Security Compliance Project Manager
Prowess Consulting · United States · 1 mo ago
RemoteRemoteProject Management$95k/yrFull-time
The Role
Drive end to end execution of security assessments that include:
- Create assessment questionnaires
- Conduct kickoffs, review assessment responses, and identify risks/control gaps from a risk management perspective
- Perform risk scoring exercise and maintain risks in the risk register
- Track implementation (and adherence) of security requirements across engineering groups/teams
- Collaborate with partner teams to build continuous monitoring capabilities/reports for security requirements
- Validate compliance to security requirements and drive compliance sign off process for upcoming releases
- Collaborate with partner teams on security scope and finalize implementation requirements
- Socialize risks/control gaps with service owners
- Support certification and audit preparation efforts for internal and external regulatory requirements
- Drive execution of Security Compliance frameworks (NIST, SDLC, etc.)
- Partner with Windows engineering teams to review feature designs and system changes (e.g., identity, credential storage, telemetry/logging, update mechanisms) for regulatory impact and required compliance controls
- Translate Cyber EO / CRA requirements into implementable control requirements, test procedures, and release gates; define clear evidence expectations (e.g., design artifacts, configurations, build/release attestations, vulnerability handling records)
- Validate compliance using technical evidence and telemetry (e.g., policy/config exports, audit logs, vulnerability scan results, update/patch metrics) and drive remediation plans with engineering owners
Qualifications
- 5+ years of Program Management experience necessary
- Strong interpersonal and written communication skills
- Demonstrated ability to own and drive programs and initiatives by working through ambiguity
- Familiarity with cybersecurity, risk management and audit best practices desirable
- Strong understanding of security and supply chain concepts, standards, and control frameworks
- Strong understanding of regulatory frameworks and the ability to interpret requirements into actionable workstreams
- Good track record of working collaboratively and effectively with senior leaders and teams across organizational boundaries
- Experience influencing others without authority
- Experience building PowerBI dashboards or producing dashboard specifications
- Experience using tools to manage compliance and evidence (e.g., control tracking, audit readiness, risk registers), plus engineering workflow tools (ADO) and security/compliance signals (e.g., vulnerability scanning findings, SBOM outputs) are desired
- Must have stellar organizational skills and be able to work well with multiple technical groups and stakeholders in multiple areas
Technical Skills (Required)
- Strong understanding of enterprise/on-prem Windows security fundamentals, such as Active Directory, authentication/authorization concepts, Group Policy, credential hygiene, hardening baselines, and security logging/auditing
- Experience operating vulnerability management and coordinated disclosure processes, including intake/triage, severity scoring (e.g., CVSS), remediation SLAs, exception handling, and reporting/notification obligations
- Software supply chain & secure development knowledge (aligned to NIST SSDF concepts), including build integrity, dependency management, SBOMs (SPDX/CycloneDX), code signing, and release/change control
- Ability to work with compliance tooling and evidence workflows (GRC/control libraries, automated evidence collection, audit trails) and integrate with engineering systems (ADO/Jira, CI/CD, ticketing)
- Data/analytics skills to build continuous monitoring and compliance reporting (Power BI or similar; ability to work with log/metric sources and perform basic querying to validate control health)
Benefits
The offered pay range for this position is $95,000 - $105,000 per year depending on experience.