Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Security Program Manager image - Rise Careers
Job details

Senior Security Program Manager

We are looking for a strategic Senior Security Program Manager with experience managing a complex information security and compliance program. You will report to Senior Manager, Information Security. You will have a strong background in cybersecurity and compliance, with proven experience managing multiple compliance audits, multiple products, and large security initiatives with cross-functional teams. You will manage projects related to compliance controls mapping, organizational security improvements, and external audits. The compliance program encompasses FedRAMP, StateRAMP, TxRAMP, ISO 27001, SOC 2, PCI, HIPAA, FISMA, CJIS, and Cyber Essentials. 



What your impact will look like here
  • Lead and manage the security program initiatives, ensuring alignment with Granicus’ security objectives
  • Collaborate with management to define security priorities
  • Manage program improvements for control mapping across the organization, compliance frameworks, and products
  • Lead continuous improvement and growth project for response and recovery, including incident response, backups, failover / switchover, disaster recovery, and business continuity
  • Support risk management program activities, and drive continuous improvements to the risk assessment and reporting process
  • Coordinate internal and external audits, including planning, scheduling, and ensuring tracking of findings or continuous improvement recommendations
  • Contribute to review and update cycles of policies and trainings, along with other security stakeholders
  • Work with cross-functional stakeholders to identify and/or track security improvements
  • Regularly report status and next steps to management


You will love this job if you have
  • 7+ years in information security program management, with at least 5 years in a leadership or program management role
  • Proven track record of managing large-scale security programs and initiatives, working with cross-functional teams
  • Experience with external audits, such as FedRAMP, ISO 27001, and SOC 2 in order to manage audit planning, audit activities, and projects to build out audit runbooks
  • In-depth knowledge of common security frameworks, such as NIST 800-53, ISO 27001, PCI, HIPAA, SOC 2, and/or Cyber Essentials
  • Experience working with a robust product set of software and cloud services, including SaaS offerings hosted in AWS, Azure and/or GCP
  • Experience with risk management, incident response, disaster recovery, and business continuity
  • Strong understanding of cloud security controls, including network security and data protection controls
  • Familiarity with common security technologies, including SIEM, firewalls, IDS/IPS, encryption tools, and endpoint protection
  • Excellent leadership and interpersonal skills; strong communication skills, written and verbal
  • Experience working with software development and cloud operations teams at a SaaS and software company
  • Ability to communicate complex requirements and security concepts to technical and non-technical teams
  • Detail-oriented and able to manage multiple projects effectively
  • Experience working in a highly regulated environment is a plus (e.g., CJIS, HIPAA, FISMA, government, finance/banking, healthcare, or FedRAMP / DoD IL)
  • Relevant degrees or security certifications are a plus, such as CISSP, SEC+, CISM, CISA, CDPSE, or equivalent 


The Team

We area globally distributed workforce across the United States, Canada, United Kingdom, India, Armenia, Australia, and New Zealand.

 

The Culture

At Granicus, we are building a transparent, inclusive, and safe space for everyone who wants to be a part of our journey. A few culture highlights include –

-        Employee Resource Groups to encourage diverse voices

-        Coffee with Mark sessions – Our employees get to interact with our CEO on very important and sometimes difficult issues ranging from mental health to work life balance and current affairs.

-        Embracing diversity & fostering a culture of ideation, collaboration & meritocracy

-        We bring in special guests from time to time to discuss issues that impact our employee population

 

The Company

Serving the People Who Serve the People

Granicus is driven by the excitement of building, implementing, and maintaining technology that is transforming the Govtech industry by bringing governments and its constituents together. We are on a mission to support our customers with meeting the needs of their communities and implementing our technology in ways that are equitable and inclusive. Granicus has consistently appeared on the GovTech 100 list over the past 5 years and has been recognized as the best companies to work on BuiltIn.

Over the last 25 years, we have served 5,500 federal, state, and local government agencies and more than 300 million citizen subscribers power an unmatched Subscriber Network that use our digital solutions to make the world a better place. With comprehensive cloud-based solutions for communications, government website design, meeting and agenda management software, records management, and digital services, Granicus empowers stronger relationships between government and residents across the U.S., U.K., Australia, New Zealand, and Canada. By simplifying interactions with residents, while disseminating critical information, Granicus brings governments closer to the people they serve—driving meaningful change for communities around the globe.

Want to know more? See more of what we do here.

 

The Impact

We are proud to serve dynamic organizations around the globe that use our digital solutions to make the world a better place — quite literally. We have so many powerful success stories that illustrate how our solutions are impacting the world. See more of our impact here.

 

The Process

-        Assessment – Take a quick assessment.

-        Phone screen – Speak to one of our talented recruiters to ensure this could be a fit.

-        Hiring Manager/Panel interview – Talk to the hiring manager so they can learn more about you and you about Granicus. Meet more members on the team! Learn more and share more.

-        Reference checks – Provide 2 references so we can hear about your awesomeness.

-        Verbal offer – Let’s talk numbers, benefits, culture and answer any questions.

-        Written offer – Sign a formal letter and get excited because we sure are!

 

Benefits at Granicus India

Along with the challenges of the job, Granicus offers employees an attractive benefits package which includes –

-        Hospitalization Insurance Policy covering employees and their family members including parents

-        All employees are covered under Personal Accident Insurance & Term Life Insurance policy

-        All employees can avail annual health check facility 

-        Eligible for reimbursement of telephone and internet expenses

-        Wellness Allowance to avail health club memberships and/or access to physical fitness centres

-        Wellbeing Wednesdays which includes 1x global Unplug Day and 2x No Meeting Days every quarter

-        Memberships for ‘meditation and mindfulness apps including on-demand mental health support 24/7 

-        Access to learning management system Say., LinkedIn Learning Premium account membership & many more

-        Access to Rewards & recognition portal and quarterly recognition program

 

Security and Privacy Requirements

-        Responsible for Granicus information security by appropriately preserving the Confidentiality, Integrity, and Availability (CIA) of Granicus information assets in accordance with the company's information security program.

-        Responsible for ensuring the data privacy of our employees and customers, their data, as well as taking all required privacy training in a timely manner, in accordance with company policies. 

  

Granicus is committed to providing equal employment opportunities. All qualified applicants and employees will be considered for employment and advancement without regard to race, color, religion, creed, national origin, ancestry, sex, gender, gender identity, gender expression, physical or mental disability, age, genetic information, sexual or affectional orientation, marital status, status regarding public assistance, familial status, military or veteran status or any other status protected by applicable law.

Granicus Glassdoor Company Review
3.5 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Granicus DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Granicus
Granicus CEO photo
Mark Hynes
Approve of CEO

Average salary estimate

$125000 / YEARLY (est.)
min
max
$100000K
$150000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Security Program Manager, Granicus

Join Granicus as a Senior Security Program Manager in Bengaluru and become an integral part of our team dedicated to securing the future of the Govtech industry. We're on the lookout for an experienced professional to take charge of our robust information security and compliance programs. In this exciting role, you will partner with cross-functional teams to propel our compliance efforts across various frameworks like FedRAMP, ISO 27001, and SOC 2. Your expertise in overseeing large-scale security initiatives will play a crucial part in aligning with Granicus' security objectives. Imagine leading projects that enhance our organizational security and coordinating successful audits while driving continuous improvement across our security landscape! If you thrive in a dynamic environment and have over seven years of experience in information security management, this is your chance to showcase your skills. You will collaborate closely with management, manage compliance controls, and execute risk management activities—all while contributing to the learning and development of our engaged, globally distributed workforce. Plus, with a strong emphasis on fostering an inclusive workplace culture, you'll feel right at home as you support our mission of transforming how government and its constituents interact. Join us, and help us make a difference! We look forward to welcoming you!

Frequently Asked Questions (FAQs) for Senior Security Program Manager Role at Granicus
What does a Senior Security Program Manager do at Granicus?

At Granicus, a Senior Security Program Manager plays a vital role in overseeing security initiatives and compliance programs, managing audits, and ensuring that the organization meets various regulatory standards. This position requires a blend of leadership, risk management, and collaboration with cross-functional teams to enhance our overall security posture.

Join Rise to see the full answer
What qualifications are needed for a Senior Security Program Manager at Granicus?

To qualify for the Senior Security Program Manager role at Granicus, candidates should have at least 7 years of experience in information security program management, with a minimum of 5 years in leadership. Comprehensive knowledge of various compliance frameworks, and security technologies, as well as strong interpersonal skills are essential.

Join Rise to see the full answer
How does the seniority of the Senior Security Program Manager influence their work at Granicus?

The seniority of the Senior Security Program Manager grants them significant responsibility in developing and managing security programs. This role engages with upper management to define security priorities, lead cross-functional initiatives, and coordinate audits, ensuring strategic alignment with Granicus' security goals.

Join Rise to see the full answer
What types of compliance frameworks will the Senior Security Program Manager work with at Granicus?

The Senior Security Program Manager at Granicus will work with a variety of compliance frameworks including FedRAMP, ISO 27001, SOC 2, PCI, HIPAA, and others. Understanding these frameworks is crucial for effectively managing compliance audits and ensuring organizational adherence to security controls.

Join Rise to see the full answer
What is the work culture like at Granicus for a Senior Security Program Manager?

The work culture at Granicus is inclusive, supportive, and focused on collaboration. As a Senior Security Program Manager, you will find an environment that encourages diverse voices, ideation, and growth, allowing you to impact the organization positively while working alongside colleagues from around the globe.

Join Rise to see the full answer
What professional growth opportunities does Granicus offer for Senior Security Program Managers?

Granicus promotes professional growth through continuous learning and development opportunities. As a Senior Security Program Manager, you'll have access to a learning management system, mentorship, and the chance to enhance your skills in a dynamic and challenging environment.

Join Rise to see the full answer
What projects might a Senior Security Program Manager handle at Granicus?

A Senior Security Program Manager at Granicus might manage compliance controls mapping, plan and schedule internal and external audits, drive continuous improvement projects related to risk management, and lead initiatives focused on incident response, disaster recovery, and organizational security enhancements.

Join Rise to see the full answer
Common Interview Questions for Senior Security Program Manager
How do you prioritize security initiatives when managing programs?

When prioritizing security initiatives, it’s essential to assess risks and align projects with organizational objectives. I evaluate the potential impact and likelihood of vulnerabilities, gather input from cross-functional teams, and ensure sufficient resources are allocated to high-priority projects to mitigate risks effectively.

Join Rise to see the full answer
Can you explain your experience with compliance frameworks relevant to this role?

In my previous roles, I have worked extensively with various compliance frameworks such as FedRAMP, ISO 27001, and SOC 2. I've managed audits, aligned policies to meet standards, and communicated requirements effectively to both technical and non-technical teams, ensuring a comprehensive understanding and adherence throughout the organization.

Join Rise to see the full answer
Describe a challenging security program project you managed and the outcome.

In a previous position, I led a complex security program project involving multiple security audits. Despite tight timelines and resource constraints, I structured a detailed plan, coordinated with cross-functional teams, and ensured clear communication. The project concluded successfully, leading to improved compliance ratings and organizational security posture.

Join Rise to see the full answer
How would you manage a security incident response process?

To manage a security incident response process, I would first establish a clear response plan that outlines communication protocols, roles, and responsibilities. I would ensure regular training and simulations for the team, conduct thorough post-incident reviews to identify lessons learned, and continuously update our incident response strategy based on findings.

Join Rise to see the full answer
What measures do you take to ensure effective team collaboration in security projects?

I prioritize open communication and regularly facilitate meetings that bring together stakeholders from different teams. By fostering a collaborative environment, sharing updates, setting clear objectives, and utilizing project management tools, I ensure everyone is on the same page and can contribute effectively to our security projects.

Join Rise to see the full answer
How do you stay updated with the latest security trends and compliance requirements?

I actively participate in security forums, attend relevant conferences, and enroll in professional training programs. Staying connected with industry leaders and following cybersecurity publications also helps me keep up with the latest trends, ensuring that I can incorporate current best practices into my role.

Join Rise to see the full answer
What strategies do you implement for effective risk management?

For effective risk management, I adopt a proactive approach by conducting comprehensive risk assessments, categorizing risks according to their potential impact, and implementing controls to mitigate them. Regular reviews and updates of the risk management strategy ensure we adapt to evolving threats and compliance requirements.

Join Rise to see the full answer
Explain how you would approach internal and external audits.

I would start by meticulously planning the audit process, identifying scope, and establishing a timeline. Collaborating with relevant departments is essential to gather information and address potential issues upfront. During audits, I maintain open lines of communication and ensure all findings are documented for continuous improvement post-audit.

Join Rise to see the full answer
Describe how you handle disagreements within your team regarding security priorities.

In instances of disagreement within the team, I encourage open dialogue to surface concerns and perspectives. A collaborative approach fosters understanding, and by analyzing the data and assessing the potential implications of differing priorities, we can make informed decisions aligned with our organizational security goals.

Join Rise to see the full answer
What role does documentation play in security program management?

Documentation is critical in security program management as it ensures transparency, compliance, and accountability. Proper documentation of processes, incidents, audits, and policy changes enables us to maintain robust records for evaluation and continuous improvement while serving as a training resource for team members.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 5 days ago
Photo of the Rise User
Posted 3 days ago
Photo of the Rise User
WebMD Hybrid No location specified
Posted 6 days ago
Photo of the Rise User
Posted 4 hours ago
Photo of the Rise User
Posted 6 days ago

Granicus is a leading provider of a platform of solutions that make digital government possible to more than 6,000 government agencies, including 850 state departments across the U.S., U.K., Australia, New Zealand, and Canada.

125 jobs
MATCH
Calculating your matching score...
BADGES
Badge ChangemakerBadge Diversity ChampionBadge Family FriendlyBadge Work&Life Balance
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
November 28, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!