> Markdown version of [/jobs/ext/1308948-sr-technical-program-manager-cybersecurity-remediation](https://www.wearedevelopers.com/jobs/ext/1308948-sr-technical-program-manager-cybersecurity-remediation). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Technical Program Manager, Cybersecurity Remediation - **Company:** Moderna, Inc. - **Location:** Cambridge, MA, United States (Remote available) - **Experience:** Expert - **Salary:** $145,900.0 - $234,200.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing Security, Cyber Security, Smartsuite, Software Vulnerability Management, Software Security, Data Analytics, GXP, Vulnerability Analysis - **Published:** July 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=4f5a018d8f4d1367 ## About the Role * Experience: 8+ years in Technical Program Management, Cybersecurity Program Management, or similar roles. * Proven experience leading complex, cross-functional remediation programs in cybersecurity, infrastructure, or enterprise IT environments. * Strong understanding of cybersecurity domains such as vulnerability management, incident response, identity, cloud security, and application security. * Experience working with findings from audits, risk assessments, penetration tests, and security incidents. * Strong stakeholder partnership and influencing skills in highly matrixed organizations. * Excellent written and verbal communication skills, including executive-level communication. * Ability to define metrics, track progress, and use data to support clear and informed decision-making. * Strong listening skills, sound judgment, and a proactive approach to feedback and problem-solving. Here's What You'll Bring to the Table (Preferred Qualifications) * Experience with GxP environments and regulatory requirements. * Familiarity with vulnerability management platforms, GRC tools, and security tracking/reporting systems. * Experience with post-incident review processes, including root cause analysis (RCA), CAPA management, and lessons-learned programs. * Experience implementing or scaling enterprise remediation or risk management programs. * Background in infrastructure, cloud, or security engineering. * Knowledge of security frameworks (e.g., NIST, ISO 27001, CIS). * Experience driving operational maturity improvements (process, tooling, governance). * Strong sense of ownership and urgency, with the ability to balance risk, timely execution, and business priorities. * Influential, inclusive, and trusted partner with a collaborative mindset. ## Description Moderna is seeking a Senior Technical Program Manager (TPM) to lead and coordinate cybersecurity remediation initiatives across the organization. We're looking for someone who brings integrity, sound judgment, strong relationship-building skills, and cybersecurity expertise , and who can partner effectively across teams to move complex work forward. In this role, you will help lead the end-to-end remediation of security findings generated through scans, assessments, audits, incident reviews, investigations, and continuous monitoring. You will bring thoughtful program management, collaboration, and clear communication to a complex, cross-functional environment where responsiveness, quality, and partnership all matter. Here's What You'll Be Doing: Program Ownership * Lead and coordinate the intake, prioritization, and execution of cybersecurity remediation programs using a structured, data-driven, and risk-based approach. * Responsible for end-to-end delivery of multiple concurrent remediation workstreams across Moderna technology and business teams, from identification through validation and closure. * Establish and manage a centralized remediation operating model, including governance, prioritization frameworks, SLAs, escalation paths, and execution tracking. * Define and monitor program metrics, risks, and trends to drive accountability, decisions, and continuous improvement. Risk and Remediation Management * Translate findings from vulnerability scans, penetration tests, risk assessments, incidents, audits, and investigations into actionable remediation plans. * Partner with teams to move remediation items through verification and closure, including management of exceptions and risk acceptance with appropriate sign-off . * Own the consolidated findings registry, maintaining a single authoritative view of vulnerabilities, risks, audit findings, post-incident action items, and assessment recommendations. * Lead executive- and board-level reporting on remediation posture, metrics, and systemic trends, translating technical risk into business-relevant language. * Identify recurring issues and drive longer-term improvements that strengthen cybersecurity practices and reduce future risk . Partner Engagement and Influence * Build strong relationships across security, engineering, and business teams to create alignment, navigate blockers, and influence prioritization in a highly matrixed environment. * Provide clear, concise, and executive-ready communications on program status, risks, decisions, and tradeoffs. * Partner with leaders to strengthen secure engineering and operational practices across the organization. * Actively contribute to creating a more inclusive culture and environment at Moderna; endorse , create, and maintain antiracist policies and processes. ## Related Videos - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)