Sr. Security Program Manager

    United States
    Full-Time
    Senior (7+ yrs)
    Operations & Project Management
    Posted on July 23, 2026

    Operational backbone of the department, ensuring the Information Security program runs efficiently and measurably by coordinating initiatives across all security functions, producing executive reporting, and managing the operational cadence so the VP, IT & Security can focus on strategy, customer security relationships, board engagement, and regulatory matters.

    This is not a hands-on engineering role, but the ideal candidate has built credibility working within an Information Security organization and understands how Security Operations, Vulnerability Management, Identity & Access Management, Cloud Security, Incident Response, and Security Engineering teams operate and partner together. Success in this role comes from translating operational security priorities into executive action, cross-functional execution, and measurable program outcomes.

    What You’ll Do (Essential Responsibilities)

    To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

    Program & Project Coordination

    • Own the security program roadmap at the execution level across all security functions

    • Track initiatives, timelines, and blockers without requiring VP involvement day-to-day

    • Coordinate cross-functional dependencies across Security Operations, Vulnerability Management, Security Engineering, Identity & Access Management, Cloud Security, IT, Legal, and Compliance.

    • Act with delegated authority from the VP on operational execution matters

    Metrics, Reporting & Dashboards

    • Build and maintain the security metrics framework — vulnerability SLA compliance, incident-response timelines, audit-finding closure, and training completion

    • Produce dashboards for board reporting, SEC disclosure prep, audit-committee updates, and customer security reviews

    • Translate raw tool and team data into a coherent program narrative for executive and external audiences

    Security Operations & Security Program Coordination

    • Partner with Security Operations, Engineering, and IT teams to coordinate security initiatives, remediation efforts, and operational follow-through across the security program.

    • Coordinate security team evidence collection for SOC 2, ISO 27001, PCI-DSS, and customer audits.

    • Serve as the security team's interface to the General Counsel's Compliance team during audits and regulatory activities.

    • Track audit findings, operational remediation activities, and follow issues through closure to improve the organization's overall security posture.

    Security Governance & Operational Enablement

    • Own the security policy lifecycle: annual review, version control, approval, accessibility

    • Own the security awareness and training program including phishing simulations

    • Manage security-tool contracts, renewals, license utilization, and MSSP relationship logistics

    This job description reflects management’s assignment of essential functions; and nothing in this herein restricts management’s right to assign or reassign duties and responsibilities to this job at any time.

    Managerial Responsibilities

    • Non-Manager: No oversight or accountability for others, an individual contributor.

    What You Need (Education/Licenses/Certifications, Experience, Knowledge, Technical Skills and Abilities)
  1. 5–8+ years of experience working within an Information Security or Cybersecurity organization, with increasing responsibility for leading security programs, coordinating cross-functional initiatives, and driving operational execution.
  2. Experience partnering closely with technical security teams such as Security Operations, Vulnerability Management, Cloud Security, Identity & Access Management, Security Engineering, or Incident Response.
  3. Experience working in close partnership with Engineering and Security teams to drive remediation efforts, operational improvements, and security program execution.
  4. Ability to translate operational security priorities, risks, and technical initiatives into executive reporting, program execution, and actionable plans for cross-functional stakeholders.
  5. Solid understanding of operational security concepts including vulnerability management, incident response, cloud security, identity and access management, and security monitoring.
  6. Working familiarity with security frameworks and standards such as NIST CSF, SOC 2, ISO 27001, and PCI-DSS, with the ability to apply them in support of operational security programs.
  7. Strong written and verbal communication skills with the ability to communicate effectively with technical teams, executives, and cross-functional stakeholders.
  8. Experience coordinating security audits by partnering with technical teams on evidence collection, remediation tracking, and driving findings through closure.
  9. What Would be Nice (Preferred Skills & Experience)
  10. Experience in financial services, fintech, SaaS, or other highly regulated industries.
  11. Experience supporting or coordinating operational security programs within a mature Information Security organization.
  12. Familiarity with modern security and regulatory frameworks such as GDPR, NIS2, or DORA.
  13. Professional certifications such as CISSP, CISM, or PMP.
  14. Experience supporting executive cybersecurity reporting, SEC cybersecurity disclosures, or Audit Committee reporting.
  15. Experience partnering with Managed Security Service Providers (MSSPs) or other security technology vendors.
  16. Success Metrics -First Year
  17. Roadmap documented, socialized, and tracked within 60 days.
  18. Security metrics dashboard established and reported monthly within 90 days.
  19. Build trusted partnerships across Security Operations, Engineering, IT, and other cross-functional teams while improving visibility into security program execution.
  20. Zero missed audit evidence deadlines during the first audit cycle.
  21. Improve visibility into operational security initiatives by ensuring remediation efforts, program milestones, and key security metrics are consistently tracked and communicated to leadership.
  22. VP time spent on day-to-day operational coordination materially reduced, enabling greater focus on strategic initiatives, customer engagement, and executive priorities.
  23. Company:  Mitek Systems

    Develops advanced identity verification technologies and global platform for digital access and fraud prevention.
    Remote-First Company
    501-1000 employees
    Software & IT Services
    HQ: United States