> Markdown version of [/jobs/ext/739913-senior-cybersecurity-program-manager](https://www.wearedevelopers.com/jobs/ext/739913-senior-cybersecurity-program-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cybersecurity Program Manager - **Company:** Spanidea Systems LLC - **Location:** San Jose, CA, United States - **Experience:** Expert - **Salary:** $156,000.0 - $187,200.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Cyber Security, Software Vulnerability Management, Information Technology, CIS Benchmarks - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6856af8f14c38eb8 ## About the Role Do you have experience in Vulnerability management?, Do you have a Bachelor's degree?, * 10+ years of cybersecurity experience, including 5+ years leading security programs,governance, or strategic initiatives. * Proven expertise in developing IT security policies, standards, and procedures fromthe ground up. * Strong knowledge of cybersecurity frameworks and compliance standards,including NIST CSF, ISO 27001, CIS Controls, SOC 2, and CMMC. * Experience in risk management, security governance, compliance programs, and vulnerability management. * Demonstrated ability to lead cross-functional teams and manage complexenterprise security initiatives. * Strong understanding of security controls, threat modeling, and cybersecurity bestpractices. * Experience with Agile, Waterfall, or similar program management methodologies. * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field. * PMP or equivalent project management certification is highly preferred. ## Description * Lead the development and implementation of enterprise-wide cybersecurity programs, governance frameworks, and strategic initiatives. * Create, document, and maintain IT security policies, standards, and procedures,ensuring alignment with industry best practices and regulatory requirements. * Partner with IT, Security, Risk, Compliance, and business stakeholders to identifysecurity gaps, establish controls, and drive continuous improvement. * Oversee cybersecurity roadmaps, program objectives, KPIs, budgets, and resourceplanning to support organizational goals. * Ensure compliance with frameworks and regulations such as NIST, ISO 27001, SOC2, CMMC, CCPA, and CPRA. * Lead risk assessments, vulnerability management, security reviews, and incidentresponse planning activities. * Manage security architecture reviews, technology evaluations, and optimization ofsecurity tools and controls. * Provide executive leadership and board-level reporting on cybersecurity posture,compliance status, risks, and program performance. * Promote security awareness and foster a strong cybersecurity culture across theorganization. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [ShapeShift: Reinventing Agile for a B2B SaaS Scale-Up](https://www.wearedevelopers.com/videos/1655-shapeshift-reinventing-agile-for-a-b2b-saas-scale-up) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)