Info Security Program Manager
Columbia University Irving Medical Center · New York, NY · 5 days ago
Information Technology$120k–$145k/yrFull-time
Position Summary
Reporting directly to the Chief Information Security Officer (CISO), the Information Security Program Manager is responsible for leading and coordinating a portfolio of enterprise cybersecurity programs and strategic initiatives that strengthen the organization's overall security posture. This role serves as a trusted advisor to the CISO, driving the planning, governance, execution, and continuous improvement of cybersecurity initiatives while ensuring alignment with organizational priorities, regulatory requirements, and industry best practices.
Responsibilities
- Coordinate the planning, execution, governance, and delivery of a portfolio of enterprise cybersecurity programs and strategic initiatives.
- Engage with the CISO to develop and execute the organization's cybersecurity roadmap, ensuring alignment with business objectives, regulatory requirements, and risk management priorities.
- Drive program governance, reporting, metrics, and executive dashboards to communicate program health, milestones, risks, dependencies, and overall security maturity.
- Coordinate cross-functional teams across CUIMC
- Manage program scope, budgets, schedules, resources, risks, issues, dependencies, and communications across multiple concurrent initiatives.
- Third-Party Risk Management
- Participate in cybersecurity governance activities, including steering committees, executive briefings, status reporting, and program reviews.
- Ensure cybersecurity initiatives comply with organizational policies and applicable regulatory and industry frameworks.
- Develop and maintain program documentation, including charters, roadmaps, project plans, risk registers, communication plans, executive presentations, and lessons learned.
- Collaborate with technology and business leaders to prioritize cybersecurity investments based on organizational risk.
- Identify opportunities to improve cybersecurity processes, operational efficiency, and program maturity.
- Serve as the Information Security representative for major enterprise transformation initiatives.
Minimum Qualifications
- Bachelor's degree or equivalent in education and experience, plus five years of related experience.
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, Business, or a related discipline, or equivalent combination of education and experience.
- Minimum of 3 years of progressively responsible experience managing enterprise cybersecurity programs, security projects, or information security initiatives.
- Demonstrated experience leading large, cross-functional cybersecurity initiatives from planning through implementation.
- Experience presenting program updates, risks, and strategic recommendations to executive leadership.
- Project Management Professional (PMP), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or comparable certification preferred.
- Experience within healthcare, higher education, or other highly regulated industries.
- Strong understanding of cybersecurity governance, risk management, and compliance programs.
- Experience implementing or managing enterprise cybersecurity technologies.
- Experience supporting enterprise risk assessments, security audits, and regulatory compliance initiatives.
- Working knowledge of cybersecurity frameworks and standards including:
- NIST Cybersecurity Framework (CSF)
- NIST 800-53
- NIST 800-171
- HITRUST
- HIPAA/HITECH
- ISO 27001
- CIS Controls
Equal Opportunity Employer / Disability / Veteran
Columbia University is committed to the hiring of qualified local residents.