Role description
Security Project Manager
Boston, MA(Onsite)
Core Responsibilities
Lead and operate an enterprise security program focused on the security posture of applications technology platforms data integrations tools and third party services.
Build and maintain a riskbased view of the enterprise attack surface including customermember applications teammember tools SAP and enterprise platforms infrastructure data flows APIs SaaS products AIenabled capabilities and vendormanaged services.
Coordinate security assessments and assurance activities across Infrastructure Cybersecurity Penetration Testing application teams SAPenterprise platforms Data and AI Architecture Privacy Legal Compliance Internal Audit Procurement and third parties.
Ensure the appropriate specialists are engaged for each priority initiative or exposure including architecture review threat modeling vulnerability assessment penetration testing dataprivacy review access review application API security review and vendor due diligence.
Translate technical findings into clear business risk statements priorities remediation plans and executive decisions.
Drive remediation of material security gaps by aligning accountable owners milestones funding needs dependencies and escalation paths.
Develop and manage the program charter integrated plan timeline governance model and meeting cadence.
Maintain an active RAID logrisks assumptions issues and dependenciesand escalate material items promptly.
Produce clear weekly program reporting and executive dashboards covering progress security posture assessment coverage material risks remediation status decisions needed and overall program health.
Partner with technology and business leaders to prioritize security investments based on enterprise exposure membercustomer impact business value operational resilience regulatory requirements and risk tolerance.
Build productive relationships with vendors and service providers ensure technical operational and contractual security obligations are assessed and monitored.
Expected Outcomes
A clear prioritized view of the enterprise security landscape across critical applications platforms data flows integrations tools and third party services.
Meaningful coverage of high risk systems major technology changes and new vendors through appropriate security privacy architecture and thirdparty reviews before release or implementation.
Material risks have accountable owners documented remediation plans target closure dates and timely escalation when progress stalls.
A measurable reduction in overdue highseverity findings and unresolved material security risks.
Faster decisions on material risk an executive decision approved remediation plan or documented risk acceptance.
Repeatable security assurance practices that are understood and adopted across technology and business teams.
Executive leadership has a concise reliable view of security posture top risks remediation progress residual risk investment needs and decisions requiring attention.
A functioning governance cadence that resolves blockers maintains accountability and keeps the program focused on the highest enterprise risks.
Stronger thirdparty oversight including risk assessments contractual safeguards and ongoing monitoring for critical vendors and connected services.
Continuous improvement in the organizations ability to identify prioritize remediate and communicate enterprise security risk.