> Markdown version of [/jobs/ext/506741-senior-program-manager-information-security](https://www.wearedevelopers.com/jobs/ext/506741-senior-program-manager-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Program Manager, Information Security - **Company:** BASIN SOD INC. - **Location:** Plano, TX, United States - **Experience:** Expert - **Salary:** $140,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Continuous Integration, Information Leak Prevention, DevOps, Monitoring of Systems, Identity and Access Management, Information Technology Operations, Nmap, PCI Data Security Standards, Azure Active Directory, Security Information and Event Management, Software Engineering, SonarQube, Systems Integration, Wireshark, Privacy Controls, Delivery Pipeline, Cyber Threat Analysis, Gitlab, Information Technology, Metasploit, Nessus, Nexpose, Devsecops - **Published:** June 7, 2026 - **Apply:** https://www.careerjet.com/jobad/use7a7ef96af7523f4d26e90f8bbb8cb81 ## About the Role * Bachelor's degree in Computer Science, Information Security, or related field (or equivalent experience) * 5+ years of progressive experience in information security * Strong program management and cross-functional leadership skills * Proven experience working with cloud security, particularly within Azure environments * Hands-on experience with Microsoft Entra ID (Azure AD) * Solid understanding and practical application of DevSecOps principles and tooling * Experience with security and vulnerability tools such as: * SonarQube, Nessus, Nmap, Nexpose, Metasploit, Wireshark, GitLab, etc. * Strong knowledge of security frameworks and standards: * ISO 27001, NIST, SOC 2, COBIT, ITIL, PCI-DSS, SANS Top 20 ## Description Are you passionate about combining security strategy, hands-on technical work, and business impact? We're seeking a Senior Program Manager Information Security to own our client's cybersecurity posture and help shape secure, scalable operations across the organization. This high-visibility role partners with leadership, engineering, and DevOps teams to identify risks, strengthen defenses, and drive modern security practices in a cloud-first environment., * Serve as the primary hands-on security owner & executor plus support broader security & data privacy function * Partner closely with IT Operations, Compliance, and Software Development teams, as well as cross-functional business stakeholders outside of IT * Take ownership of information security, cybersecurity, data privacy & security controls across the organization * Design, implement & maintain security controls, policies, standards, and procedures to mitigate evolving threats * Identify, analyze, and respond to security vulnerabilities, threat vectors, and incidents in real time * Lead incident response activities, including triage, investigation, containment, and remediation using logs, SIEM tools, and monitoring systems * Monitor system activity and perform continuous evaluation of security posture and risk exposure * Support secure application development by reviewing architectures, integrations, and DevSecOps practices * Assist in implementing data loss prevention (DLP), privacy controls, and compliance requirements * Administer and improve identity and access management controls using Microsoft Entra ID (Azure AD) * Work with mature DevSecOps processes, ensuring security is embedded into CI/CD & deployment pipelines * Document threats, vulnerabilities, and remediation strategies, and provide regular reporting to leadership * Collaborate on physical security systems like access controls & related infrastructure (training provided) * Participate in security system administration, monitoring, and operational support as needed * Support training and awareness initiatives related to security best practices and DevSecOps adoption * Transition from a hands-on individual contributor role into a future team leadership position, including people management as the function scales ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)