> Markdown version of [/jobs/ext/1242732-cybersecurity-program-manager](https://www.wearedevelopers.com/jobs/ext/1242732-cybersecurity-program-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Program Manager - **Company:** Granite Construction - **Location:** The Woodlands, TX, United States - **Experience:** Expert - **Salary:** $168,947.0 - $253,420.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Microsoft Azure, Software as a Service, Cyber Security, Information Systems, Databases, Information Technology, Cybercrime, Vulnerability Analysis - **Published:** July 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=31ab32d6bb9744b6 ## About the Role * Bachelor's degree in Computer Science, Information Systems, or a related field required * Professional certification in cybersecurity or information security, such as CISSP or CISM Work Experience * 10+ years of progressive cybersecurity management experience * 15+ years of hands-on cybersecurity experience Knowledge, Skills, and Abilities * Demonstrated expertise in managing cybersecurity and security operations functions * Advanced knowledge of the cybersecurity threat landscape, including emerging threats, attack vectors, and mitigation strategies * Advanced knowledge of IT systems, tools, and infrastructure, with the ability to stay current on new and evolving technologies * In-depth knowledge of cybersecurity solutions and services in the market, including evaluation and selection of vendor offerings * Proficiency in cybersecurity frameworks (e.g., NIST, ISO 27001), including implementation and compliance alignment * Experience developing and executing cybersecurity roadmaps and budget forecasts, with measurable alignment to business objectives * Strong persuasive reasoning and influencing skills, with the ability to drive decision-making across stakeholders * Customer-focused mindset, with the ability to deliver responsive, solutions-oriented service to internal and external stakeholders * Advanced verbal and written communication skills, including the ability to clearly and concisely present complex technical information to non-technical audiences * Ability to operate effectively in dynamic, evolving environments, including influencing and motivating without direct authority * Strong analytical and problem-solving skills, with the ability to assess risks and implement effective solutions Physical Demands The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. While performing the duties of this job, the employee is regularly required to talk and hear. The employee frequently is required to stand, walk, sit and use hands to operate a computer keyboard. The employee is occasionally required to reach with hands and arms. The employee must occasionally lift and/or move up to 20 pounds. Specific vision abilities required by this job include close vision, and ability to adjust focus. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Additional Requirements/Skills * Valid driver's license and ability to drive, with flexibility to travel as required * Comply, understand, and support company safety initiatives to ensure a safe work environment * Ability and willingness to abide by company code of conduct daily ## Description This position leads the company's cybersecurity program, overseeing security operations and reporting while identifying and addressing risks across the organization. The role prioritizes and drives initiatives to reduce or eliminate cybersecurity threats., * Lead the Information Technology (IT) organization in developing a comprehensive cybersecurity risk profile across the enterprise to ensure the company's IT infrastructure is secure and resilient * Oversee cybersecurity controls and risk management practices across cloud platforms, including Microsoft 365, Azure, SaaS applications, identity systems, and hybrid environments, to protect critical systems and data * Implement selected cybersecurity frameworks and publish standards to drive consistent practices and ensure enterprise-wide compliance * Align the cybersecurity program with regulatory and industry requirements (e.g., FARS/DFARS, NIST CSF & 800-171, CMMC, FedRAMP, CCPA) to maintain compliance and reduce legal and operational risk * Partner with IT Delivery and Infrastructure teams to develop and enforce best practices and procedures that strengthen cybersecurity controls and reduce vulnerabilities * Prioritize cybersecurity initiatives in collaboration with IT Delivery and Infrastructure teams to ensure timely mitigation of identified risks * Develop and manage the incident response plan for cyber events to enable effective, coordinated, and timely responses to security incidents * Develop and report metrics, KPIs, and KRIs to IT Steering, executive leadership, and the Board of Directors to demonstrate program effectiveness and secure ongoing support * Develop and communicate the cybersecurity roadmap across the enterprise to build awareness, alignment, and sponsorship for key initiatives * Lead cybersecurity awareness and training programs to ensure employees understand and can recognize and respond to cyber threats * Manage the security operations function to monitor, detect, and respond to vulnerabilities and cyber threats, ensuring timely mitigation and protection of company assets * Develop and maintain a third-party cybersecurity risk management program to evaluate and validate vendor security practices and ensure partners meet company standards * Manage the cybersecurity budget by allocating resources effectively and advocating for investments needed to address emerging threats and support program priorities, Granite Construction, Inc. and its subsidiaries ("Granite") will not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to Granite, including unsolicited resumes sent to a Granite mailing address, fax machine or email address, directly to Granite employees, or to Granite's resume database will be considered Granite property. Granite will NOT pay a fee for any placement resulting from the receipt of an unsolicited resume. Granite will consider any candidate for whom an Agency has submitted an unsolicited resume to have been referred by the Agency free of any charges or fees. Agencies must obtain advance written approval from Granite's recruiting function to submit resumes, and then only in conjunction with a valid fully-executed contract for service and in response to a specific job opening. Granite will not pay a fee to any Agency that does not have such agreement in place. Agency agreements will only be valid if in writing and signed by Granite's Human Resources Representative or his/ her designee. No other Granite employee is authorized to bind Granite to any agreement regarding the placement of candidates by Agencies. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j)