City, Urban, Building, Campus, Downtown, Metropolis, College, Person, Neighborhood, Grass

Info Security Program Manager

CUIMC IT

Info Security Program Manager

  • 559336
  • Columbia University Medical Center
  • CUIMC IT
  • Full Time
  • Opening on: Aug 26 2026
  • Grade 106
View favorites
  • Job Type: Officer of Administration
  • Bargaining Unit:
  • Regular/Temporary: Regular
  • End Date if Temporary:
  • Hours Per Week: 35
  • Standard Work Schedule:
  • Building:
  • Salary Range: $120,000 - $145,000
The salary of the finalist selected for this role will be set based on a variety of factors, including but not limited to departmental budgets, qualifications, experience, education, licenses, specialty, and training. The above hiring range represents the University's good faith and reasonable estimate of the range of possible compensation at the time of posting.
 

Position Summary

Reporting directly to the Chief Information Security Officer (CISO), the Information Security Program Manager is responsible for leading and coordinating a portfolio of enterprise cybersecurity programs and strategic initiatives that strengthen the organization's overall security posture. This role serves as a trusted advisor to the CISO, driving the planning, governance, execution, and continuous improvement of cybersecurity initiatives while ensuring alignment with organizational priorities, regulatory requirements, and industry best practices.

The successful candidate will possess a strong background in cybersecurity program management, exceptional leadership and communication skills, and demonstrated experience managing complex cross-functional security initiatives within a large healthcare, academic, or similarly regulated environment.


Responsibilities

  • Coordinate the planning, execution, governance, and delivery of a portfolio of enterprise cybersecurity programs and strategic initiatives.
  • Engage with the CISO to develop and execute the organization's cybersecurity roadmap, ensuring alignment with business objectives, regulatory requirements, and risk management priorities.
  • Drive program governance, reporting, metrics, and executive dashboards to communicate program health, milestones, risks, dependencies, and overall security maturity.
  • Coordinate cross-functional teams across CUIMC
  • Manage program scope, budgets, schedules, resources, risks, issues, dependencies, and communications across multiple concurrent initiatives.
    o Third-Party Risk Management
  • Participate in cybersecurity governance activities, including steering committees, executive briefings, status reporting, and program reviews.
  • Ensure cybersecurity initiatives comply with organizational policies and applicable regulatory and industry frameworks.
  • Develop and maintain program documentation, including charters, roadmaps, project plans, risk registers, communication plans, executive presentations, and lessons learned.
  • Collaborate with technology and business leaders to prioritize cybersecurity investments based on organizational risk.
  • Identify opportunities to improve cybersecurity processes, operational efficiency, and program maturity.
  • Serve as the Information Security representative for major enterprise transformation initiatives.

Essential Functions:

Cybersecurity Program Leadership and Delivery – 60%

  • Implement strategic cybersecurity programs from initiation through adoption while ensuring delivery within scope, schedule, budget, and quality expectations.

Cybersecurity Governance and Stakeholder Management – 30%

  • Coordinate governance activities, executive reporting, risk management, and cross-functional collaboration to support enterprise cybersecurity objectives.

Continuous Improvement and Other Duties – 10%

  • Drive continuous improvement of cybersecurity program management processes, reporting, and operational maturity while performing other duties as assigned.
  • Perform other related duties and responsibilities as assigned/requested.

Minimum Qualifications

  • Bachelor's degree or equivalent in education and experience, plus five years of related experience. 

Preferred Qualifications

  • Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, Business, or a related discipline, or equivalent combination of education and experience.
  • Minimum of 3 years of progressively responsible experience managing enterprise cybersecurity programs, security projects, or information security initiatives.
  • Demonstrated experience leading large, cross-functional cybersecurity initiatives from planning through implementation.
  • Experience presenting program updates, risks, and strategic recommendations to executive leadership.
  • Project Management Professional (PMP), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or comparable certification preferred.
  • Experience within healthcare, higher education, or other highly regulated industries.
  • Strong understanding of cybersecurity governance, risk management, and compliance programs.
  • Experience implementing or managing enterprise cybersecurity technologies
  • Experience supporting enterprise risk assessments, security audits, and regulatory compliance initiatives.
  • Working knowledge of cybersecurity frameworks and standards including:
    o NIST Cybersecurity Framework (CSF)
    o NIST 800-53
    o NIST 800-171
    o HITRUST
    o HIPAA/HITECH
    o ISO 27001
    o CIS Controls

Required Competencies

  • Strong cybersecurity program and portfolio management skills.
  • Demonstrated leadership managing multiple concurrent enterprise initiatives.
  • Excellent stakeholder management and executive communication skills.
  • Ability to influence without direct authority across multidisciplinary teams.
  • Strong analytical, organizational, and problem-solving capabilities.
  • Experience developing executive dashboards, KPIs, and program metrics.
  • Ability to identify and proactively mitigate program risks and dependencies.
  • Excellent written communication skills, including executive presentations, governance documentation, and strategic planning materials.
  • Knowledge of Agile, Waterfall, and hybrid delivery methodologies.

Equal Opportunity Employer / Disability / Veteran

Columbia University is committed to the hiring of qualified local residents.

Similar Jobs

We're still syncing jobs similar to this posting. We invite you to Search All Jobs to learn more about our other open roles.