What you’ll be doing...The Verizon Cyber Security (VCS) organization securely enables the business by protecting assets and information across Verizon systems, networks, infrastructure, and applications. VCS integrates cybersecurity governance, policies, technologies, and operations across Verizon and works to incorporate security into the design of technology systems and services. In VCS, the Cyber Governance team defines cyber policies, maintains regulatory alignment, and drives organizational accountability across business units.
The Cyber Governance Program Lead will serve as a key individual contributor owning the operational management and execution of the enterprise cyber risk register and associated business-owned remediation tasks. You will be responsible for collaborating with cross-functional teams to ensure identified security risks, audit findings, and governance gaps are remediated in a prioritized, timely manner according to severity, threat context, and business impact. You will act as the primary Governance engine driving risk closure across technology, product, and business engineering teams.
- Maintaining, optimizing, and overseeing the daily operational workflow of the enterprise Cyber Risk Register and prioritization queue.
- Driving end-to-end accountability by actively following up with system owners, engineering teams, and business units to enforce remediation deadlines and milestone commitments in partnership with TPD, N&T, and IT Security Teams.
- Evaluating LLM-generated and automated risk prioritization determinations based on technical severity, business context, asset criticality, regulatory impact, and compensating controls. Provide ongoing feedback to continuously improve LLM training and automation capabilities.
- Facilitating regular cadence meetings with cross-functional technical teams to remove blockers, clarify governance expectations, and establish realistic remediation roadmaps.
- Establishing and executing formal escalation pathways for overdue risks, unmitigated control gaps, or non-responsive risk owners, elevating visibility to senior leadership.
- Aggregating and analyzing risk trends to build and present clear governance metrics, dashboards, and executive level status readouts.
- Reviewing, evaluating, and processing policy exception and risk acceptance requests, ensuring all proposals meet governance standards before submission for approval decisions.
- Partnering closely with BISO, IRM, VIA, and other VCS teams to ensure findings are ingested properly and tracked through full post-remediation validation.
- Leading end-to-end SSDLC governance by ensuring threat modeling, risk assessments, and security controls are embedded into engineering workflows in partnership with TPD and IT Security.
- Driving OSS supply chain risk reduction through robust usage policies, enforcing license compliance, and automated vulnerability management in partnership with TPD and IT Security Teams.
What we’re looking for...You are an assertive, highly organized process operator who excels at driving accountability across matrixed environments. You understand and can communicate technical risk context and know how to push back constructively when teams push off security deadlines. You know how to translate dense security and compliance findings into clear, prioritized action plans, and you possess the persistence required to chase work through to complete resolution. You are a clear communicator who can discuss technical nuances with engineers and summarize risk posture concisely for leadership.
You’ll need to have:
- Bachelor’s degree or four or more years of work experience.
- Eight or more years of relevant work experience in Cybersecurity Governance, Risk Management & Compliance (GRC), IT Audit, or Technical Program Management.
- Experience managing risk registers, issue tracking queues, or technical remediation workflows.
Even better if you have one or more of the following:
- Bachelor’s degree in Information Systems, Cybersecurity, Business Administration, or a related technical field.
- Professional certifications such as CRISC, CISM, CISSP, CISA, or PMP.
- Experience utilizing enterprise GRC platforms (e.g., ServiceNow GRC, Archer, etc.) and issue-tracking platforms (e.g., Jira).
- Direct, hands-on experience designing, implementing, or auditing SSDLC methodologies and/or OSS management programs within a complex engineering environment.
- Familiarity with internal (ViSF) and industry control frameworks and standards (e.g., NIST CSF, ISO 27001, PCI-DSS, SOX).
- Proven track record of influencing cross-functional technical teams and driving operational accountability without direct authority.
- Strong data visualization and reporting skills using tools like Tableau, Looker, Google Sheets, or Excel to tell a story with risk metrics.
- Excellent written and verbal communication skills with experience building leadership presentations and running cross-departmental escalation calls.
If Verizon and this role sound like a fit for you, we encourage you to apply even if you don’t meet every “even better” qualification listed above.
In this hybrid role, you'll have a defined work location that includes working from home and a minimum of three days per week in the office, which will be set by your manager. Employees are responsible for maintaining compliance with hybrid work policies.
Scheduled Weekly Hours40
Benefits and CompensationOur benefits are designed to help you move forward in your career, and in areas of your life outside of Verizon. From health and wellness benefit options including: medical, dental, vision, short and long term disability, basic life insurance, supplemental life insurance, AD&D insurance, identity theft protection, pet insurance and group home & auto insurance. We also offer a matched 401(k) savings plan, up to 8 company paid holidays per year and up to 6 personal days per year, paid parental leave, adoption assistance and tuition assistance, plus other incentives, we’ve got you covered with our award-winning total rewards package. Depending on the role, employees have the opportunity to receive compensation in the form of premium pay such as overtime, shift differential, holiday pay, allowances, etc. Newly hired employees receive up to 15 days of vacation per year, which grows with additional service. For part-timers, your coverage will vary as you may be eligible for some of these benefits depending on your individual circumstances.
The salary will vary depending on your location and confirmed job-related skills and experience. This is an incentive based position with the potential to earn more. For part-time roles, your compensation will be adjusted to reflect your hours.
The annual salary range for the location(s) listed on this job requisition based on a full-time schedule is: $137,000.00 - $263,000.00.