Sr. InfoSec Program Manager
Mitek Systems · United States · 1 mo ago
RemoteRemoteProject ManagementFull-time
What You’ll Do (Essential Responsibilities)
- Own the security program roadmap at the execution level across all security functions
- Track initiatives, timelines, and blockers without requiring VP involvement day-to-day
- Manage cross-functional dependencies with Engineering, IT, Legal, and Compliance
- Build and maintain the security metrics framework — vulnerability SLA compliance, incident-response timelines, audit-finding closure, and training completion
- Produce dashboards for board reporting, SEC disclosure prep, audit-committee updates, and customer security reviews
- Translate raw tool and team data into a coherent program narrative for executive and external audiences
- Audit & Compliance Coordination
- Coordinate security-team evidence collection for SOC 2, ISO 27001, PCI-DSS, and customer audits
- Serve as the security team's interface to the General Counsel's Compliance team
- Maintain audit-readiness documentation year-round and track findings to closure
- Policy, Awareness & Vendor Administration
- Own the security policy lifecycle — annual review, version control, approval, accessibility
- Own the security awareness and training program including phishing simulations
- Manage security-tool contracts, renewals, license utilization, and MSSP relationship logistics
What You Need (Education/Licenses/Certifications, Experience, Knowledge, Technical Skills and Abilities)
- Knowledge, skills and abilities typically gained through 5-8 years in security or IT program management, or a security operations coordination role
- Familiarity with NIST CSF, SOC 2, ISO 27001, and PCI-DSS
- Cross-functional program management in a regulated or compliance-driven environment
- Strong written communication for executive reports and board materials
- Experience coordinating audits including evidence collection and finding tracking
What Would Be Nice (Preferred Skills & Experience)
- Financial services, fintech, or SaaS serving regulated industries
- Familiarity with GDPR, NIS2, or DORA
- MPP, CISM, or CISSP
- SEC cybersecurity disclosure or public-company audit-committee reporting
- MSSP relationship management