Technical Program Manager leading the delivery of security and compliance solutions for Onit’s SaaS platforms. Collaborating with multiple teams to ensure regulatory compliance and best practices.
Responsibilities
Drive cross-functional initiatives to deliver security and compliance solutions, including resource planning, timeline management, and coordination with external vendors.
Monitor and manage remediation efforts across applications and infrastructure for issues identified via scans, assessments, and customer feedback.
Manage and track the execution of key security and compliance such as access reviews, WAF reviews, and other quarterly and yearly BAU activities required by our security and compliance certifications and customer contracts.
Facilitate the rollout and adoption of the Security Champion Program across teams to level up security knowledge, increase security visibility with tooling, and other key practices.
Oversee the continued adoption and integration of Vanta for automated compliance monitoring.
Support selection, onboarding, and coordination of vendors for penetration testing, audits, and other security services.
Evaluate system designs for security strengths and weaknesses and facilitate technical discussions.
Act as product owner for security and compliance initiatives, creating user stories, prioritizing work, and guiding teams through grooming and delivery.
Work with teams across regions to define, design, and deliver secure SaaS solutions.
Assist with process improvements with incident response, training, runbook definition, and other key areas of the security and compliance program.
Maintain, track, and report key performance indicators/metrics for various activities in security and compliance.
Document key practices within the security and compliance function to improve visibility and adoption.
Requirements
10+ years in technical project management or similar leadership roles.
5+ years in security and compliance domains.
Strong technical background in the cybersecurity domain which includes experience with security tooling, vulnerability management, 3rd party penetration testing, incident response, thread detection, etc.
Proven track record executing security and compliance projects for Enterprise SaaS solutions.
Extensive experience managing the security of cloud-based applications (AWS preferred)
Ability to navigate trade-offs and prioritize across multiple teams.
Proficiency in agile methodologies and tools (e.g., Jira, Scrum, Kanban).
Experience with security and compliance frameworks such as SOC2, NIST, and ISO 27001.
Strong communication, problem-solving, and collaboration skills.
Experience with EDR, CSPM, and SEIM security tooling.
Relevant certifications (CISSP, CCSP, CISM, AWS Security Specialty) are a plus.
Regulatory, compliance, or legal experience is a plus.
Experience with containerized applications is a plus.
Benefits
Health Coverage: Employee and immediate family members.
Time Away: Flexible paid time off and 10 company paid holidays annually.
Family Support: Exceptional paid leave for birth parents, non-birth parents, and caregivers. Onit also offers surrogacy and adoption reimbursement.
Income Protection: 100% employer-paid life and disability insurance.
Additional Coverage Options: Voluntary benefits including hospital indemnity, critical illness, accident, and even pet insurance.
Tax-Advantaged Accounts: Flexi, NPS.
Community Engagement: One paid volunteer day each year to give back to the community.
Route Sales Driver responsible for building customer partnerships and meeting sales targets. Delivering products and maintaining effective customer relationships in the Bell Gardens area.
System Security Manager overseeing vulnerability management and compliance for critical systems at Agile5 Technologies. Driving security improvements and collaborating across project teams.
Security Guard responsible for protecting clients and staff at The Providence Center. Involves patrolling facilities, reporting incidents, and maintaining security protocols.
Corporate Security Manager ensuring safety and security of employees and assets at Vodafone. Responsible for implementing security policies and coordinating security personnel in an international environment.
Process & Information Security Manager responsible for IT governance and security at ilem, based in Casablanca. Leading ISO 27001 compliance and improving security practices.
Cyber Security Service Owner for Exposure & Vulnerability Management at ASSA ABLOY. Leading the performance and evolution of exposure management services globally.
Site Security Officer responsible for ensuring security compliance and managing risks. Collaborating in an international context at Saab Underwater Systems in Linköping or Motala.
Information Security Intern participating in security monitoring, threat analysis, and policy development. Engaging in hands - on projects to develop skills in information security operations.
Corporate Security Intern at Atlantic Union gaining practical work experience in security and safety management. Involvement with physical security systems and contributing to security strategy.
Internship role developing skills in Information Security at Atlantic Union Bank. Engaging in real assignments and gaining practical work experience with mentoring and training.