Live opening · Posted 2 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
I’m helping Avance Consulting Group find a top candidate to join their team flexible for the role of Senior Program Manager – Global Information Security.
You will drive global security strategy by leading complex programs for a premier financial firm.
Compensation:
USD 80 - 110/hour
Location:
Remote (for United States and Canada residents)
Mission of Avance Consulting Group:
"To turn business challenges into growth opportunities by delivering practical, experience-driven solutions that accelerate our clients’ success."
What makes you a strong candidate:
You have +7 years experience in Program management.
You are proficient in Information security, Agile methodologies.
English - Fully fluent.
Responsibilities and more:
Job Description: Senior Program Manager – Global Information Security
Position Overview
Avancé Consulting Group is seeking an adaptable, high-impact Senior Program Manager to embed directly with Global Information Security (GIS) leadership at a premier global investment management organization.
This role serves as a strategic execution thought partner and delivery lead to a senior pillar head within the Information Security portfolio, bridging high-level security strategies with tactical execution across Global Technology and enterprise business units. Rather than managing a strictly predefined, static scope, you will operate with significant autonomy, partnering 1-on-1 with security domain leaders to unpack complex mandates, establish program structures, prioritize critical initiatives, and drive execution across distributed enterprise teams.
Four positions are currently open across four distinct Information Security functional pillars. Candidates will be aligned to one of these specific domains based on relevant technical background and delivery strengths.
________________________________________
Role Details
• Engagement Type: Contract (12-Month Engagement with high likelihood to extend)
• Target Start Date: October 15, 2026 (Immediate hiring cadence)
• Work Arrangement: Remote (East Coast / Eastern Time alignment preferred; Charlotte, NC hub)
• Operating Model: Embedded within Global Information Security (GIS) leadership under the governance and delivery frameworks of the central Enterprise Change Office (ECO).
________________________________________
Core Responsibilities
• Strategic Thought Partnership: Serve as the dedicated delivery partner to a Security Pillar Lead, translating high-level imperatives, audit remediation goals, and emerging security demands (including AI-driven governance and operational resilience) into structured, actionable program roadmaps.
• Program Delivery & Execution: Establish milestones, drive accountability, track complex cross-functional interdependencies, and manage risks across multi-disciplinary global technology teams without requiring rigid top-down project parameters.
• Cross-Functional Orchestration: Facilitate seamless alignment between Information Security pillar leads, application engineering teams, enterprise architecture, infrastructure operations, and central change management governance.
• Scope Definition & Governance: Dissect broad, ambiguous technical mandates into discrete workstreams, project plans, and measurable operational outcomes.
• Executive Visibility & Reporting: Deliver clear visibility into portfolio delivery status, resource bottlenecks, critical path milestones, and key security deliverables for executive leadership.
________________________________________
Target Pillars & Functional Scope
Candidates will be deployed into one of the following four Information Security pillars:
1. Cybersecurity Incident Management
• Domain Focus: Cyber incident preparedness, response orchestration, crisis escalation paths, and post-incident remediation.
• Core Initiatives:
o Modernize enterprise incident response playbooks and cross-functional crisis communication workflows.
o Mature tabletop exercises and cyber simulation drills across global technology and executive leadership.
o Lead post-mortem tracking, root cause analysis (RCA), and continuous control validation workstreams.
• Specialized Acumen: Working familiarity with CSIRT/SOC operating cadences, threat escalation frameworks, and NIST Incident Handling standards (NIST SP 800-61); ability to coordinate cross-functional teams (Legal, Compliance, Communications, SecOps) under time-sensitive conditions.
2. Application Security (AppSec)
• Domain Focus: Embedding proactive security governance directly into the modern software development lifecycle (SDLC) across global engineering teams.
• Core Initiatives:
o Scale developer security enablement, threat modeling workflows, and secure coding standards across product teams.
o Operationalize centralized penetration testing scheduling, vulnerability prioritization, and third-party vendor testing engagements.
o Drive the rollout and engineering adoption of SAST, DAST, SCA, and container security scanning tooling across enterprise CI/CD pipelines.
• Specialized Acumen: Deep familiarity with DevSecOps practices, secure SDLC integration, and application vulnerability remediation cadences across distributed software engineering groups.
3. Identity & Access Security (IAM / Governance)
• Domain Focus: Enterprise identity governance, privileged access management (PAM), and machine/non-human identity controls.
• Core Initiatives:
o Lead program execution around non-human identity lifecycle management (service accounts, API keys, tokens, certificate management).
o Rationalize and execute role-based access control (RBAC) cleanups, least-privilege enforcement, and privileged access workflows.
o Modernize identity governance and administration (IGA) integration across hybrid cloud and enterprise environments.
• Specialized Acumen: Working knowledge of modern IAM architectures (e.g., SailPoint, CyberArk, Okta, Active Directory/Entra ID) and access compliance audits in financial institutions.
4. Security Tooling & Infrastructure Modernization
• Domain Focus: Delivery governance across internal and vendor-provided security tools protecting enterprise infrastructure, endpoints, and cloud environments.
• Core Initiatives:
o Plan and coordinate enterprise-wide security tooling migrations, upgrades, agent rollouts, and rationalizations.
o Track vendor integration milestones, proof-of-concept (POC) evaluations, and enterprise deployment across thousands of endpoints and server instances.
o Partner with enterprise infrastructure and cloud engineering to ensure monitoring coverage and tool telemetry integration with SIEM/data lakes.
• Specialized Acumen: Technical breadth across endpoint protection (EDR/XDR), network security tooling, vulnerability scanners, and telemetry pipelines; strong vendor delivery management.
________________________________________
Qualifications & Key Competencies
• Enterprise Program Management: 7+ years of experience leading complex, large-scale technology programs or portfolios.
• Information Security Acumen: Demonstrated experience supporting cybersecurity, InfoSec, or technology risk domains aligned with at least one of the four core pillars above.
• Consultative Problem Solver: Proven ability to thrive in ambiguous, fast-moving environments; operates effectively as a hands-on strategic partner rather than a rigid checklist-driven coordinator.
• Communication & Influence: Exceptional interpersonal and stakeholder engagement skills, capable of influencing senior technical leaders, engineering directors, and cross-functional business partners.
• Delivery Frameworks: Deep experience with Agile, hybrid delivery frameworks, and Enterprise Change Office / PMO standards.\
• Financial Services & Investment Management (Nice to Have):
o Prior background within Financial Services, with a strong preference for Investment Management (buy-side / asset management) or wealth management environments.
o Familiarity with the operational, audit, compliance, and regulatory landscapes typical of global financial institutions.
Your potential leaders:
Manuel Ramirez - Founder
Work arrangement
Yes
More openings worth a look
Recently tracked roles with full details and direct application links.