Cyber Security Program Manager
Ceribell is a medical technology company focused on transforming the diagnosis and management of patients with serious neurological conditions. The Ceribell System is a novel, point-of-care electroencephalography (“EEG”) platform designed to address unmet needs in the acute care setting, used across hundreds of community hospitals, large academic facilities, and major IDNs.
About the role
As the Cybersecurity Program Management Lead, you will coordinate efforts with Information Security and Governance, Risk & Compliance (GRC) leadership to strategically plan, execute, and oversee cybersecurity initiatives aligned with company-wide objectives and regulatory compliance. This role involves directing continuous monitoring, leading FedRAMP audits, improving NIST 800-53 control effectiveness, and collaborating on risk assessments, vulnerability management, and security training.
You will partner across the organization to align on strategic IT and Security objectives, drive operational efficiency, and manage complex, high-impact projects. Additionally, you will contribute to incident response planning, ensure compliance with evolving frameworks, and optimize project management tools like Jira or Notion.
Responsibilities
- Lead coordination efforts with Information Security and GRC leadership to strategically plan, execute, and oversee cybersecurity initiatives, ensuring alignment with company-wide objectives and regulatory compliance.
- Direct and refine ongoing continuous monitoring requirements to ensure effectiveness and audit readiness.
- Lead and participate in FedRAMP audits, driving documentation strategy, POA&M tracking, and interdepartmental reporting between vendors, internal teams, and Security leadership.
- Guide the team in identifying and prioritizing improvements for NIST 800-53 control effectiveness and maturity.
- Coordinate risk assessments, vulnerability management activities, and security training schedules in collaboration with key stakeholders.
- Partner across the organization to align on strategic IT and Security objectives, shaping roadmaps and navigating complex, high-impact projects with agility.
- Drive initiatives to streamline operational efficiency and maximize software utilization across the enterprise.
- Collaborate with the GRC team to ensure policies, procedures, and standards are proactively updated to maintain alignment with evolving compliance frameworks.
- Facilitate security risk assessments, documenting critical risks and establishing measurable strategies for mitigation and accountability.
- Provide strategic input in incident response planning and execution, contributing to process design and assisting in escalation and resolution of security incidents.
- Drive delivery of complex, cross-functional projects—from requirements gathering through implementation—defining schedules, scopes, and mitigation plans for enterprise-level initiatives.
- Manage multiple, concurrent initiatives with conflicting priorities and tight deadlines, ensuring alignment with organizational goals.
- Optimize use of project management tools such as Jira or Notion to enhance transparency, reporting, and collaboration.
Requirements
- 10+ years of progressive experience in cybersecurity, FedRAMP, or IT program management with a proven track record of leading large-scale security or compliance programs.
- Demonstrated leadership in Program Management activities, including continuous monitoring, documentation, and third-party assessments.
- Deep expertise in NIST frameworks (800-53, 800-30, 800-161) with the ability to advise teams and influence policy and control implementation.
- Experience overseeing multiple compliance programs (e.g., SOC 2 Type 2, HIPAA, SOX ITGC) and ensuring cross-functional coordination for audit readiness.
- Strong executive communication skills with the ability to present complex security topics to both technical and non-technical audiences.
- Advanced problem-solving, strategic thinking, and decision-making abilities in complex IT environments.
- U.S. citizenship required due to federal compliance.
- Must meet identification verification requirements prior to start.
- Demonstrated ability to thrive in high-pressure, fast-paced environments while managing competing priorities.
- Open to remote candidates.
Preferred Qualifications
- Industry-recognized certifications such as CISA, CISSP, or PMP.
- Experience with security and monitoring tools such as Jira, Splunk, Tenable, and Trend Micro.
- Strong knowledge of cloud architectures, especially AWS and associated services.
Pay
Compensation range: $144,000—$195,000 USD. A candidate’s final salary offer will be based on skills, education, work location, and experience, and may include bonuses consistent with Ceribell’s corporate compensation plan.
Benefits
- Performance-based incentive compensation (varies by role).
- Equity opportunities.
- 100% employer-paid health benefits for employees.
- 50% - 70% employer-paid health, dental, and vision for dependents (depending on plan selection).
- 100% paid life and long-term disability insurance.
- 401(k) with a generous company match.
- Employee Stock Purchase Plan (ESPP) with a discount.
- Monthly cell phone stipend.
- Flexible paid time off.
- 13 paid holidays + 3 company wellness days.
- Excellent parental leave policy.
- Fantastic culture with tremendous career advancement opportunities.
- Mission-driven organization.