Run the vulnerability scanning program across AWS and Azure cloud environments and on-premises ... Policy management: Own the security policy library - ensure policies and standards are current ...
Run the vulnerability scanning program across AWS and Azure cloud environments and on-premises ... Policy management: Own the security policy library - ensure policies and standards are current ...
Gen-AI Program Lead
Portland, OR · On-site
The Gen-AI space demands a unique combination of technical knowledge, program management capabilities, and the ability to navigate complex governance and security considerations. A seasoned Gen-AI ...
Quick apply
Gen-AI Program Lead
Portland, OR · On-site
The Gen-AI space demands a unique combination of technical knowledge, program management capabilities, and the ability to navigate complex governance and security considerations. A seasoned Gen-AI ...
Security Assistant
Portland, OR · On-site
$43K/yr
The Personnel Security Program assures that all appointees have the appropriate level of security ... States Office of Personnel Management's website at transcript must be submitted with your ...
Security Assistant
Portland, OR · On-site
$43K/yr
The Personnel Security Program assures that all appointees have the appropriate level of security ... States Office of Personnel Management's website at transcript must be submitted with your ...
You\'ll be the person who keeps the program examiner-ready by default: coherent policy architecture ... Manage relationships with internal audit (3LOD) and external assessors (SOC 2, FFIEC CAT, regulator ...
You\'ll be the person who keeps the program examiner-ready by default: coherent policy architecture ... Manage relationships with internal audit (3LOD) and external assessors (SOC 2, FFIEC CAT, regulator ...
Program Manager III - South Korea
Portland, OR · On-site
$177K - $196K/yr
Understands OCONUS (Outside Continental United States), Government security requirements and ... The Program Manager is actively involved at an operational level in reviewing the relevant costs ...
Program Manager III - South Korea
Portland, OR · On-site
$177K - $196K/yr
Understands OCONUS (Outside Continental United States), Government security requirements and ... The Program Manager is actively involved at an operational level in reviewing the relevant costs ...
Program Manager III - South Korea
$177K - $196K/yr
Understands OCONUS (Outside Continental United States), Government security requirements and ... The Program Manager is actively involved at an operational level in reviewing the relevant costs ...
Quick apply
Program Manager III - South Korea
$177K - $196K/yr
Understands OCONUS (Outside Continental United States), Government security requirements and ... The Program Manager is actively involved at an operational level in reviewing the relevant costs ...
Proactively manage a joint Information Security program that ensures the integrity, confidentiality, and availability of Client's information assets in Custody of HCL 6.Ensure that the control ...
Proactively manage a joint Information Security program that ensures the integrity, confidentiality, and availability of Client's information assets in Custody of HCL 6.Ensure that the control ...
Information Systems Security Officer
Camas, WA · On-site
$89K - $140K/yr
Responsibilities include implementation of the requirements of Risk Management Framework, including the Joint Special Access Program (SAP) Implementation Guide (JSIG), NIST 800-53, or other security ...
Information Systems Security Officer
Camas, WA · On-site
$89K - $140K/yr
Responsibilities include implementation of the requirements of Risk Management Framework, including the Joint Special Access Program (SAP) Implementation Guide (JSIG), NIST 800-53, or other security ...
Responsibilities include implementation of the requirements of Risk Management Framework, including the Joint Special Access Program (SAP) Implementation Guide (JSIG), NIST 800-53, or other security ...
Responsibilities include implementation of the requirements of Risk Management Framework, including the Joint Special Access Program (SAP) Implementation Guide (JSIG), NIST 800-53, or other security ...
Technical Program Director
Portland, OR · On-site
$87/hr
... Security, Quality Assurance, Business Processes, Technical Architecture, and Data Governance. This position oversees all aspects of the program life cycle, using a formal program management ...
Technical Program Director
Portland, OR · On-site
$87/hr
... Security, Quality Assurance, Business Processes, Technical Architecture, and Data Governance. This position oversees all aspects of the program life cycle, using a formal program management ...
Program Manager, Global Technical Services
$136K - $177K/yr
... including Security, Legal, Compliance, Product Language, Enablement, and Marketing), you will ... Experience with program/portfolio management tools (JIRA/Confluence). Strategy, Data & Process ...
New
Program Manager, Global Technical Services
$136K - $177K/yr
... including Security, Legal, Compliance, Product Language, Enablement, and Marketing), you will ... Experience with program/portfolio management tools (JIRA/Confluence). Strategy, Data & Process ...
New
Vulnerability and Exposure Management Program Manager
Gresham, OR · On-site
$136K/yr
... Program Manager is accountable for the enterprise vulnerability management strategy and operating ... Partner across CIO/CTO organizations, security, engineering, and business lines to embed ...
Vulnerability and Exposure Management Program Manager
Gresham, OR · On-site
$136K/yr
... Program Manager is accountable for the enterprise vulnerability management strategy and operating ... Partner across CIO/CTO organizations, security, engineering, and business lines to embed ...
... security and stability. Residents at Respite receive three meals a day, interact in the milieu ... Management reserves the right to modify, add or remove duties as necessary. * Establishes work ...
... security and stability. Residents at Respite receive three meals a day, interact in the milieu ... Management reserves the right to modify, add or remove duties as necessary. * Establishes work ...
Physical Security Specialist
Portland, OR · On-site +1
$106K - $149K/yr
Step into a high-visibility advisory role, providing direct counsel to the Physical Security Manager and shaping the direction and effectiveness of BPA's entire security program. * Transition from ...
Physical Security Specialist
Portland, OR · On-site +1
$106K - $149K/yr
Step into a high-visibility advisory role, providing direct counsel to the Physical Security Manager and shaping the direction and effectiveness of BPA's entire security program. * Transition from ...
Real Estate Development Program Manager
Sherwood, OR · On-site
$72K - $84K/yr
Real Estate Development Program Manager - CASA of Oregon This position is classified as Exempt and ... Today, we enhance economic and housing security for Oregonians in need by working in four key areas:
Real Estate Development Program Manager
Sherwood, OR · On-site
$72K - $84K/yr
Real Estate Development Program Manager - CASA of Oregon This position is classified as Exempt and ... Today, we enhance economic and housing security for Oregonians in need by working in four key areas:
You will own the technical direction of Panthalassa's information security program across corporate infrastructure, cloud environments, engineering systems, identity and access management, enterprise ...
You will own the technical direction of Panthalassa's information security program across corporate infrastructure, cloud environments, engineering systems, identity and access management, enterprise ...
You will own the technical direction of Panthalassa's information security program across corporate infrastructure, cloud environments, engineering systems, identity and access management, enterprise ...
Quick apply
You will own the technical direction of Panthalassa's information security program across corporate infrastructure, cloud environments, engineering systems, identity and access management, enterprise ...
Director of Information Security
Portland, OR · On-site
You will own the technical direction of Panthalassa's information security program across corporate infrastructure, cloud environments, engineering systems, identity and access management, enterprise ...
Director of Information Security
Portland, OR · On-site
You will own the technical direction of Panthalassa's information security program across corporate infrastructure, cloud environments, engineering systems, identity and access management, enterprise ...
You will own the technical direction of Panthalassa's information security program across corporate infrastructure, cloud environments, engineering systems, identity and access management, enterprise ...
Quick apply
You will own the technical direction of Panthalassa's information security program across corporate infrastructure, cloud environments, engineering systems, identity and access management, enterprise ...
Program Supervisor
Portland, OR · On-site
$88K - $96K/yr
Program Manager FLSA status: Exempt/Salaried Location : Portland, OR Job Type: Full Time (Eligible ... Security Parenting, etc.), and support quality improvement and data collection activities.
Program Supervisor
Portland, OR · On-site
$88K - $96K/yr
Program Manager FLSA status: Exempt/Salaried Location : Portland, OR Job Type: Full Time (Eligible ... Security Parenting, etc.), and support quality improvement and data collection activities.
Security Program Manager information
See Portland, OR salary details
$57.8K - $68.6K
0% of jobs
$68.6K - $79.5K
0% of jobs
$79.5K - $90.3K
0% of jobs
$90.3K - $101.2K
0% of jobs
$101.2K - $112K
2% of jobs
$112K - $122.9K
2% of jobs
$122.9K - $133.7K
0% of jobs
$143.9K is the 25th percentile. Wages below this are outliers.
$133.7K - $144.6K
22% of jobs
$144.6K - $155.4K
0% of jobs
The median wage is $166K / yr.
$155.4K - $166.3K
24% of jobs
$171.6K is the 75th percentile. Wages above this are outliers.
$166.3K - $177.1K
49% of jobs
$57.8K
$158K
$177.1K
How much do security program manager jobs pay per year?
What jobs pay 2000 a day?
What are the key skills and qualifications needed to thrive in the Security Program Manager position, and why are they important?
To thrive as a Security Program Manager, you need a solid background in information security, risk management, and project management, typically bolstered by a relevant degree and experience in security operations. Experience with security frameworks (like NIST or ISO 27001), tools such as SIEM platforms, and certifications like CISSP or PMP are highly valued. Excellent cross-functional communication, leadership, and problem-solving abilities help you coordinate teams and drive initiatives forward. These capabilities are crucial to effectively lead security programs, mitigate risks, and ensure organizational compliance in a dynamic threat landscape.
Can you make $500,000 a year in cyber security?
What is a Security Program Manager job?
A Security Program Manager (SPM) oversees an organization's security initiatives, ensuring they align with business objectives and compliance requirements. They coordinate security programs, manage risks, and implement policies to protect assets, data, and infrastructure. SPMs work closely with cross-functional teams, including IT, legal, and leadership, to enhance security posture. Their role involves assessing threats, driving security awareness, and managing security projects efficiently.
How much does a security manager get paid?
What are some typical challenges faced by Security Program Managers, and how are they addressed?
Security Program Managers often face challenges such as balancing evolving cybersecurity threats with business objectives, managing cross-departmental initiatives, and ensuring ongoing compliance with industry standards. Success in this role typically involves continuous learning to stay ahead of threat trends, fostering collaboration among IT, compliance, and executive stakeholders, and implementing clear processes for incident response and policy enforcement. Program Managers regularly review and adjust security strategies, conduct gap analyses, and ensure team alignment through effective communication and stakeholder engagement. Proactively addressing these challenges helps maintain robust security postures while enabling organizations to achieve their goals.
What is the role of a security program manager?
Other
Medical, Dental, Vision, Retirement, PTO
Posted 21 days ago
Job description
The Company
Cypress Creek Energy is powering a sustainable future, one project at a time. We develop, finance, own and operate utility-scale and distributed solar and storage projects across the country. Fostering a diverse group of innovative thinkers from all backgrounds, Cypress people are drawn to work in a purpose-driven organization. We hope you will join us.
Overview
Cypress Creek Energy is hiring an Information Security Manager to lead the company's security operations and compliance program. This is a hands-on individual contributor role designed for a senior technical security professional ready to take ownership of a complete program - with the opportunity to grow into a leader of a team as the function scales.Â
The successful candidate brings a balance of deep technical execution and program-level compliance maturity. You will own the day-to-day security tooling stack, lead the company's NIST-based compliance program, shape policy in emerging areas including artificial intelligence, and maintain an accurate view of every system in the environment. You will report directly to the Chief Technology Officer and partner closely with IT, Counsels, and business stakeholders across the company.Â
Responsibilities
Security Operations & EngineeringÂ
- Endpoint security:Â Administer and tune Microsoft Defender across the endpoint estate, including policy configuration, alert triage, response, and reporting.Â
- Network and access security:Â Manage the Zscaler platform (ZIA/ZPA), including policy development, traffic inspection, access controls, and integration with identity systems.Â
- SIEM operations:Â Own SIEM tuning, detection engineering, log source onboarding, alerting, and incident workflows. Build dashboards and metrics that surface meaningful signals.Â
- Vulnerability management:Â Run the vulnerability scanning program across AWS and Azure cloud environments and on-premises infrastructure. Prioritize, track, and verify remediation in partnership with IT and engineering teams.Â
- Patch management: Maintain endpoint patching cadence and reporting, ensuring coverage, exception tracking, and SLA adherence.Â
- Digital forensics & incident response: Lead investigations into security events, perform forensic analysis, document findings, and coordinate response with internal teams and external partners as needed.Â
Compliance & GovernanceÂ
- NIST-based program: Maintain and continuously improve the company's NIST Cybersecurity Framework-aligned security program, including controls mapping, evidence collection, and gap remediation.Â
- Policy management:Â Own the security policy library - ensure policies and standards are current, reviewed on a defined cadence, approved through the right channels, and communicated to the business.Â
- AI policy and guidance: Develop and maintain the company's AI usage policies, acceptable use guidance, and review process for new AI tools, in coordination with Counsels and IT.Â
- System inventory: Build and maintain an authoritative inventory of systems, applications, data flows, and ownership. Keep it accurate as the environment evolves.Â
- Audit and assessment support:Â Lead responses to internal and external audits, customer security reviews, and regulatory inquiries. Manage remediation of identified findings through closure.Â
- Risk management:Â Identify, document, and track information security risks; propose mitigations and report on residual risk to leadership.Â
Leadership & Cross-Functional PartnershipÂ
- Stakeholder engagement: Partner with IT, Counsels, HR, and business leaders on security matters, providing clear guidance that balances risk with business needs.Â
- Operational Technology (OT): Act as a partner and advisor to the OT team coordinating security and compliance initiatives across the company. Manage intersection of IT and OT endpoints, systems, and networks.Â
- Security awareness:Â Drive the security awareness program, including phishing simulations, training content, and ongoing communications.Â
- Vendor and third-party risk:Â Assess and manage security risk associated with vendors, contractors, and third-party service providers.Â
- Future team leadership: Lay the groundwork to scale the function. As the program matures, hire, mentor, and lead a team of security professionals.Â
Education & Experience Required
- Use of AI to enhance and scale security operations - establish AI first Security OpsÂ
- Bachelor's degree in computer science, information systems, cybersecurity, or related field - or equivalent professional experience.Â
- 5+ years of progressive experience in information security, with demonstrated depth in security operations, engineering, or a combination of both.Â
- Hands-on administration and tuning experience with Microsoft Defender (Endpoint, Identity, Cloud).Â
- Production experience operating Zscaler (ZIA and/or ZPA), including policy management and troubleshooting.Â
- Strong SIEM experience - building detections, tuning alerts, investigating incidents, and onboarding log sources.Â
- Vulnerability management experience across cloud environments, specifically AWS and Azure.Â
- Working knowledge of digital forensics and incident response methodology.Â
- Demonstrated experience operating a security program aligned to the NIST Cybersecurity Framework or NIST 800-53.Â
- Track record of writing, maintaining, and operationalizing security policies and standards.Â
- Clear written and verbal communication, including the ability to explain technical risk to non-technical audiences.Â
- Ability to work from the Durham, NC or Washington, DC office three days per week.Â
- Embrace and live by the mission and values of Cypress Creek Energy
Preferred QualificationsÂ
- Industry certifications such as CISSP, CISM, GIAC (GCIH, GCFA, GCIA), or equivalent.Â
- Experience operating in the energy, utility, or critical infrastructure sector.Â
- Familiarity with NERC CIP or other regulatory frameworks relevant to the power sector.Â
- Experience scripting or automating security workflows (Python, PowerShell, KQL).Â
- Prior experience as a senior technical lead preparing to step into a manager role.Â
Location: The preferred location for this role is for our offices in Durham, NC and Washington, DC. Our team operates on a hybrid schedule, with in-office schedule of three days per week.
Compensation: The salary range for the position is $140,000 - $170,000 plus bonus and benefits. Compensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience, and location.
Benefits:
- 15 days of Paid Time Off, accrual up to 20 days, 11 observed holidays.
- 401(k) Match
- Comprehensive package including medical, dental, vision and health insurance
- Wellness stipend, family planning stipend, and generous parental leave
- Tuition Reimbursement
- Phone Bill Reimbursement
- Company Swag
A note to Recruiting Agencies Cypress Creek Energy Human Resources team does not accept unsolicited resumes from third party recruiters, staffing firms, or related agencies. The Human Resources team coordinates all recruiting and hiring at our company. We do not accept resumes from third-party recruiters unless authorized by the Human Resources team and if a signed agreement is in place. Any unsolicited resumes will be considered property of CCE and we are not responsible for any related fees. All communication related to recruiting partnerships should ONLY be directed to the Human Resources team.Â
Cypress Creek Energy is an equal opportunity employer and considers all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or veteran status. We are committed to providing a workplace that is inclusive and values diversity, and we encourage candidates from all backgrounds to apply.
Please be aware of recruiting scams-official communications will only come from @ccrenew.com, we will never request personal or financial information, and any suspicious activity should be reported to HR@ccrenew.com.
About Cypress Creek Renewables
Sourced by ZipRecruiter
Industry
Clean energy power generation
Company size
201 - 500 Employees
Headquarters location
Durham, NC, US
Year founded
2014