Director, Cybersecurity Program Delivery Lead
for sections present: About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule. Only include sections with real content. We need to parse the posting. First, job title: Cybersecurity Program Delivery Lead Global Cybersecurity and Fraud Management, Program Office. Not to repeat as heading. We need to extract content. Let's identify sections: - About the role: The first paragraph: "Cybersecurity Program Delivery Lead Global Cybersecurity and Fraud Management, Program Office is seeking an accomplished Program Manager to drive agile delivery of our strategic cyber and fraud program —a role that bridges technical innovation with enterprise cybersecurity strategy by coordinating cross-functional teams to deliver transformative capabilities. This position demands expert-level program management capability to lead the organization's largest and most complex initiatives, with a specific focus on applying that expertise to frontier AI strategic projects; given the high-visibility, high-complexity nature of this AI-focused mandate, we're looking for a leader who has already proven this level of capability, ideally with prior hands-on experience navigating the unique coordination challenges, vendor landscape, and cross-functional dependencies inherent to AI-related programs." That's about the role. - Responsibilities: The list under "Key Responsibilities And Duties" includes many bullet points. We'll need to capture each as
- .
List items:
- Program Coordination: Coordinate cross-functional activities across GCFM, CTO, CDAIO, and business teams. Maintain program schedules, track milestones, manage dependencies, risk management and ensure alignment with cybersecurity strategy and organizational objectives.
- Stakeholder Management: Translate technical cyber concepts for executive audiences and business priorities for technical teams. Prepare status/executive reports, facilitate steering committee meetings, and maintain transparency on progress, challenges, and resource needs.
- Roadmap: Work with internal GCFM stakeholders and develop 6 quarter roadmaps, including 30-60-90 day plans.
- Risk and Compliance: Ensure strategic initiatives comply with data governance, privacy requirements, and TIAA's Enterprise Responsible AI Policy.
- Resource and Vendor Management: Track budgets, allocate resources, and coordinate with external vendors.
- Metrics and Reporting: Define and track KPIs including threat detection accuracy, false positive rates, incident response times, and efficiency gains. Report regularly on metrics to demonstrate value and inform scaling decisions.
- Change Management: Support adoption through training coordination, process documentation, user feedback collection, and addressing resistance. Develop adoption plans that introduce new cyber controls while maintaining operational continuity.
- Continuous Improvement: Facilitate retrospectives after initiatives and milestones. Capture lessons learned, identify process improvements, share best practices, and build institutional AI delivery capability.
- Agile: Facilitate agile ceremonies including sprint planning, daily standups, retrospectives, and demos. Maintain and prioritize product backlogs, manage sprint execution, remove impediments, and foster collaboration within cross-functional agile teams delivering AI capabilities.
We need to preserve all substantive info. Could combine each bullet as a
- containing the description.
- Requirements: There's "Educational Requirements University (Degree) Preferred Work Experience 5+ Years Required; 7+ Years Preferred Physical Requirements Physical Requirements: Sedentary Work Career Level 9IC". Also "Required Skills 5+ years of experience in Program Delivery 3+ years of Strategy Planning 2+ years of experience in a Cybersecurity role". Also "Preferred Skills Experience in automation to simplify processes Knowledge of AI concepts and how it ties in with Cybersecurity Development of 6 quarter road map including 30/60/90 Day Plans Resource and vendor management (resource allocation, budget tracking and coordination with vendors) Development with OKR (Objectives and Key Results) and KPI (Key Performance Indicators) Cybersecurity and Agile certifications". Also "Related Skills Adaptability, Collaboration, Communication, Consultative Communication, Executive Presence, General Risk Management, Influence, Problem Solving, Program Management, Project Management, Relationship Management, Stakeholder Engagement". Also "Anticipated Posting End Date: 2026-09-02". Also "Base Pay Range: $139,000/yr - $188,000/yr Actual base salary may vary based upon, but not limited to, relevant experience, time in role, base salary of internal peers, prior performance, business sector, and geographic location. In addition to base salary, the competitive compensation package may include, depending on the role, participation in an incentive program linked to performance (for example, annual discretionary incentive programs, non-annual sales incentive plans, or other non-annual incentive plans)."
Also "Benefits And Total Rewards" section: description about benefits.
Also "Company Overview" etc but we need to remove boilerplate like company overview? The instruction: Remove cookie/navigation/legal/EEO/equal-opportunity/scam-warning boilerplate, duplicated lines, and application instructions. Company overview may be considered not boilerplate? It's descriptive about TIAA. Might be considered substantive? The instruction says preserve ALL substantive information; do NOT invent or summarize away detail. However, we should only include sections when posting has real, specific content for it. The company overview is substantive but not one of the allowed headings? The allowed headings list includes About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule. Company overview is not in list, so we should not create a heading for it; we could possibly incorporate into About the role? But better to omit because not allowed heading. However, we could treat it as part of About the role? The instruction: "Use
for section headings (e.g. About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay, Schedule)." It says e.g., implying those are examples but we should use those headings for sections. It didn't say we cannot have other headings, but likely they want only those. Safer to stick to those. Thus we will include sections: About the role, Responsibilities, Requirements, Qualifications, Skills, Benefits, Pay. Schedule? Not present. No schedule info. So omit. Now we need to extract content for each. About the role: as above. Responsibilities: list as above. Requirements: includes educational requirements, work experience, physical requirements, career level. Also maybe "Required Skills" could be under Requirements or Skills. We'll separate: Requirements: educational, experience, physical, career level. Qualifications: maybe required skills? But we have both Required Skills and Preferred Skills. Could treat Required Skills as Qualifications, Preferred Skills as Skills. Or combine. Let's map: - Requirements: Educational Requirements (University Degree Preferred), Work Experience (5+ Years Required; 7+ Years Preferred), Physical Requirements (Sedentary Work), Career Level (9IC). Also maybe "Required Skills" could be considered qualifications. - Qualifications: Required Skills: 5+ years of experience in Program Delivery, 3+ years of Strategy Planning, 2+ years of experience in a Cybersecurity role. - Skills: Preferred Skills list: Experience in automation to simplify processes, Knowledge of AI concepts and how it ties in with Cybersecurity, Development of 6 quarter road map including 30/60/90 Day Plans, Resource and vendor management (resource allocation, budget tracking and coordination with vendors), Development with OKR (Objectives and Key Results) and KPI (Key Performance Indicators), Cybersecurity and Agile certifications. Also Related Skills list: Adaptability, Collaboration, Communication, Consultative Communication, Executive Presence, General Risk Management, Influence, Problem Solving, Program Management, Project Management, Relationship Management, Stakeholder Engagement. We could combine Preferred Skills and Related Skills into Skills section. Benefits: The "Benefits And Total Rewards" paragraph. Pay: Base Pay Range and incentive info. Schedule: none. Now we need to output HTML fragment with
headings and appropriate
or
- .
We must not include boilerplate like EEO, accessibility, drug policy, privacy notices, etc. Also remove duplicated lines (like Preferred Skills repeated). Also remove "Anticipated Posting End Date: 2026-09-02" maybe considered metadata; could be placed in a short
under About the role? But instruction: do NOT put Job ID / requisition numbers as headings — fold minor metadata into a short
or drop it. So we could include the posting end date as a short paragraph maybe under About the role or separate? Probably better to drop it as not essential. But we could include as a short
under About the role? It's minor metadata. I'd drop it. Also "Base Pay Range" is Pay section. Now craft HTML. We'll need to escape any special characters? Not needed. Let's write:
About the role
Cybersecurity Program Delivery Lead Global Cybersecurity and Fraud Management, Program Office is seeking an accomplished Program Manager to drive agile delivery of our strategic cyber and fraud program —a role that bridges technical innovation with enterprise cybersecurity strategy by coordinating cross-functional teams to deliver transformative capabilities. This position demands expert-level program management capability to lead the organization's largest and most complex initiatives, with a specific focus on applying that expertise to frontier AI strategic projects; given the high-visibility, high-complexity nature of this AI-focused mandate, we're looking for a leader who has already proven this level of capability, ideally with prior hands-on experience navigating the unique coordination challenges, vendor landscape, and cross-functional dependencies inherent to AI-related programs.
Responsibilities
- Program Coordination: Coordinate cross-functional activities across GCFM, CTO, CDAIO, and business teams. Maintain program schedules, track milestones, manage dependencies, risk management and ensure alignment with cybersecurity strategy and organizational objectives.
- Stakeholder Management: Translate technical cyber concepts for executive audiences and business priorities for technical teams. Prepare status/executive reports, facilitate steering committee meetings, and maintain transparency on progress, challenges, and resource needs.
- Roadmap: Work with internal GCFM stakeholders and develop 6 quarter roadmaps, including 30-60-90 day plans.
- Risk and Compliance: Ensure strategic initiatives comply with data governance, privacy requirements, and TIAA's Enterprise Responsible AI Policy.
- Resource and Vendor Management: Track budgets, allocate resources, and coordinate with external vendors.
- Metrics and Reporting: Define and track KPIs including threat detection accuracy, false positive rates, incident response times, and efficiency gains. Report regularly on metrics to demonstrate value and inform scaling decisions.
- Change Management: Support adoption through training coordination, process documentation, user feedback collection, and addressing resistance. Develop adoption plans that introduce new cyber controls while maintaining operational continuity.
- Continuous Improvement: Facilitate retrospectives after initiatives and milestones. Capture lessons learned, identify process improvements, share best practices, and build institutional AI delivery capability.
- Agile: Facilitate agile ceremonies including sprint planning, daily standups, retrospectives, and demos. Maintain and prioritize product backlogs, manage sprint execution, remove impediments, and foster collaboration within cross-functional agile teams delivering AI capabilities.
Requirements
- Educational Requirements: University degree preferred.
- Work Experience: 5+ years required; 7+ years preferred.
- Physical Requirements: Sedentary work.
- Career Level: 9IC.
Qualifications
- 5+ years of experience in Program Delivery.
- 3+ years of experience in Strategy Planning.
- 2+ years of experience in a Cybersecurity role.
Skills
- Experience in automation to simplify processes.
- Knowledge of AI concepts and how it ties in with Cybersecurity.
- Development of 6 quarter road map including
- .
We must not include boilerplate like EEO, accessibility, drug policy, privacy notices, etc. Also remove duplicated lines (like Preferred Skills repeated). Also remove "Anticipated Posting End Date: 2026-09-02" maybe considered metadata; could be placed in a short