1

Senior Cybersecurity Program Manager Jobs in Oregon

OnSite Cybersecurity Custodian

Tualatin, OR · Hybrid

$104K - $134K/yr

Key Responsibilities Cybersecurity Program Execution & Evidence Ownership Supported and lead by BV Senior Cybersecurity Consultants from Home Office, manage day-to-day execution of the on-site OT ...

S . The Senior Cybersecurity Engineer is responsible for identifying security risks ... Lead cross-functional program governance with engineering, product management, quality, and ...

S . The Senior Cybersecurity Engineer is responsible for identifying security risks ... Lead cross-functional program governance with engineering, product management, quality, and ...

We're looking for a Senior Cybersecurity Engineer who wants to leave their mark by building and ... risk management program that brings together assessments, vulnerability management, threat ...

Sr. Cybersecurity Engineer

OR · On-site +1

$121K - $153K/yr

We're looking for a Senior Cybersecurity Engineer who wants to leave their mark by building and ... risk management program that brings together assessments, vulnerability management, threat ...

Advise senior management on system risk levels and cybersecurity posture for cloud-based ... Work with program ISSOs and ISSMs to effectively aggregate technical details for government ...

Provide regular updates and escalations to senior leadership and stakeholders * Conduct quarterly ... Agile program management and cross-team coordination * Experience leading or establishing value ...

next page

Showing results 1-20

Senior Cybersecurity Program Manager information

Can you make 200k a year in cyber security?

Senior cybersecurity program managers can earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISM, and leadership responsibilities. Salaries vary based on industry, location, and company size, with some roles in high-demand sectors reaching or exceeding this level.

What does a Senior Cybersecurity Program Manager do?

A Senior Cybersecurity Program Manager oversees the planning, development, and implementation of an organization's cybersecurity strategies and programs. They coordinate teams, manage budgets, and ensure compliance with relevant regulations and standards. Their responsibilities often include risk assessment, policy development, and incident response planning. They also serve as a bridge between technical teams and executive leadership, ensuring alignment between security initiatives and business objectives.

What is the 80 20 rule in cyber security?

The 80/20 rule in cybersecurity suggests that approximately 80% of security issues are caused by 20% of vulnerabilities or threats. For a Senior Cybersecurity Program Manager, focusing on the most critical vulnerabilities and implementing prioritized controls can significantly improve security posture and resource efficiency.

What are the key skills and qualifications needed to thrive as a Senior Cybersecurity Program Manager, and why are they important?

To thrive as a Senior Cybersecurity Program Manager, you need extensive knowledge of information security principles, risk management, and program management, often backed by a bachelor's or master's degree in a related field and certifications like CISSP or CISM. Familiarity with security frameworks (e.g., NIST, ISO 27001), security tools, and project management systems (such as Jira or MS Project) is crucial. Exceptional leadership, communication, and strategic planning skills are important for guiding cross-functional teams and aligning cybersecurity initiatives with organizational goals. These skills are vital to effectively manage complex security programs, mitigate risks, and ensure compliance in a rapidly evolving threat landscape.

Can you make $500,000 a year in cyber security?

Senior cybersecurity program managers with extensive experience, advanced certifications, and leadership roles in large organizations can potentially earn $500,000 or more annually, especially with bonuses and stock options. Achieving this level typically requires a combination of technical expertise, strategic management skills, and a track record of successful security initiatives.

What is a cybersecurity program manager?

A cybersecurity program manager oversees and coordinates an organization's cybersecurity initiatives, ensuring security policies, risk management, and compliance are effectively implemented. They often manage teams, develop strategic plans, and work with tools like security frameworks and incident response processes to protect digital assets.

What is the difference between Senior Cybersecurity Program Manager vs Cybersecurity Analyst?

AspectSenior Cybersecurity Program ManagerCybersecurity Analyst
CertificationsCISSP, PMP, CISMCompTIA Security+, CEH
Work EnvironmentOversees security programs, manages teams, strategic planningMonitors security systems, analyzes threats, implements security measures
Employer & Industry UsageUsed in large organizations, government agencies, corporationsCommon in IT departments, security firms, tech companies

The main difference is that a Senior Cybersecurity Program Manager leads and manages security initiatives and teams, focusing on strategic planning and program oversight. In contrast, a Cybersecurity Analyst primarily monitors and analyzes security threats, implementing technical solutions. The Program Manager role involves higher-level management and coordination, while the Analyst role is more technical and operational.

How does a Senior Cybersecurity Program Manager typically collaborate with other departments to ensure organization-wide security compliance?

A Senior Cybersecurity Program Manager frequently works cross-functionally, partnering with IT, legal, compliance, and business units to develop and implement security strategies. They lead security awareness initiatives, coordinate risk assessments, and ensure that various teams are aligned with regulatory requirements and internal policies. Regular communication, training sessions, and collaborative projects are integral, as the role relies on fostering a culture of security across all levels of the organization. This collaborative approach helps proactively identify vulnerabilities and implement effective safeguards.
What are popular job titles related to Senior Cybersecurity Program Manager jobs in Oregon? For Senior Cybersecurity Program Manager jobs in Oregon, the most frequently searched job titles are:
What job categories do people searching Senior Cybersecurity Program Manager jobs in Oregon look for? The top searched job categories for Senior Cybersecurity Program Manager jobs in Oregon are:
What cities in Oregon are hiring for Senior Cybersecurity Program Manager jobs? Cities in Oregon with the most Senior Cybersecurity Program Manager job openings:
OnSite Cybersecurity Custodian

OnSite Cybersecurity Custodian

Black & Veatch

Tualatin, OR • Hybrid

$104K - $134K/yr

Other

Retirement

Posted 23 days ago


Black & Veatch rating

8.6

Company rating: 8.6 out of 10

Based on 18 frontline employees who took The Breakroom Quiz

61st of 352 rated engineering


Job description

OnSite Cybersecurity Custodian

Location: Ann Arbor, MI, US Jacksonville, FL, US Cary, NC, US Greenville, SC, US Tampa, FL, US Phoenix, AZ, US Orlando, FL, US Atlanta, GA, US Charleston, SC, US Dallas, TX, US Tualatin, OR, US Columbia, SC, US Austin, TX, US South Jordan, UT, US Kansas City, MO, US Houston, TX, US Company: Black & Veatch Family of Companies Together, we own our company, our future, and our shared success. As an employee-owned company, our people are Black & Veatch. We put them at the center of everything we do and empower them to grow, explore new possibilities and use their diverse talents and perspectives to solve humanity's biggest challenges in an ever-evolving world. With over 100 years of innovation in sustainable infrastructure and our expertise in engineering, procurement, consulting and construction, together we are building a world of difference.

Company: Black & Veatch Corporation Opportunity Type: Staff Relocation eligible: Yes Full time/Part time: Full-Time Project Only Hire: Yes Visa Sponsorship Available: No

Why Black & Veatch?

Black & Veatch allows you to lend your talent and perspective to humanity's biggest challenges in a flexible environment where you are empowered to grow and explore new possibilities. We offer competitive compensation, 401k match and benefits that start day one. Our hybrid environment allows you to balance your work and personal life. At Black & Veatch, you own your career with purpose and meaning. You are empowered to grow and explore new possibilities at every step of your career journey. Bring your big ideas knowing you are safe to be who you are and speak up with concerns or questions and put your diverse talents and perspectives to use.

The Opportunity

Black & Veatch (BV) is seeking a direct-hire, full-time on-site Cybersecurity Custodian to support cybersecurity execution for a new Power Plant project in Beech Island, South Carolina. Supported and led by BV Senior Cybersecurity Consultants, this individual will be the day-to-day on-site custodian for Operational Technology (OT) / Industrial Control Systems (ICS) cybersecurity activities, coordinating with EPC, Owner, and vendors to ensure systems are secured, cybersecurity requirements are met, and all work is documented in a complete, audit-ready evidence package. This role is perfect for individuals experienced with power plant control systems (DCS/PLC/SCADA/HMI) who are enthusiastic about applying cybersecurity in practical construction and commissioning settings. The role begins no later than November 2026 to support readiness activities ahead of Distributed Control System (DCS) Factory Acceptance Testing (FAT) in March 2027, includes travel to vendor FAT/Cyber FAT (CFAT) locations, and remains on-site through installation, commissioning, and turnover. After completion of the Beech Island project, the role is expected to continue as a full-time ICS Cybersecurity Consultant position supporting B&V's Infrastructure Advisory (IA) Industrial Cybersecurity team across additional OT/ICS projects. The post-project role can be based at the BV office in Columbia, SC or any other BV office location.

Reporting & Teaming

Report operationally to the project leadership team, while working closely with B&V cybersecurity stakeholders. Work closely with the IA ICS Cybersecurity team who provides back-office support including: Project planning and cybersecurity execution roadmap, Standards, templates, and evidence packages, Requirements interpretation and technical guidance and Action-item tracking support and cadence facilitation Execute the on-site work, coordinate vendors, and ensure evidence is captured and organized.

Key Responsibilities

Cybersecurity Program Execution & Evidence Ownership Supported and lead by BV Senior Cybersecurity Consultants from Home Office, manage day-to-day execution of the on-site OT cybersecurity program, including tracking requirements, planned actions, and completion status and report status of activities to BV Senior Cybersecurity Consultants for review and approvals Build and maintain an organized evidence repository (audit-ready), ensuring deliverables are properly dated, labeled, and attributable. Maintain logs, checklists, procedures, forms, test results, scan outputs, approvals, and sign-offs as required. CFAT / Cyber Site Acceptance Testing (CSAT) Support Support pre-CFAT readiness and participate in vendor CFAT activities as required (travel required). Validate cybersecurity controls prior to shipment (where applicable), including accounts, logging, backups, malware controls, and baseline configurations. Track and close cyber-related FAT punch items; ensure retests and final evidence are captured and filed. Identity, Credential, and Access Control Verify and document required access controls including MFA for remote access, least privilege, and role-based access models. Support account management documentation: default credential changes, service account controls, privilege verification, termination/role-change access actions, and secure credential handover processes. Asset Inventory, Configuration Baselines & Change Tracking Maintain support for hardware/software inventory requirements (including OS/firmware versions, asset tags, locations, network references). Track configuration baselines, redlines, and as-built updates throughout construction and commissioning. Coordinate change documentation and evidence, including post-change backup capture and validation. Removable Media & Transient Cyber Assets (TCA) Controls Enforce and document removable media and transient device controls in line with Owner policies and site procedures. Oversee malware scanning workflows, authorization forms, encrypted media handling, quarantine steps, and scanning evidence retention. Coordinate vendor site visit preparations (e.g., ensuring vendor laptop/TCA scanning expectations are met). Monitoring, Logging, and Detection Enablement Coordinate and document OT log onboarding to Splunk/SIEM, including log sources, retention requirements, and forwarding architecture. Support readiness for NIDS/span port configuration and event forwarding requirements. Validate and document that logging is enabled, time-synchronized, and functioning without impacting system performance. Additional Key Responsibilities Backup, Recovery, and Resilience Verify backup procedures are in place for OT assets and that backups are created after major changes (patching, configuration updates). Support restoration testing where required; ensure offline backup handling meets custody and storage requirements. Track encrypted portable hard drives / backup media custody and handover documentation where applicable. Incident Reporting & Response Support Maintain cyber escalation contacts and on-site reporting procedures. Support documentation of cybersecurity events, policy violations, corrective actions, and evidence of remediation steps. Coordinate with ICS Cybersecurity and Owner stakeholders for incident-related communications and records. Training, Workforce Security & Compliance Documentation Track and maintain evidence for required cybersecurity awareness training completion. Support workforce security evidence collection (e.g., authorization logs, background check logs, access revocations). Conduct periodic verification that access authorizations remain current and justified.

A Successful Cybersecurity Custodian Will:

Maintain a complete, well-organized cyber evidence repository that maps activities to requirements and stands up to Owner and compliance scrutiny. Enable smooth FAT/CFAT/commissioning progress by identifying cybersecurity gaps early and driving closure without schedule disruption. Demonstrate strong coordination across vendors, EPC, site teams, and the back-office cyber team. Establish consistent cyber processes on-site that improve repeatability and reduce risk.

Management Responsibilities

Individual Contributor Preferred Qualifications 3+ years supporting industrial/power generation control systems or OT environments. Cybersecurity training or certifications (e.g., Security+, GIAC, ISA/IEC 62443, CISSP). Practical knowledge of OT networking fundamentals such as: IP addressing, VLANs, firewall concepts, routing basics. Familiarity with NERC CIP concepts, OT segmentation, MFA, jump hosts, and least-privilege design. Ability to work on-site in Beech Island, SC for 12+ months (typical 5x8 with occasional off-hours during cutovers). Willingness to travel to vendor facilities for CFAT support. Occasional travel for planning/working sessions may be requested. Eligible to meet badging/background/site access requirements. Experience with Splunk/SIEM, antivirus/whitelisting, vulnerability scanning, or backup tooling. Experience supporting FAT/commissioning on large capital projects (power generation or similar). Strong documentation discipline—ability to produce clear procedures, logs, checklists, and evidence packages. Experience working with vendors and multi-discipline teams in construction/commissioning environments Minimum Qualifications Bachelor's Degree or relevant work experience. 4+ years experience in a business/consulting environment. All applicants must be able to complete pre-employment onboarding requirements (if selected) which may include any/all of the following: criminal/civil background check, drug screen, and motor vehicle records search, in compliance with any applicable laws and regulations. Certifications Certifications related to area of expertise, where applicable preferred.


What Black & Veatch employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Black & Veatch logo

About Black & Veatch

Sourced by ZipRecruiter

Company: Black & Veatch Family of Companies Together, we own our company, our future, and our shared success. As an employee-owned company, our people are Black & Veatch. We put them at the center of everything we do and empower them to grow, explore new possibilities and use their diverse talents and perspectives to solve humanity's biggest challenges in an ever-evolving world. With over 100 years of innovation in sustainable infrastructure and our expertise in engineering, procurement, consulting and construction, together we are building a world of difference.

Industry

Civil engineering construction

Company size

10,000+ Employees

Headquarters location

Overland Park, KS, US

Year founded

1915