Role Overview:This role is for an OT Security Program Manager responsible for overseeing and coordinating multiple security workstreams within Lab Systems & OT Security. The manager will drive program planning, track progress, coordinate agile delivery teams, manage stakeholders, and ensure effective communication and dependency management across various internal and external partners.
Key Responsibilities:- Own and maintain the master program plan across four active security workstreams: NAA remediation, software download restrictions, vulnerability remediation, and USB data transfer controls.
- Maintain the program Gantt chart, ensuring accuracy of task owners, dependencies, milestones, and target dates.
- Track progress against key milestones including RC4 pilot test, allow/deny list activation, service account demand intake launch, system owner engagement completion, and full Phase 2 completion.
- Identify and manage task dependencies across workstreams, site partners, InfoSec, Active Directory teams, ServiceNow, and external vendors (BeyondTrust, CrowdStrike, Waters).
- Maintain a live risk and issue log, escalating blockers in a timely manner.
- Facilitate regular sprint planning, stand-ups, and retrospectives for the agile pod of five OT Security Engineers.
- Manage the team's work backlog, prioritizing items in alignment with program milestones.
- Coordinate workload distribution across site partners to ensure balanced coverage and tracked site-specific dependencies.
- Work closely with the Business Analyst to align stakeholder engagement timelines with engineering execution.
- Prepare and deliver regular program status updates to Head of Lab Solutions, Program Manager, and Stu Director, Lab Systems.
- Produce clear, concise reporting packs for leadership audiences including workstream RAG status, milestone progress, open risks, and upcoming decision points.
- Maintain the Lab & OT Security Confluence page, ensuring workstream status, milestone dates, and team information remain current.
- Support leadership reviews with CISO and CIDO sponsors, providing structured input on program health.
- Track and manage external dependencies with InfoSec, Active Directory teams, ServiceNow, and technology vendors including BeyondTrust and CrowdStrike.
- Coordinate vendor engagement scheduling across sites, ensuring vendor access approvals and named-allow confirmations are tracked.
- Monitor the service account demand intake pipeline once activated, ensuring requests are triaged and actioned within agreed timelines.
- Plan and coordinate hypercare periods following major program milestones, ensuring the team is staffed and response processes are documented.
- Track and close out hypercare findings, ensuring issues identified during stabilization periods are logged and resolved.
- Maintain a lessons-learned log across all workstreams, contributing to continuous improvement.
Required Skills:- Strong command of program planning tools and techniques including Gantt charts, risk logs, RAID registers, dependency mapping, and milestone tracking.
- Proficiency in project management tooling such as Jira, Microsoft Project, or Smartsheet.
- Familiarity with both agile (Scrum/Kanban) and traditional waterfall delivery approaches.
- Excellent written and verbal communication skills, capable of producing crisp status reports and presenting program health to senior leadership.
- Strong meeting facilitation skills for structured stand-ups, planning sessions, and risk reviews with distributed teams.
- Ability to build credibility quickly with both technical engineers and non-technical business stakeholders.
- Proficiency with Confluence or equivalent wiki platform for maintaining living program documentation.
- Experience with ServiceNow or equivalent ITSM platform for demand tracking and change management.
- Competency in Microsoft Office suite (Excel, PowerPoint, Word) for reporting, Gantt management, and communications.
- Highly organized with a strong bias for structure and clarity.
- Proactive and anticipatory, surfacing risks and dependencies before they become issues.
- Collaborative and low-ego, demonstrating effective influence without authority.
- Resilient and adaptable, able to replan quickly when priorities shift.
Qualifications:- Bachelor's degree required (B.S. in Business, Information Systems, Engineering, or a related field, or equivalent practical experience).
- PMP, PRINCE2, or equivalent project management certification preferred.
- 3-6 years of relevant project or program management experience, preferably within technology, IT security, or a regulated life sciences environment.
- Demonstrated experience managing concurrent workstreams with multiple owners, dependencies, and stakeholders in a complex organizational environment.
- Experience working with or coordinating agile delivery teams, including facilitation of sprint ceremonies.
- Proven track record of producing clear, structured program reporting for senior and executive audiences.
- Experience managing vendor relationships and external dependencies as part of a delivery program.
- Prior experience in a pharmaceutical, biotech, or similarly regulated industry is strongly preferred.
Preferred Skills:- PMP, CAPM, PRINCE2, or SAFe certification is a plus.
- Familiarity with security or IT operations tooling (CrowdStrike, BeyondTrust, Active Directory) is a meaningful advantage.