Technical Program Manager leading the delivery of security and compliance solutions for Onit’s SaaS platforms. Collaborating with multiple teams to ensure regulatory compliance and best practices.
Responsibilities
Drive cross-functional initiatives to deliver security and compliance solutions, including resource planning, timeline management, and coordination with external vendors.
Monitor and manage remediation efforts across applications and infrastructure for issues identified via scans, assessments, and customer feedback.
Manage and track the execution of key security and compliance such as access reviews, WAF reviews, and other quarterly and yearly BAU activities required by our security and compliance certifications and customer contracts.
Facilitate the rollout and adoption of the Security Champion Program across teams to level up security knowledge, increase security visibility with tooling, and other key practices.
Oversee the continued adoption and integration of Vanta for automated compliance monitoring.
Support selection, onboarding, and coordination of vendors for penetration testing, audits, and other security services.
Evaluate system designs for security strengths and weaknesses and facilitate technical discussions.
Act as product owner for security and compliance initiatives, creating user stories, prioritizing work, and guiding teams through grooming and delivery.
Work with teams across regions to define, design, and deliver secure SaaS solutions.
Assist with process improvements with incident response, training, runbook definition, and other key areas of the security and compliance program.
Maintain, track, and report key performance indicators/metrics for various activities in security and compliance.
Document key practices within the security and compliance function to improve visibility and adoption.
Requirements
10+ years in technical project management or similar leadership roles.
5+ years in security and compliance domains.
Strong technical background in the cybersecurity domain which includes experience with security tooling, vulnerability management, 3rd party penetration testing, incident response, thread detection, etc.
Proven track record executing security and compliance projects for Enterprise SaaS solutions.
Extensive experience managing the security of cloud-based applications (AWS preferred)
Ability to navigate trade-offs and prioritize across multiple teams.
Proficiency in agile methodologies and tools (e.g., Jira, Scrum, Kanban).
Experience with security and compliance frameworks such as SOC2, NIST, and ISO 27001.
Strong communication, problem-solving, and collaboration skills.
Experience with EDR, CSPM, and SEIM security tooling.
Relevant certifications (CISSP, CCSP, CISM, AWS Security Specialty) are a plus.
Regulatory, compliance, or legal experience is a plus.
Experience with containerized applications is a plus.
Benefits
Health Coverage: Employee and immediate family members.
Time Away: Flexible paid time off and 10 company paid holidays annually.
Family Support: Exceptional paid leave for birth parents, non-birth parents, and caregivers. Onit also offers surrogacy and adoption reimbursement.
Income Protection: 100% employer-paid life and disability insurance.
Additional Coverage Options: Voluntary benefits including hospital indemnity, critical illness, accident, and even pet insurance.
Tax-Advantaged Accounts: Flexi, NPS.
Community Engagement: One paid volunteer day each year to give back to the community.
Head of Security Data and AI Lab driving strategic leadership and innovation for security data and AI solutions at Lloyds Banking Group. Managing security data and AI capabilities to protect and innovate.
Senior Data Security Engineer leading design and implementation of data protection solutions at Phoenix Group. Collaborating closely with teams to enhance data security posture.
Network Security Engineer at Bank of America focusing on designing and implementing network security solutions. Requires deep knowledge in cybersecurity and collaboration with global teams.
Security Alarm Technician installing various security and smart home devices at Guardian Protection. Delivering quality service while adhering to company standards and regulations.
Senior Security Architect providing cyber security and privacy risk solutions for clients at PwC New Zealand. Collaborating with teams to set a new standard in digital services.
Security Consultant supporting customers with IT Security Consulting in various areas. Engaging in project management from analysis to execution, both remotely and on - site.
Security Consultant providing guidance on information security management systems and compliance. Analyzing processes, assessing risks, and developing security strategies for clients in Germany.
Cyber Security Specialist focuses on securing IT environments and implementing security standards. Engaging in continuous development of security strategies and solutions across systems in a hybrid role.
Cyber Security Consultant developing sustainable products and services for the public sector. Leading expertise in Digital Security with external customer consultation.
Information Security Manager leading data privacy efforts and risk management strategies. Working for D - Trust GmbH in Berlin to enhance information security and compliance initiatives.