The IT Security Program Manager is responsible for executing and managing the day-to-day operations of Recovery Centers of America's cybersecurity program. Reporting to the manager of infrastructure ...
The IT Security Program Manager is responsible for executing and managing the day-to-day operations of Recovery Centers of America's cybersecurity program. Reporting to the manager of infrastructure ...
Information Security Program Lead
Cranberry Township, PA · On-site
$125K - $152K/yr
Own and maintain the Information Security Management System (ISMS), ensuring alignment with ISO ... Contribute to security awareness programs and training initiatives, adapting content for regional ...
Information Security Program Lead
Cranberry Township, PA · On-site
$125K - $152K/yr
Own and maintain the Information Security Management System (ISMS), ensuring alignment with ISO ... Contribute to security awareness programs and training initiatives, adapting content for regional ...
Information Security Program Lead
$125K - $152K/yr
Own and maintain the Information Security Management System (ISMS), ensuring alignment with ISO ... Contribute to security awareness programs and training initiatives, adapting content for regional ...
Information Security Program Lead
$125K - $152K/yr
Own and maintain the Information Security Management System (ISMS), ensuring alignment with ISO ... Contribute to security awareness programs and training initiatives, adapting content for regional ...
Cybersecurity Program Management * Support IT security goals and objectives to reduce overall organizational risk * Communicate the value of IT security throughout all levels of organization ...
Cybersecurity Program Management * Support IT security goals and objectives to reduce overall organizational risk * Communicate the value of IT security throughout all levels of organization ...
Cybersecurity Program Management * Support IT security goals and objectives to reduce overall organizational risk * Communicate the value of IT security throughout all levels of organization ...
Cybersecurity Program Management * Support IT security goals and objectives to reduce overall organizational risk * Communicate the value of IT security throughout all levels of organization ...
Cybersecurity Program Management * Support IT security goals and objectives to reduce overall organizational risk * Communicate the value of IT security throughout all levels of organization ...
Cybersecurity Program Management * Support IT security goals and objectives to reduce overall organizational risk * Communicate the value of IT security throughout all levels of organization ...
They are seeking an Information Systems Security Manager III to oversee and manage the information security program implementation for the Naval Surface Warfare Center Philadelphia Division, focusing ...
They are seeking an Information Systems Security Manager III to oversee and manage the information security program implementation for the Naval Surface Warfare Center Philadelphia Division, focusing ...
Experience managing security programs supporting classified systems and information * Demonstrated experience implementing and maintaining NIST 800-171 and CMMC compliance Technical Knowledge
Experience managing security programs supporting classified systems and information * Demonstrated experience implementing and maintaining NIST 800-171 and CMMC compliance Technical Knowledge
The Information Systems Security Manager III will support the Naval Surface Warfare Center Philadelphia Division, overseeing the implementation of information security programs and ensuring ...
The Information Systems Security Manager III will support the Naval Surface Warfare Center Philadelphia Division, overseeing the implementation of information security programs and ensuring ...
The Information Systems Security Manager III will support the Naval Surface Warfare Center Philadelphia Division, overseeing the implementation of information security programs and ensuring ...
The Information Systems Security Manager III will support the Naval Surface Warfare Center Philadelphia Division, overseeing the implementation of information security programs and ensuring ...
Information System Security Manager (ISSM) - Contingent Upon Contract Award
Philadelphia, PA · On-site
$123K - $187K/yr
Cybersecurity Program & Risk Management * Support information security goals and initiatives that reduce organizational cybersecurity risk. * Coordinate cybersecurity activities and communicate ...
New
Quick apply
Information System Security Manager (ISSM) - Contingent Upon Contract Award
Philadelphia, PA · On-site
$123K - $187K/yr
Cybersecurity Program & Risk Management * Support information security goals and initiatives that reduce organizational cybersecurity risk. * Coordinate cybersecurity activities and communicate ...
New
Security Program Leadership: Design and manage the enterprise-wide information security strategy, aligning security initiatives with software development lifecycles (SDLC) and business goals. * Risk ...
Security Program Leadership: Design and manage the enterprise-wide information security strategy, aligning security initiatives with software development lifecycles (SDLC) and business goals. * Risk ...
Security Program Leadership: Design and manage the enterprise-wide information security strategy, aligning security initiatives with software development lifecycles (SDLC) and business goals. * Risk ...
Security Program Leadership: Design and manage the enterprise-wide information security strategy, aligning security initiatives with software development lifecycles (SDLC) and business goals. * Risk ...
Manage and evolve vulnerability management- tooling, reporting, and remediation governance. You ... Under the direction VP, TechOps, improve the Proscia Information Security Program, with a focus on ...
Manage and evolve vulnerability management- tooling, reporting, and remediation governance. You ... Under the direction VP, TechOps, improve the Proscia Information Security Program, with a focus on ...
Manage and evolve vulnerability management- tooling, reporting, and remediation governance. You ... Under the direction VP, TechOps, improve the Proscia Information Security Program, with a focus on ...
Manage and evolve vulnerability management- tooling, reporting, and remediation governance. You ... Under the direction VP, TechOps, improve the Proscia Information Security Program, with a focus on ...
Global Information Security Lead 100% (f/m/d)
Indiana, PA · On-site
$90 - $120/hr
Intro Information security is central to earning the trust of our global customers and protecting ... Familiarity with ISO 27001 or SOC 2 programs * Experience with vulnerability management and ...
Global Information Security Lead 100% (f/m/d)
Indiana, PA · On-site
$90 - $120/hr
Intro Information security is central to earning the trust of our global customers and protecting ... Familiarity with ISO 27001 or SOC 2 programs * Experience with vulnerability management and ...
Qualifications: 8+ years of experience managing cybersecurity and the technical execution of a cybersecurity program, including the utilization of Security Information and Event Management (SIEM ...
Qualifications: 8+ years of experience managing cybersecurity and the technical execution of a cybersecurity program, including the utilization of Security Information and Event Management (SIEM ...
Director IT Security
Eighty Four, PA · On-site
Qualifications: 8+ years of experience managing cybersecurity and the technical execution of a cybersecurity program, including the utilization of Security Information and Event Management (SIEM ...
Director IT Security
Eighty Four, PA · On-site
Qualifications: 8+ years of experience managing cybersecurity and the technical execution of a cybersecurity program, including the utilization of Security Information and Event Management (SIEM ...
The Manager, Information Security, will join a dynamic security team that is responsible for ... WorkWell wellness program * Free use of building gym * Caregiving assistance with Bright Horizons ...
The Manager, Information Security, will join a dynamic security team that is responsible for ... WorkWell wellness program * Free use of building gym * Caregiving assistance with Bright Horizons ...
Assistant Director, IT Security
Blue Bell, PA · On-site
$75K - $90K/yr
... management of systems that support institutional Information Security objectives. The position assists the Senior Director with the implementation and administration of the IT Security program. The ...
Assistant Director, IT Security
Blue Bell, PA · On-site
$75K - $90K/yr
... management of systems that support institutional Information Security objectives. The position assists the Senior Director with the implementation and administration of the IT Security program. The ...
Information Security Program Manager information
See Pennsylvania salary details
$54.6K - $64.9K
0% of jobs
$64.9K - $75.1K
0% of jobs
$75.1K - $85.4K
0% of jobs
$85.4K - $95.6K
0% of jobs
$95.6K - $105.9K
2% of jobs
$105.9K - $116.1K
2% of jobs
$116.1K - $126.4K
0% of jobs
$136K is the 25th percentile. Wages below this are outliers.
$126.4K - $136.6K
22% of jobs
$136.6K - $146.9K
0% of jobs
The median wage is $156.9K / yr.
$146.9K - $157.1K
24% of jobs
$162.2K is the 75th percentile. Wages above this are outliers.
$157.1K - $167.4K
49% of jobs
$54.6K
$149.4K
$167.4K
How much do information security program manager jobs pay per year?
What is an information security program manager?
What are some typical challenges faced by information security program managers when implementing new security initiatives across an organization?
What are the key skills and qualifications needed to thrive as an information security program manager, and why are they important?
What is the difference between Information Security Program Manager vs Security Analyst?
| Aspect | Information Security Program Manager | Security Analyst |
|---|---|---|
| Certifications | CISSP, CISM, PMP | CompTIA Security+, CISSP (optional) |
| Work Environment | Oversees security programs, manages teams, strategic planning | Monitors security systems, analyzes threats, implements security measures |
| Employer & Industry Usage | Used in organizations with complex security needs, corporate sectors | Common in IT departments, security operations centers |
The main difference is that an Information Security Program Manager focuses on managing and coordinating security initiatives at a strategic level, while a Security Analyst primarily monitors and analyzes security threats to protect systems. The Program Manager leads security programs, whereas the Analyst executes security measures and responds to incidents.
What cities in Pennsylvania are hiring for Information Security Program Manager jobs?
Cities in Pennsylvania with the most Information Security Program Manager job openings:

IT Security Program Manager
Devon, PA
5.3
Based on 22 frontline employees who took The Breakroom Quiz
People enjoy working here
Respectful managers
Full-time
Re-posted 26 days ago
Job description
Position Overview:
The IT Security Program Manager is responsible for executing and managing the day-to-day operations of Recovery Centers of America's cybersecurity program. Reporting to the manager of infrastructure under the IT OPS director and ensures that RCA's security posture remains compliant with HIPAA, HITECH, and NIST 800-53 standards while continuously improving the effectiveness of the organization's security controls and risk management framework.
This role will coordinate and perform audits, oversee third-party risk management, manage RCA's security awareness and phishing programs, drive policy governance, and ensure the timely resolution of open risk items and vulnerabilities. The ideal candidate is an organized, hands-on leader with a strong understanding of healthcare security and compliance who can align security initiatives with RCA's mission of saving one million lives.
Essential Duties and Responsibilities
Program Management & Governance
- Manage the daily operations of RCA's cybersecurity program under the guidance of the CISO.
- Coordinate and track the completion of internal and external security audits, including HIPAA, SOC 2, and NIST-based assessments.
- Maintain and monitor the Information Security Risk Register, ensuring timely resolution of identified issues and mitigation of critical findings.
- Lead tabletop exercises and incident response simulations to test and improve RCA's preparedness and business continuity planning.
- Collaborate with RCA leadership and department heads to ensure that security policies and controls are understood and effectively implemented across all business units.
Third-Party Risk & Vendor Management
- Manage the third-party risk assessment program, ensuring that all vendors with access to PHI or critical systems undergo security evaluation and periodic reassessment.
- Review BAAs, security questionnaires, and compliance attestations; ensure corrective action for identified gaps.
- Partner with Procurement and Legal to integrate security requirements into new and existing vendor contracts.
Policy, Compliance, and Reporting
- Work with the CISO to review, update, and publish information security policies, standards, and procedures in accordance with HIPAA, HITECH, and NIST frameworks.
- Develop dashboards and recurring reports to track security metrics, compliance posture, and program maturity for presentation to the CISO and executive leadership.
- Monitor and interpret changes to regulatory requirements, ensuring timely updates to RCA's compliance program.
Security Awareness & Training
- Administer and optimize RCA's KnowBe4 Security Awareness and Phishing Training Program.
- Track user engagement and training completion rates, and provide metrics and recommendations to leadership.
- Develop creative awareness campaigns to strengthen RCA's security culture.
Vulnerability & Infrastructure Management
- Identify and track critical infrastructure vulnerabilities, working with IT and Infrastructure teams to ensure remediation and continuous monitoring.
- Oversee MDM security, ensuring appropriate device controls, encryption, and enforcement of mobile security policies.
- Support the CISO in analyzing threat intelligence, vulnerability trends, and endpoint security performance (e.g., CrowdStrike, firewall alerts).
Risk and Compliance Leadership
- Ensure continuous compliance with HIPAA, HITECH, and NIST 800-53 / 800-171 requirements.
- Coordinate with Compliance, Legal, and Clinical leadership to ensure consistent risk management practices.
- Participate in post-incident reviews, documenting lessons learned and recommending process improvements.
Education
- Bachelor's degree in Information Security, Computer Science, Information Technology, or related field required.
Experience
- Minimum of 5-7 years of progressive experience in cybersecurity, IT risk management, or audit within a regulated environment (preferably healthcare).
- At least 2 years in a program management or leadership role overseeing information security functions.
- Strong working knowledge of HIPAA, NIST 800-53, HITRUST, and security risk management frameworks.
Certifications (preferred but not required)
- Security +, CISSP, CISM, CRISC, HCISPP, or equivalent security certification.
- PMP or similar project management certification is a plus.
Technical Skills
- Understanding of endpoint protection, SIEM tools, MDM platforms (e.g., Intune), and vulnerability management solutions.
- Experience with vendor risk tools, audit tracking systems, and compliance reporting.
- Familiarity with Microsoft 365 Security Suite, KnowBe4, and GRC platforms.
Core Competencies
- Strong analytical and problem-solving skills.
- Excellent written and verbal communication skills, with the ability to translate technical risks for non-technical stakeholders.
- Highly organized and detail-oriented, with the ability to manage multiple priorities simultaneously.
- Demonstrated ability to build cross-functional relationships and drive accountability.
- Passionate about RCA's mission and maintaining the privacy and security of patient information
Travel
- Limited travel is required for this position
- This position is primarily a remote position
This job description is not designed to cover or contain a comprehensive listing of all activities, duties, or responsibilities required of the employee. Duties, responsibilities, and activities may change at any time, with or without notice, to meet the evolving needs of the organization. Nothing in this job description alters the at-will nature of employment, and either RCA or the employee may terminate the employment relationship at any time, with or without cause or notice.
RCA is committed to providing reasonable accommodations to qualified individuals with disabilities to enable them to perform the essential functions of their role. Employees or applicants requiring accommodation should contact Human Resources to initiate the interactive accommodation process.
This position primarily involves sedentary work, including extended periods of sitting and computer use. The employee must be able to communicate effectively via phone, video conferencing, and written correspondence.
#EXEC
About Recovery Centers of America
Sourced by ZipRecruiter
Recovery Centers of America (RCA) is a ground-breaking addiction and mental health treatment provider, setting the standard when it comes to accessible, affordable, and effective care. RCA understands the heartache, damage, and pain substance use disorder causes a person as well as their family and friends. Not only do we believe that addiction treatment should be affordable, accessible, and evidence-based, but our driven, compassionate, and dedicated employees make those beliefs a reality.
Industry
Health care and social assistance
Company size
1,001 - 5,000 Employees
Headquarters location
King of Prussia, PA, US
Year founded
2015
Website
What Recovery Centers of America employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom