Duke University

ITSO Sr. Program Manager

Duke University$100K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in related field plus 3+ years of experience in security, audit, analytics, or related areas.
  • 5+ years of combined education/experience in a relevant field is acceptable.
  • Preferred certifications: SANS/GIAC, CISSP, CISA, CISM.
  • Experience with cybersecurity, risk analytics, or security program development preferred.
  • Proficient in quantitative and qualitative analysis for data-driven decision making.

Responsibilities

  • Assess the cyber risk landscape and improve risk quantification with metrics dashboards.
  • Advise on the development of tracking and measurement tools for security assets and practices.
  • Identify strategic priorities for ITSO initiatives based on metrics and potential impact.
  • Provide briefings to the security community on trends affecting operational decisions.
  • Lead projects to align security programs with industry best practices.
  • Manage embedded security roles for program alignment.
  • Develop materials that articulate security policies and guidance.

Benefits

  • Competitive benefits package including health insurance and retirement plans.
  • Work-life balance with a supportive culture that values flexibility.
  • Opportunities for professional growth and influence in cybersecurity strategy.
  • Work in a collaborative and intellectually rich environment.
  • Be part of an innovative, mission-driven security organization.
Full Job Description
Duke University's IT Security Office (ITSO) is seeking a skilled Senior Program Manager to help shape, communicate, and advance Duke's cybersecurity strategy. This role focuses on quantifying, contextualizing, and managing cyber risk across Duke University. You will partner closely with leadership, including the CISO and other Security Office leaders, to craft and communicate standards, practices, and program direction.

This position is ideal for someone who thrives in a fast-paced, analytical environment and enjoys translating complex information into clear guidance for diverse audiences. While prior security experience is helpful, candidates with strong backgrounds in analytics, risk, or strategic program management are encouraged to apply.

Minimum Requirements
• Bachelor's degree in a related field plus 3 or more years of experience in security, audit, analytics, or related areas.

OR
• 5+ years of combined education/experience in a related field.

Preferred Qualifications
• Certifications such as SANS/GIAC, CISSP, CISA, CISM.
• Experience with cybersecurity, risk analytics, or security program development.
• Proficiency with quantitative and qualitative analysis supporting data-driven decisions.

Other Requirements
• Strong verbal, written, and analytical communication skills.
• Ability to collaborate across diverse teams and influence through clarity and insight.
• Ability to work independently and in team settings on complex, fast-moving projects.

Be Bold

As Senior Program Manager, you will help drive the strategic maturity of Duke's information security program guided by the CI Security Critical Controls. This means providing insight into cyber risk trends, enabling data-driven decision-making, and ensuring the security program evolves with the regulatory landscape, including NIST SP 800-171.
• Assess the cyber risk landscape using metrics dashboards and advise on enhancements to improve clarity and risk quantification.
• Advise on development of inventory, tracking, and measurement tools, including dashboards covering accounts, devices, servers, network activity, websites, and adoption of key controls such as MFA, endpoint management, patching, and automated IP blocking.
• Identify strategic priorities for ITSO initiatives based on metrics, analysis, potential impact, and risk.
• Provide briefings to the security community, highlighting trends and implications for operational and strategic decisions.
• Lead project work to align the program with actionable industry best practices.
• Manage embedded security roles to ensure alignment with program priorities.
• Develop materials articulating policies, positions, and security guidance.
• Create innovative approaches to enhance the efficiency and value of ITSO's risk management programs-including vendor reviews.
• Coordinate response efforts on cross-functional issues involving groups such as Privacy and Audit, the Duke Health Information Security Office, and other departmental IT groups.

Supervisory Responsibilities
• Manage a team of 3-7 direct reports, 5 indirect reports, and graduate student interns.
• Perform all aspects of staff management including hiring, performance management, professional development, recognition, and staffing alignment for services provided by the team.

About Duke University

Duke University is a private research university in Durham, North Carolina. Founded by Methodists and Quakers in the present-day town of Trinity in 1838, the school moved to Durham in 1892. Duke's campus spans over 8,600 acres on three contiguous campuses in Durham as well as a marine lab in Beaufort. Duke University is consistently ranked among the top 20 universities in the United States and is a member of the prestigious Ivy League. Duke is also known for its highly ranked medical, law, and business schools. Duke University has a diverse student body, with students from all 50 states and over 100 countries. Duke University was founded in 1838 and is located in Durham, North Carolina.
Learn more about Duke University
Size
40,000 employees
Industry

Similar Jobs

More Jobs at Duke University

More Information Technology Jobs

Find similar ITSO Sr. Program Manager jobs: