Manager Information Security Programs
Role details
Job location
Tech stack
Job description
The Manager Information Security Programs manages the execution of enterprise-wide security initiatives at AEG Worldwide, reporting to the Chief Information Security Officer (CISO). This role oversees a diverse portfolio of programs, partnering with cross-functional teams to ensure alignment, progress, and measurable outcomes. It requires strong program management skills and a solid understanding of key security domains such as risk, threat detection, and compliance., * Program and Cross-Functional Management: Oversee a portfolio of security initiatives aligned with enterprise priorities, ensuring clear scope, timelines, and deliverables. Coordinate across InfoSec, GES, PMO, IT, Legal, and external partners to align efforts, manage risks, and drive outcomes that support the CISO's strategic objectives.
- Governance and Risk Reporting: Support the development and ongoing improvement of security governance processes, integrating program-level updates into enterprise risk management and compliance reporting cycles. Maintain and track key performance indicators (KPIs) and key risk indicators (KRIs) for critical programs, ensuring alignment with internal audit, regulatory, and compliance standards.
- Executive Communication: Develop and deliver executive-level updates, dashboards, and briefings that summarize program status, key risks, and strategic impact. Collaborate with the CISO and senior leadership to present insights and recommendations to executive stakeholders and governance boards.
- Vendor and Contract Oversight: Assist in the evaluation and selection of third-party vendors, review security-related contracts, and manage relationships with external service providers. Ensure all engagements meet defined service level agreements (SLAs), compliance requirements, and delivery expectations.
- Continuous Improvement: Identify gaps or inefficiencies in existing security program processes and recommend improvements to enhance execution and maturity. Promote the adoption of industry best practices, support post-project reviews, and integrate feedback loops to drive continuous learning and refinement.
Requirements
- BA/BS Degree (4-year) Information Systems, Computer Science, Cybersecurity, Business Administration, or a related field.
- 4-6 years Program or project management experience in a security, technology, or risk function.
- Strong understanding of security domains such as SOC, IR, Vulnerability Management, GRC, DLP, and compliance frameworks (NIST, PCI-DSS, ISO 27001).
- Proven experience managing complex, cross-functional programs in a highly matrixed environment.
- Excellent communication skills with the ability to tailor messages to technical and non-technical stakeholders.
- Experience coordinating external vendors, drafting statements of work (SOWs), and ensuring service delivery.
- Strong understanding of information security principles, technologies, and industry standards.
- Proven ability to manage multiple initiatives and prioritize under pressure.
- Exceptional organizational and analytical skills, with attention to detail.
- Ability to influence without authority and drive cross-functional alignment.
- Strong interpersonal skills and emotional intelligence for working in a politically nuanced environment.
- Proficient in project management tools (e.g., Jira, MS Project Pro, MS PowerPoint).
- Relevant certifications such as PMP/CAPM, Security+, CISSP, CISM, CEH, or equivalent are highly desirable.
Benefits & conditions
Pay Scale: $160,000.00 - $175,000.00
Bonus: This position is eligible for a bonus under the current bonus plan requirements.
Benefits: Full-time: We offer a comprehensive benefits package that includes: medical, dental and vision insurance, paid holidays, vacation and sick time, company paid basic life insurance, voluntary life insurance, parental leave, 401k Plan (with a current employer match of 3%), flexible spending and health savings account options, and wellness offerings.