Additional Detail
Senior IT Program ManagerStarting Salary Range: $125,000 - $160,000
The State Corporation Commission (SCC) is seeking a Senior IT Program Manager to join our Enterprise Technology Services Division. The Senior IT Program Manager will be responsible for planning, coordinating, and overseeing the execution of IT and cybersecurity programs, projects, and initiatives that protect the SCC's information assets and technology infrastructure. The Senior IT Program Manager will work across departments, including managing a cross-functional team, vendors, and stakeholders to deliver security capabilities on time, within scope, and on budget.
Essential Functions of the Senior IT Program Manager position includes the following:
- Establish and oversee governance processes for cybersecurity initiatives, ensuring alignment with enterprise priorities and compliance requirements.
- Lead multiple concurrent cybersecurity projects, ensuring dependencies are managed and milestones are met.
- Manage relationships with vendors, MSSPs/MDR providers, and consulting partners.
- Serve as the primary point of contact for program-related decisions and strategic direction.
- Develop, manage, and maintain cybersecurity program plans that adhere to relevant frameworks and regulations as well as support organizational security objectives and risk tolerance.
- Track program progress and measure success using key performance indicators (KPIs) and security metrics to drive continuous improvement.
- Oversee the procurement and implementation of cybersecurity technologies, tools, and services.
- Lead regular executive briefings and status updates on cybersecurity program progress, challenges, and achievements.
- Prepare communications and reports for internal and external stakeholders, including reports for internal and external audits.
- Identify and track cybersecurity risks, threats, and vulnerabilities across programs and projects.
- Assist in coordinating cybersecurity incident response activities and lessons learned.
- Partner with IT teams to validate risk mitigation strategies and incident response readiness.
- Track and remediate audit findings, security exceptions, and penetration test findings.
- Assist with maintaining risk register and work with IT and business units to close control gaps.
- Support the development and testing of business continuity and disaster recovery plans as they relate to cybersecurity.
- Perform related work as required.
This position offers a hybrid work schedule (some in-office and telework days each week) as well as a variety of professional development and training opportunities.
Please Note: SCC only accepts applications received through its career center site. Applications submitted through Virginia Jobs site directly will not be considered.
For more information and to apply for this position directly on the SCC Career Center website, click the
Additional Detail button on this page.
To view all current SCC job openings, visit the SCC Career Center website and click the Search button under Job Search.