Senior IT Risk Project Manager

Luxoft Usa, Inc.
Columbus, OH, United States
2 days ago
Apply on www.disabledperson.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Artificial Intelligence Software System Penetration Testing Cyber Security Data Governance Information Leak Prevention PRINCE2 Systems Development Life Cycle Software Engineering Information Technology CIS Benchmarks Static Application Security Testing Dynamic Application Security Testing

Job description

Ensure successful delivery of projects

  • Achieve financial targets
  • Manage stakeholders’ expectations
  • Drive presales & business development activities
  • People management activities
  • Project manager activities:
  • Pre-sale
  • Contracting
  • Project start
  • Project Planning and Execution
  • Team Management
  • Self-management

Requirements

  • 7+ years of professional experience in software development projects and management
  • 5+ years of experience in large scale Project/Program management
  • Proven track record in complex projects with global, distributed teams
  • People management experience for 20+ FTEs
  • Good understanding of program financials and reporting
  • Good understanding of project manager areas of responsibility:
  • Project Planning
  • Backlog prioritization, detailing and decomposition
  • Understanding of SDLC and ability to build/optimize project processes
  • Communication with the team, client
  • Understanding of motivation factors
  • Team Management
  • Result-oriented
  • Working with feedback: provide and receive
  • Risk management:
  • Demonstrable experience running IT risk, security, or compliance-driven programmes
  • not only feature delivery
  • Ability to build and maintain a risk register: identification, qualification, scoring, mitigation planning, ownership assignment, and escalation
  • Experience coordinating remediation programmes across multiple engineering teams (patching, vulnerability closure, control implementation) and tracking them to measurable closure
  • Comfortable operating with audit, InfoSec, and compliance stakeholders; experience preparing evidence and status for governance forums or steering committees
  • Working knowledge of at least one control or risk framework (NIST CSF/RMF, ISO 27001, CIS Controls, SOC 2, or similar)
  • Ability to translate technical findings into business impact and risk-based prioritization for senior stakeholders
  • Soft skills and education:
  • Verbal and written business communication skills
  • Presentation skills, including to executive and risk-committee audiences
  • Negotiation skills
  • Master’s Degree in computer science or similar education
  • Certification advantage: PMP / PRINCE2 / SAFe, plus one of CISSP, CISM, CRISC, or CISA

Nice to have

  • Familiarity with security vulnerability management: CVE/CVSS, severity triage, SLA-based remediation cycles
  • Exposure to penetration testing engagements
  • scoping, vendor coordination, findings review, retest tracking
  • Understanding of AI/GenAI risk: model and data governance, AI risk scans and assessments, prompt injection and data leakage exposure, third-party AI tooling review
  • Awareness of emerging AI governance and regulation (EU AI Act, NIST AI RMF) and how it lands on delivery teams
  • Understanding of secure SDLC practices: SAST/DAST/SCA, dependency and supply chain risk, threat modelling

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.disabledperson.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:12 min

Navigating technical clarity as a global black belt

Chris Heilmann +2 · LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:34 min

Transitioning from traditional software development to artificial intelligence consulting

Patrick Schnell Patrick Schnell · Coffee With Developers

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all