The C-SCRM Program Manager will perform the following duties and have overall responsibility for ... Define and enforce minimum security requirements for suppliers, including software integrity ...
The C-SCRM Program Manager will perform the following duties and have overall responsibility for ... Define and enforce minimum security requirements for suppliers, including software integrity ...
... compliance with airline security programs, TSA regulations, and contractual standards. The ... performance management • Ensure professional appearance and adherence to certification ...
... compliance with airline security programs, TSA regulations, and contractual standards. The ... performance management • Ensure professional appearance and adherence to certification ...
The C-SCRM Program Manager will perform the following duties and have overall responsibility for ... Define and enforce minimum security requirements for suppliers, including software integrity ...
The C-SCRM Program Manager will perform the following duties and have overall responsibility for ... Define and enforce minimum security requirements for suppliers, including software integrity ...
Security Supervisor - Armed
Houston, TX · On-site
Review Post orders and make recommendations for changes to senior management. * Report any major ... security programs. The successful candidate must have at least 2 years of security supervisor ...
Security Supervisor - Armed
Houston, TX · On-site
Review Post orders and make recommendations for changes to senior management. * Report any major ... security programs. The successful candidate must have at least 2 years of security supervisor ...
Security Supervisor - Armed
Houston, TX · On-site
Review Post orders and make recommendations for changes to senior management. * Report any major ... security programs. The successful candidate must have at least 2 years of security supervisor ...
Security Supervisor - Armed
Houston, TX · On-site
Review Post orders and make recommendations for changes to senior management. * Report any major ... security programs. The successful candidate must have at least 2 years of security supervisor ...
Manager V - DEPDC Senior Program Manager (Full-time, Temporary)
Huntsville, TX · On-site
$99K - $100K/yr
... programs ... Posting Information This position is security-sensitive and thereby subject to the provisions of ...
Manager V - DEPDC Senior Program Manager (Full-time, Temporary)
Huntsville, TX · On-site
$99K - $100K/yr
... programs ... Posting Information This position is security-sensitive and thereby subject to the provisions of ...
Security Guard
Houston, TX · On-site
$15.25 - $18.50/hr
Reporting of all pertinent issues and incidents to the operations manager, the client and other ... Must be able to operate and maintain site specific security programs. * Must have at least one year ...
Security Guard
Houston, TX · On-site
$15.25 - $18.50/hr
Reporting of all pertinent issues and incidents to the operations manager, the client and other ... Must be able to operate and maintain site specific security programs. * Must have at least one year ...
Director, Security
Houston, TX · On-site
Ensure travel security, journey management, residential security, and workforce protection programs are robust and effective Governance, Risk & Assurance * Establish and maintain security policies ...
Director, Security
Houston, TX · On-site
Ensure travel security, journey management, residential security, and workforce protection programs are robust and effective Governance, Risk & Assurance * Establish and maintain security policies ...
... program management, economics or closely related field. * Experience in Defense contracting or Defense financial management. * Current DoD Secret (or Higher) security clearance. * Experience with ...
... program management, economics or closely related field. * Experience in Defense contracting or Defense financial management. * Current DoD Secret (or Higher) security clearance. * Experience with ...
Director, Security
Houston, TX · On-site
$190 - $230/hr
Ensure travel security, journey management, residential security, and workforce protection programs are robust and effective**Governance, Risk & Assurance*** Establish and maintain security policies ...
New
Director, Security
Houston, TX · On-site
$190 - $230/hr
Ensure travel security, journey management, residential security, and workforce protection programs are robust and effective**Governance, Risk & Assurance*** Establish and maintain security policies ...
New
Deputy Project Manager
Houston, TX · On-site
$111K/yr
... program management, economics or closely related field. * Experience in Defense contracting or Defense financial management. * Current DoD Secret (or Higher) security clearance. * Experience with ...
Deputy Project Manager
Houston, TX · On-site
$111K/yr
... program management, economics or closely related field. * Experience in Defense contracting or Defense financial management. * Current DoD Secret (or Higher) security clearance. * Experience with ...
Director, Security
Houston, TX · On-site
$180 - $280/hr
... journey management, residential security, and workforce protection programs are robust and effectiveGovernance, Risk & AssuranceEstablish and maintain security policies, standards, and ...
Director, Security
Houston, TX · On-site
$180 - $280/hr
... journey management, residential security, and workforce protection programs are robust and effectiveGovernance, Risk & AssuranceEstablish and maintain security policies, standards, and ...
Part-Time Lakewood Greenway Security Guard
Houston, TX · On-site
$15.25 - $18.50/hr
Reporting of all pertinent issues and incidents to the operations manager, the client and other ... Must be able to operate and maintain site specific security programs. * Must have at least one year ...
Part-Time Lakewood Greenway Security Guard
Houston, TX · On-site
$15.25 - $18.50/hr
Reporting of all pertinent issues and incidents to the operations manager, the client and other ... Must be able to operate and maintain site specific security programs. * Must have at least one year ...
Security Officer - Commercial Operations
Houston, TX · On-site
$15.25 - $18.25/hr
Manage conflicts with diverse groups of people by utilizing de-escalation skills and effective ... Successfully complete the Security Program's new-hire training program within one month of the job ...
Security Officer - Commercial Operations
Houston, TX · On-site
$15.25 - $18.25/hr
Manage conflicts with diverse groups of people by utilizing de-escalation skills and effective ... Successfully complete the Security Program's new-hire training program within one month of the job ...
Here, you'll be supported by unique initiatives like our Dream Manager program, one-on-one guidance ... The Chief Information Security Officer (CISO) is a senior leadership role responsible for the ...
Here, you'll be supported by unique initiatives like our Dream Manager program, one-on-one guidance ... The Chief Information Security Officer (CISO) is a senior leadership role responsible for the ...
Virtual Chief Information Security Officer (vCISO)
Houston, TX · On-site
$180 - $230/hr
This position owns the customer security program at a strategic level, including security roadmaps ... Compliance and Risk Management * Lead compliance and audit readiness efforts for frameworks and ...
Virtual Chief Information Security Officer (vCISO)
Houston, TX · On-site
$180 - $230/hr
This position owns the customer security program at a strategic level, including security roadmaps ... Compliance and Risk Management * Lead compliance and audit readiness efforts for frameworks and ...
Sr. Security Risk Analyst
Houston, TX · On-site
Influence the continuous improvement of the security program. * Other duties as assigned OTHER SKILLS AND ABILITIES * Knowledge of risk management frameworks and applying risk methodologies.
Sr. Security Risk Analyst
Houston, TX · On-site
Influence the continuous improvement of the security program. * Other duties as assigned OTHER SKILLS AND ABILITIES * Knowledge of risk management frameworks and applying risk methodologies.
Influence the continuous improvement of the security program. * Other duties as assigned OTHER SKILLS AND ABILITIES * Knowledge of risk management frameworks and applying risk methodologies.
New
Influence the continuous improvement of the security program. * Other duties as assigned OTHER SKILLS AND ABILITIES * Knowledge of risk management frameworks and applying risk methodologies.
New
Program Information Manager
Houston, TX · On-site
$99K - $100K/yr
DEPADM The Opportunity The Program Information Manager (PIM) serves as the Enterprise Information ... Security and peace of mind - Life and disability insurance programs that provide protection when it ...
Program Information Manager
Houston, TX · On-site
$99K - $100K/yr
DEPADM The Opportunity The Program Information Manager (PIM) serves as the Enterprise Information ... Security and peace of mind - Life and disability insurance programs that provide protection when it ...
Virtual Chief Information Security Officer (vCISO)
Houston, TX · On-site
$150 - $230/hr
This position owns the customer security program at a strategic level, including security roadmaps ... Compliance and Risk Management * Lead compliance and audit readiness efforts for frameworks and ...
Virtual Chief Information Security Officer (vCISO)
Houston, TX · On-site
$150 - $230/hr
This position owns the customer security program at a strategic level, including security roadmaps ... Compliance and Risk Management * Lead compliance and audit readiness efforts for frameworks and ...
Security Program Manager information
See Conroe, TX salary details
$46.7K - $55.4K
0% of jobs
$55.4K - $64.2K
0% of jobs
$64.2K - $72.9K
0% of jobs
$72.9K - $81.7K
0% of jobs
$81.7K - $90.4K
2% of jobs
$90.4K - $99.2K
2% of jobs
$99.2K - $108K
0% of jobs
$116.2K is the 25th percentile. Wages below this are outliers.
$108K - $116.7K
22% of jobs
$116.7K - $125.5K
0% of jobs
The median wage is $134K / yr.
$125.5K - $134.2K
24% of jobs
$138.6K is the 75th percentile. Wages above this are outliers.
$134.2K - $143K
49% of jobs
$46.7K
$127.6K
$143K
How much do security program manager jobs pay per year?
What are the key skills and qualifications needed to thrive as a security program manager?
To thrive as a Security Program Manager, you need a solid background in information security, risk management, and project management, typically bolstered by a relevant degree and experience in security operations. Experience with security frameworks (like NIST or ISO 27001), tools such as SIEM platforms, and certifications like CISSP or PMP are highly valued. Excellent cross-functional communication, leadership, and problem-solving abilities help you coordinate teams and drive initiatives forward. These capabilities are crucial to effectively lead security programs, mitigate risks, and ensure organizational compliance in a dynamic threat landscape.
What is a security program manager?
A Security Program Manager (SPM) oversees an organization's security initiatives, ensuring they align with business objectives and compliance requirements. They coordinate security programs, manage risks, and implement policies to protect assets, data, and infrastructure. SPMs work closely with cross-functional teams, including IT, legal, and leadership, to enhance security posture. Their role involves assessing threats, driving security awareness, and managing security projects efficiently.
What are some typical challenges faced by security program managers, and how are they addressed?
Security Program Managers often face challenges such as balancing evolving cybersecurity threats with business objectives, managing cross-departmental initiatives, and ensuring ongoing compliance with industry standards. Success in this role typically involves continuous learning to stay ahead of threat trends, fostering collaboration among IT, compliance, and executive stakeholders, and implementing clear processes for incident response and policy enforcement. Program Managers regularly review and adjust security strategies, conduct gap analyses, and ensure team alignment through effective communication and stakeholder engagement. Proactively addressing these challenges helps maintain robust security postures while enabling organizations to achieve their goals.

$136K/yr
Full-time
Re-posted 3 days ago
Job description
This position will be based full-time in our Houston, TX office located at 990 Town & Country Blvd in CityCentre.
POSITION SUMMARY: This position establishes, leads, and governs the enterprise-wide Cybersecurity Supply Chain Risk Management (C SCRM) program for both Operational Technology (OT or digital instrumentation and controls) and Information Technology (IT). The C-SCRM Program Manager reports to the Supervisor, Information Security and leads an interdisciplinary team of subject matter experts from Information Security, Instrumentation and Controls Engineering and Manufacturing (i.e., Supply Chain), and Plant Services Cyber Security to deliver a scalable, defensible, and compliant supply chain assurance program for digital assets and software systems that are safety-related, augmented requirements, physical security-related, or emergency preparedness related in accordance with NIST SP 800-161, NIST SP 800-53 (SR/SA/RA/PM), NIST SP 800-82, and nuclear sector guidance (NEI 08-09, Regulatory Guide 5.71, RIS 2015-08 Rev 1).
ESSENTIAL DUTIES AND RESPONSIBILITIES:
The C-SCRM Program Manager will perform the following duties and have overall responsibility for the administration and implementation of the C-SCRM Program. Will be required to perform other duties as assigned.
Program Governance and Strategy
- Develop and manage the enterprise CSCRM program for OT (digital I&C platforms, field devices, PLCs, networked sensors, safetyrelated cyber systems) and IT (commercial software, COTS hardware, servers, cloud services, network equipment).
- Create and maintain policies, standards, and procedures aligned to NIST SP 800161 and NIST SP 80053 SR, SA, RA, PM control families.
- Integrate nuclear sector guidance (NEI 0809, RG-5.71, RIS 201508 Rev 1) into supply chain expectations for safetyrelated and securityrelated digital systems.
- Establish supplier risk tiering and criticality criteria covering safetyrelated functions, digital asset categorization, and impacts on plant operations and corporate environments.
- Lead the CSCRM Steering Committee and drive alignment between Supply Chain, Engineering, Plant Services Cyber Security, Legal, QA, and Supplier Quality Assurance
Supplier Lifecycle Management
- Oversee the complete supplier lifecycle: inherent risk assessments, due diligence, technical evaluation, contracting, onboarding, continuous monitoring, reassessment, and offboarding.
- Ensure contractual language includes security requirements, SBOM/MBOM deliverables, secure SDLC expectations, vulnerability disclosure procedures, and subtier supplier transparency.
- Implement structured workflows for thirdparty risk assessments that incorporate NIST SP 80053 SR/SA obligations, NEI 0809 defensive architecture principles, and NIST SP 80082 OT constraints.
- Coordinate supplier audits and assessments, ensuring traceability of security commitments and evidence of control effectiveness.
Technical Assurance for OT and IT
- Define and enforce minimum security requirements for suppliers, including software integrity controls, code signing, firmware assurance, and supply chain provenance.
- Evaluate SBOMs for software, firmware, and embedded system components; drive vulnerability assessment and remediation plans based on exploitability in OT/ICS contexts.
- Oversee technical acceptance processes such as Factory Acceptance Testing (FAT), Site Acceptance Testing (SAT), configuration verification, deterministic communication requirements, and architecture compliance checks for digital I&C components.
- Support secure engineering design reviews for systems that integrate COTS hardware, virtualized servers, network infrastructure, and embedded digital components.
- Coordinate risk analysis and compensating control strategies where patching or upgrading is constrained in OT environments.
Risk Analysis and Decision Support
- Perform qualitative and quantitative supply chain risk assessments covering vendor security posture, component integrity, lifecycle support, and cyber threat exposure.
- Document risk findings, residual risk calculations, and recommended mitigations; present clear decision options to executive leadership.
- Develop Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) to track program maturity and supplier health.
- Maintain centralized risk evidence repositories supporting compliance and audit readiness.
Compliance, Audit, and Regulatory Engagement
- Ensure the CSCRM program adheres to NIST SP 800161, NIST SP 80053, NIST SP 80082, NEI 0809, RG 5.71, and RIS 201508 Rev 1 requirements.
- Prepare for internal audits, external assessments, and US NRC reviews; provide documentation showing control compliance and technical baselines.
- Coordinate with Engineering and Plant Services Cyber Security to ensure digital I&C assets meet expectations for secure procurement, configuration control, and lifecycle management.
Training, Communications, and Stakeholder Engagement
- Develop training and communication materials to improve supply chain security awareness across engineering, operations, IT, and procurement teams.
- Coach project managers, system owners, and procurement professionals on secure supplier interactions and risk evaluation processes.
- Communicate supply chain threats, vulnerabilities, mitigations, and accepted risks to senior leadership in clear, actionable terms.
CORE COMPETENCIES: To perform the job successfully, the individual should demonstrate competencies in performing the essential functions of this position by performing satisfactorily in each of these competencies.
- Problem solving: Identifies and resolves problems in a timely manner, gathers and reviews information appropriately. Uses own judgment and acts independently; seeks input from other team members as appropriate for complex or sensitive situations.
- Oral/written communication: Listens carefully and speaks clearly and professionally in all situations. Edits work for accuracy and clarity, is able to create, read and interpret complex written information. Ability to develop strong interpersonal networks within the organization.
- Planning/organizing: Prioritizes and plans work activities, organizes personal and project timelines and deadlines, tracks project timelines and deadlines, and uses time efficiently.
- Adaptability: Adapts to changes in the work environment, manages competing demands and is able to deal with frequent interruptions, changes, delays, or unexpected events.
- Dependability: Consistently on time and at work, responds to management expectations and solicits feedback to improve performance.
- Team Building: Capable of developing strong interpersonal networks and trust within the organization.
- Safety Culture: Adheres to the NuScale safety culture and is expected to model safe behavior and influence peers to meet high standards.
- Quality Assurance: Commits to the understanding and implementation of quality assurance regulations, standards and guidelines of 10 CFR 50 Appendix B, 10 CFR 21, and NQA-1.
MINIMUM SKILLS, QUALIFICATIONS AND ABILITIES:
- Education/Certification: A minimum of a bachelor's degree in Cybersecurity, Computer Science, Engineering, or related field is required. Alternatively, an additional 4 years (12 years total) of equivalent full-time nuclear industry cyber security experience may be considered in lieu of a degree. NSCP 800-161 Foundation Certificate or equivalent is required. Professional certifications such as CISSP, CISM, CRISC, GICSP, CISA, or ISA/IEC 62443 certificates are preferred.
- Experience: A minimum of 8 years of full-time cybersecurity experience with a focus on supply chain risk, vendor management, or secure procurement is required. Must have experience across OT/ICS and IT cybersecurity, including digital I&C systems, embedded controllers, industrial networking, and enterprise IT infrastructure. Additional required experience included:
- Detailed knowledge of NIST SP 800161, NIST SP 80082, and NIST SP 80053 control families related to supply chain, assurance, and risk assessment (SR/SA/RA/PM) .
- Familiarity with nuclear regulatory guidance including NEI 0809, RG 5.71, and RIS 201508 Rev 1.
- Demonstrated ability to lead crossdisciplinary teams and manage complex supplier ecosystems.
- Strong written and verbal communication skills; ability to influence at all organizational levels. Experience in nuclear energy, critical infrastructure, or similarly regulated sectors preferred.
- Working knowledge of SBOM formats (SPDX, CycloneDX) and secure software development lifecycle (SSDLC) practices (e.g., NIST SP 800-218).
- Understanding of OT protocols, deterministic network architectures, physical/functional separation concepts, and secure digital I&C implementation (e.g., Regulatory Guide 1.152, Revision 3, Regulatory Position C.2).
- Industry Requirements: Eligible to work under Department of Energy 10 CFR Part 810.
PHYSICAL DEMANDS: The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- Ability to understand and communicate clearly using a phone, personal interaction, and computers.
- Ability to learn new job functions and comprehend and understand new concepts quickly and apply them accurately in a rapidly evolving environment.
- The employee frequently is required; to sit and stand; walk; bend, use hands to operate office equipment; and reach with hands and arms. Ability to lift ten to fifteen pounds.
Disclaimer: Employee(s) must perform the essential duties and responsibilities with or without reasonable accommodation efficiently and accurately without causing significant safety threat to self or others. The above statements are intended to describe the general nature and level of work being performed by employee(s) assigned to this classification. They are not intended to be construed as an exhaustive list of all responsibilities, duties and/or skills required of all employees in this classification.
NuScale Power, LLC is an equal opportunity employer and does not discriminate against otherwise qualified applicants on the basis of race, color, creed, religion, ancestry, age, sex, marital status, national origin, disability or handicap, or veteran status.
Pay and Benefits:
At NuScale, compensation decisions are determined using factors such as relevant job-related skills, full-time working experience, education and training, equity within the department.
For information on employee benefits, please visit our Careers Overview page: Employee Benefits | NuScale Power
Employment Type: Full-TimeAbout NuScale Power
Sourced by ZipRecruiter
Industry
Oil and gas extraction
Company size
501 - 1,000 Employees
Headquarters location
Portland, OR, US
Year founded
2007