

What is the difference between Information Security Program Manager vs Security Analyst?

AspectInformation Security Program ManagerSecurity Analyst
CertificationsCISSP, CISM, PMPCompTIA Security+, CISSP (optional)
Work EnvironmentOversees security programs, manages teams, strategic planningMonitors security systems, analyzes threats, implements security measures
Employer & Industry UsageUsed in organizations with complex security needs, corporate sectorsCommon in IT departments, security operations centers

The main difference is that an Information Security Program Manager focuses on managing and coordinating security initiatives at a strategic level, while a Security Analyst primarily monitors and analyzes security threats to protect systems. The Program Manager leads security programs, whereas the Analyst executes security measures and responds to incidents.

What is an Information Security Program Manager?

An Information Security Program Manager is responsible for overseeing and coordinating an organization’s information security initiatives. They develop, implement, and manage security policies, procedures, and programs to protect an organization's data and IT systems from threats. Their role often involves risk assessment, compliance management, incident response coordination, and ensuring that security strategies align with business objectives. Information Security Program Managers work closely with IT teams, leadership, and external partners to maintain robust security postures.

What are the key skills and qualifications needed to thrive as an Information Security Program Manager, and why are they important?

To thrive as an Information Security Program Manager, you need in-depth knowledge of cybersecurity frameworks, risk management, and governance, typically supported by a bachelor’s degree in a related field and certifications like CISSP or CISM. Familiarity with security information and event management (SIEM) tools, vulnerability assessment platforms, and compliance management systems is crucial. Exceptional leadership, communication, and project management skills help you drive cross-functional initiatives and foster a strong security culture. These competencies are vital for effectively mitigating security risks, ensuring regulatory compliance, and aligning security programs with organizational goals.

What are some typical challenges faced by Information Security Program Managers when implementing new security initiatives across an organization?

Information Security Program Managers often encounter challenges such as gaining buy-in from stakeholders, navigating organizational resistance to change, and balancing security needs with business objectives. They must coordinate with various departments to ensure consistent adherence to security policies and effectively communicate the value of new initiatives. Additionally, they manage competing priorities and tight deadlines while ensuring compliance with regulatory requirements and industry standards.
What cities are hiring for Information Security Program Manager jobs? Cities with the most Information Security Program Manager job openings:
What states have the most Information Security Program Manager jobs? States with the most job openings for Information Security Program Manager jobs include:
Infographic showing various Information Security Program Manager job openings in the United States as of July 2026, with employment types broken down into 1% As Needed, 73% Full Time, 23% Part Time, 1% Temporary, and 2% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $149,013 per year, or $71.6 per hour.
Information Security Program Specialist

Information Security Program Specialist

Metropolitan Washington Airports Authority

Iola, KS • On-site

$106K - $154K/yr

Full-time

Posted yesterday


Job description

Compensation Grade:

S21

Salary Range:

$106,262.00-$154,080.00

Opening Date:

July 24, 2026

Closing Date:

August 8, 2026

Please Note: All job announcements close at 11:59 p.m. of the day before the posted closing date.

As an Information Security Program Specialist, you will support the Airports Authority's Information Security program by monitoring, testing and supporting existing security tools and researching and implementing new security tools.
Information Security Program Specialist
Serves in the Cyber Security Department in the Office of Technology at the Headquarters Office.
Monitors, tests, and reports on security, confidentiality, integrity, and availability of the Airports Authority's information assets in compliance with national, industry and organizational regulations, policies and standards. Performs related functions.

GENERAL RESPONSIBILITIES

Serves as an internal information security subject matter expert on projects and other initiatives to identify security issues and mitigate them. Monitors, tests, and reports on user activity for adherence to security policies and procedures. Identifies user-related security problems and reports problem activity to appropriate managers.

Recommends security solutions (e.g. firewalls, administrative controls), as appropriate.

Regularly reviews regulations and monitors changes in legislation and accreditation standards affecting information security to support organizational compliance. Advises the Airports Authority on compliance issues and related security technologies.

Serves as information security liaison for data owners, custodians, and users. Initiates and facilitates activities to create information security awareness within the Airports Authority.

Reviews system-related security plans throughout the network; works closely with IT management to ensure that security is built in to all initiatives.

Plans and schedules penetration testing, security appliance upgrades, and vulnerability assessments.

Collects and reviews log files from various hosts on the network. Conducts network and system audits and continuous vulnerability assessments and prepares assessment reports.

Conducts security review of new software systems and reviews and validates changes to production systems.

Serves as a security team lead for security activities which involve external resources performing security tasks and other professional services (i.e. penetration tests, security assessments and audits).

Monitors internal control systems to ensure appropriate access levels are maintained.

Reviews and makes recommendations on the Business Continuity and Disaster Recovery Plans. May conduct information security risk assessments or collect forensic data for the Office of Legal Counsel or the Office of Human Resources.

Performs other duties as assigned.

QUALIFICATIONS

Six years of progressively responsible experience in information technology security including applying industry and legal/regulatory standards and requirements (e.g., International Organization for Standardization (ISO), International Information Systems Security Certification Consortium ((ISC)2), Health Insurance Portability and Accountability Act (HIPAA), National Institute of Standards and Technology (NIST)) to network security for an organization.

Knowledge of and ability to apply computer system/network techniques, requirements, sources, procedures, and specialized command languages, including firewall administration, for mainframe computers, Intel-based servers and workstations, workstation support, server administration; network device configuration, and data administration.

Skill in effectively handling sensitive situations by ensuring that system security remains uncompromised and that evidentiary facts presented to management are based on expertly executed forensic investigation of system use/misuse.

Ability to perform detailed analyses of data and information and make recommendations.

Ability to speak and write effectively, with emphasis on communicating technical information to non-technical audiences.

PREFERRED QUALIFICATIONS

Certification as a Certified Information Security Manager (CISM) from the Information Systems Audit and Control Association (ISACA), Certified Information Systems Security Professional (CISSP) from (ISC)2, or Information Systems Security Engineering Professional (CISSP-ISSEP) from (ISC)2.

EDUCATION

A Bachelor's Degree in Information Security, Cybersecurity, Computer Science, or related field.

CERTIFICATIONS AND LICENSES REQUIRED

None.

NECESSARY SPECIAL FACTORS

Work is typically reviewed in progress and upon completion for quantity, quality, timeliness, teamwork, customer service, and other factors.

May move computer equipment weighing up to 45 pounds.

Is subject to hold-over and recall for IT emergencies and may need to work nights and weekends depending on operational requirements and other factors.

#WP

#DICE

A background security investigation will be required for all new hires.

Metropolitan Washington Airports Authority is an Equal Opportunity Employer.| Follow us on Twitter @MWAAcareers.