Technical Program Manager leading the delivery of security and compliance solutions for Onit’s SaaS platforms. Collaborating with multiple teams to ensure regulatory compliance and best practices.
Responsibilities
Drive cross-functional initiatives to deliver security and compliance solutions, including resource planning, timeline management, and coordination with external vendors.
Monitor and manage remediation efforts across applications and infrastructure for issues identified via scans, assessments, and customer feedback.
Manage and track the execution of key security and compliance such as access reviews, WAF reviews, and other quarterly and yearly BAU activities required by our security and compliance certifications and customer contracts.
Facilitate the rollout and adoption of the Security Champion Program across teams to level up security knowledge, increase security visibility with tooling, and other key practices.
Oversee the continued adoption and integration of Vanta for automated compliance monitoring.
Support selection, onboarding, and coordination of vendors for penetration testing, audits, and other security services.
Evaluate system designs for security strengths and weaknesses and facilitate technical discussions.
Act as product owner for security and compliance initiatives, creating user stories, prioritizing work, and guiding teams through grooming and delivery.
Work with teams across regions to define, design, and deliver secure SaaS solutions.
Assist with process improvements with incident response, training, runbook definition, and other key areas of the security and compliance program.
Maintain, track, and report key performance indicators/metrics for various activities in security and compliance.
Document key practices within the security and compliance function to improve visibility and adoption.
Requirements
10+ years in technical project management or similar leadership roles.
5+ years in security and compliance domains.
Strong technical background in the cybersecurity domain which includes experience with security tooling, vulnerability management, 3rd party penetration testing, incident response, thread detection, etc.
Proven track record executing security and compliance projects for Enterprise SaaS solutions.
Extensive experience managing the security of cloud-based applications (AWS preferred)
Ability to navigate trade-offs and prioritize across multiple teams.
Proficiency in agile methodologies and tools (e.g., Jira, Scrum, Kanban).
Experience with security and compliance frameworks such as SOC2, NIST, and ISO 27001.
Strong communication, problem-solving, and collaboration skills.
Experience with EDR, CSPM, and SEIM security tooling.
Relevant certifications (CISSP, CCSP, CISM, AWS Security Specialty) are a plus.
Regulatory, compliance, or legal experience is a plus.
Experience with containerized applications is a plus.
Benefits
Health Coverage: Employee and immediate family members.
Time Away: Flexible paid time off and 10 company paid holidays annually.
Family Support: Exceptional paid leave for birth parents, non-birth parents, and caregivers. Onit also offers surrogacy and adoption reimbursement.
Income Protection: 100% employer-paid life and disability insurance.
Additional Coverage Options: Voluntary benefits including hospital indemnity, critical illness, accident, and even pet insurance.
Tax-Advantaged Accounts: Flexi, NPS.
Community Engagement: One paid volunteer day each year to give back to the community.
Manager at PwC contributing to digital transformation in Utilities through technology consulting and stakeholder management. Focused on creating strategies and providing technology solutions in a data - driven world.
Research Associate conducting advanced research in iOS security within a leading institute for applied cybersecurity. Emphasis on secure application development and vulnerability analysis.
Cybersecurity Engineer focused on threat monitoring and incident response for Verizon's network security. Collaborating on security architecture and vulnerability management across multiple locations.
Senior Manager of Application Security leading initiatives to protect applications at Nordstrom through strategic leadership and AI - driven tooling. Collaborating with engineering to ensure secure software development practices.
Information Security Engineer responsible for deploying and supporting security tools across cloud and on - premise systems. Collaborating with IT to mitigate security risks in a hybrid work environment.
Casual Retail Security Officer for MSS Security ensuring safety at Tweed Mall in Tweed Heads. Responsible for patrols, incident response, and customer service.
Financial security advisor at Desjardins developing client relationships and selling life and health insurance products. Focusing on customer satisfaction and personalized financial solutions.
Principal Information Security Consultant at Westpac focusing on security protocols and employee benefits for staff. Hybrid role centrally located with opportunities for professional development and employee perks.
Engineer supporting secure development lifecycle processes for product lines in the energy sector. Collaborating with R&D on security requirements and compliance audits.
Automation Oversight Engineer providing oversight of compliance in automated device configurations for Comcast Business. Managing configuration checks and reporting, ensuring reliable oversight and improvement strategies.