Security Program Manager
Assess client security postures, develop customized security programs using frameworks like NIST and SOC2, provide implementation guidance, and collaborate with auditors and internal teams to achieve compliance goals.
About the job
Key Responsibilities
- Conduct initial consultation calls with new clients to assess their current security posture, infrastructure stack, compliance requirements and overall objectives.
- Provide guidance and recommendations for improving client security posture.
- Develop high-level security programs consisting of technical, operational and administrative controls based on industry frameworks and client needs.
- Collaborate with clients to customize and refine the security program to match their specific use cases.
- Communicate with clients and stakeholders to ensure smooth and efficient security program creation.
- Liaise with auditors to ensure clients' security programs align with auditors' expectations.
- Maintain expertise across a range of security frameworks, control types, and technologies including NIST, SOC2, ISO27001, CMMC, AWS, Azure, GCP, Kubernetes, Docker, Terraform, and more.
- Provide feedback to Oneleet's engineering team to inform development of integrations, solutions, and products that deliver on client needs.
- Be highly technical, learn new technologies quickly, and translate security concepts into implementations.
- Partner with internal teams to translate security programs into implementations consisting of policies, procedures, configurations and software integrations.
Requirements
- 3+ years in an information security role.
- Broad knowledge of security best practices, frameworks, control types, and relevant technologies.
- Ability to understand client infrastructure and map security controls to meet compliance goals.
- Strong analytical skills to evaluate environments and determine appropriate safeguards.
- Excellent verbal and written communication skills.
- Self-driven with the ability to work independently and move fast in a startup environment.
- Willingness to go the extra mile to meet tight deadlines and deliver results.
Skills
Nist, Soc2, Iso27001, Cmmc, AWS, Azure, GCP, Kubernetes, Docker, Terraform
Similar jobs
Security Engineering jobsBuild and automate technical security controls, compliance workflows, and audit evidence for enterprise readiness. The role requires strong scripting or programming skills, security fundamentals, and the ability to collaborate across engineering, security, legal, and customer-facing teams.
Develop and operate global physical security systems, controls, and compliance processes across data centers and other facilities. The role manages investigations, risk mitigation, audits, vendor deployments, and cross-functional security initiatives, with approximately 35% travel required.
Security Engineer responsible for building detection and prevention controls, automating security operations, conducting threat hunts, and supporting incident response across a remote-first organization. Requires 3+ years of security or software development experience, cloud-native security expertise, and automation skills.
Own network engineering and government cybersecurity compliance for on-site and field-deployed aerospace systems. The role requires 5+ years of experience, end-to-end IATT/ATO experience, strong networking skills, and familiarity with DoD security frameworks and tactical communications.
Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.