1

Information Security Program Manager Jobs in California

Security Program Manager

San Francisco, CA · On-site

$152K - $185K/yr

About the Role Crusoe is seeking a Security Program Manager to lead the physical security strategy ... genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference ...

Security Program Manager

San Francisco, CA · On-site

$152K - $185K/yr

About the Role Crusoe is seeking a Security Program Manager to lead the physical security strategy ... genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference ...

next page

Showing results 1-20

Information Security Program Manager information

See California salary details

$53.8K

$147.1K

$164.8K

How much do information security program manager jobs pay per year?

As of Aug 28, 2026, the average yearly pay for information security program manager in California is $147,062.00, according to ZipRecruiter salary data. Most workers in this role earn between $127,300.00 and $154,900.00 per year, depending on experience, location, and employer.

What is an information security program manager?

An Information Security Program Manager is responsible for overseeing and coordinating an organization’s information security initiatives. They develop, implement, and manage security policies, procedures, and programs to protect an organization's data and IT systems from threats. Their role often involves risk assessment, compliance management, incident response coordination, and ensuring that security strategies align with business objectives. Information Security Program Managers work closely with IT teams, leadership, and external partners to maintain robust security postures.

What are some typical challenges faced by information security program managers when implementing new security initiatives across an organization?

Information Security Program Managers often encounter challenges such as gaining buy-in from stakeholders, navigating organizational resistance to change, and balancing security needs with business objectives. They must coordinate with various departments to ensure consistent adherence to security policies and effectively communicate the value of new initiatives. Additionally, they manage competing priorities and tight deadlines while ensuring compliance with regulatory requirements and industry standards.

What are the key skills and qualifications needed to thrive as an information security program manager, and why are they important?

To thrive as an Information Security Program Manager, you need in-depth knowledge of cybersecurity frameworks, risk management, and governance, typically supported by a bachelor’s degree in a related field and certifications like CISSP or CISM. Familiarity with security information and event management (SIEM) tools, vulnerability assessment platforms, and compliance management systems is crucial. Exceptional leadership, communication, and project management skills help you drive cross-functional initiatives and foster a strong security culture. These competencies are vital for effectively mitigating security risks, ensuring regulatory compliance, and aligning security programs with organizational goals.

What is the difference between Information Security Program Manager vs Security Analyst?

AspectInformation Security Program ManagerSecurity Analyst
CertificationsCISSP, CISM, PMPCompTIA Security+, CISSP (optional)
Work EnvironmentOversees security programs, manages teams, strategic planningMonitors security systems, analyzes threats, implements security measures
Employer & Industry UsageUsed in organizations with complex security needs, corporate sectorsCommon in IT departments, security operations centers

The main difference is that an Information Security Program Manager focuses on managing and coordinating security initiatives at a strategic level, while a Security Analyst primarily monitors and analyzes security threats to protect systems. The Program Manager leads security programs, whereas the Analyst executes security measures and responds to incidents.

What cities in California are hiring for Information Security Program Manager jobs?

Cities in California with the most Information Security Program Manager job openings:

Infographic showing various Information Security Program Manager job openings in California as of August 2026, with employment types broken down into 1% As Needed, 79% Full Time, 16% Part Time, 2% Temporary, and 2% Contract. Highlights an 96% Physical, 1% Hybrid, and 3% Remote job distribution, with an average salary of $147,062 per year, or $70.7 per hour.

Information Security Program Manager

Infinite Resource Solutions

Los Angeles, CA

Full-time

Re-posted 18 days ago


Job description

Job Description JOB SUMMARY: The Information Security Program Manager is responsible for ensuring information systems architecture, configuration, use, and functionality are compliant with regulations and industry best practice to safeguard protected information and the integrity of information assets of the client. He or she ensures activities and functions of information systems reflect client's policies and procedures, federal and state laws, and industry standards. The role is also responsible for ensuring disaster recovery and business continuity plans are in place for information assets.

This leader assumes a primary role in incident response and vulnerability management. This position manages the information security risks and directs IT resources in the management of risk analysis, remediation or acceptance. He or she will manage security risk remediation projects including deployment of new technologies, adoption of new procedures, and ongoing monitoring efforts.

This includes management of ongoing security awareness training and security incident response. He or she works closely with the Compliance Officer with respect to privacy issues and possible breach response. The Information Security serves as the organizational Information Security Officer and is the subject matter expert for information security administrative and technical controls, and as such, serves as a resource to the CIO and other departmental leaders.

He or she will make technology and process recommendations to the organization to ensure best practice. EXPERIENCE/QUALIFICATIONS: Four (4) plus years of information security experience IT Engineering experience in security systems (e.g., malware, server hardening, network intrusion detection, firewalls, etc) EDUCATION: Bachelor's degree or equivalent LICENSURES/CERTIFICATION: At least one of the following security certifications required: Certified Information System Security Professional (CISSP) CISM CISA Must successfully complete and maintain LA County Fire Card certification at the time of hire or within the first 30 days of employment DUTIES AND RESPONSIBILITIES ( These are the essential job functions for this position. The essential functions of this job include, but may not be limited to those listed in this job description

Employees hired for this position must be able to perform the essential function of this job without imposing significant risk of substantial harm to the health or safety of themselves or others) : Develops and maintains Information Security program through establishment of information security governance, policies, technology framework, best practices in IT, and staff education and certification Coordinates execution of security assessments, health checks and security enhancements. Develops, implements, and maintains information privacy and security policies, procedures, and guidelines through ongoing review and authorship. Performs periodic information privacy and security risk assessments while developing risk mitigation plans.

Evaluates, recommends, and implements systems for detection and prevention of information privacy and security breaches. Oversees and continually improves information security awareness training program Evaluates all new systems for compliance with information privacy and security policies and procedures, federal and state laws, and industry standards through a risk assessment process. Maintains current knowledge of federal and state information privacy and security laws and industry standards.

Coordinates the development of procedures and implementation of information technologies to ensure capability to recover from disaster or outages for each critical functional area of the organization Coordinates, designs, develops, maintains, and exercises (tests) the overall IT disaster recovery plans for each critical functional area of the organization . Works with IT and non-IT staff on security program initiatives and resolves security related issues. Provides leadership of projects and technical implementations.

Directs penetration tests, vulnerability scans and the vulnerability management program. Creates remediation plans to address relevant security findings. Monitors advancements in information security technologies and adapts new technology to enhance the company's security posture.

Creates security posture dashboard for management level reporting Manages information security risk register and risk remediation efforts emanating from the most recent risk analysis under applicable frameworks. Manages the relationship with Security Operations Center (SOC), threat Intelligence providers, including all professional monitoring of security events, logs, and alerts. Ensures and continually improves quality and value of the deliverables from these external partners.

Takes active leadership role in coordinating security incident response including identification, containment, remediation, forensics and, in collaboration with Compliance Officer, breach notification. Assesses all security tools for effectiveness, appropriateness, obsolescence and makes recommendations for future tool investments and maintains the enterprise security position dashboard Audits business associate compliance with existing BAA and regularly reviews BAAs or other contractual terms and conditions related to security while making recommendations Assists the CIO in development of information security presentations for executive leadership and board.