• Location: Madison, Wisconsin
  • Remote: Hybrid
  • Type: Contract To Hire
  • Job #6367

Carex is partnering with a Insurance industry partner to hire a Cybersecurity Program Manager to turn cybersecurity assessment findings into an executable, measurable, and governed transformation program. This role will build the roadmap, metrics, governance, and operating discipline required to manage a complex, multi-workstream cybersecurity transformation within a federally regulated healthcare environment.

The Cybersecurity Program Manager will provide dedicated program management capacity to Enterprise Security leadership, translating identified security gaps into prioritized remediation efforts and ensuring initiatives are sequenced, owned, measured, and aligned with regulatory obligations. The environment operates under federal and healthcare security requirements, including FISMA, NIST SP 800-53, HIPAA, and independent information security program evaluations conducted under Section 912 of the Medicare Prescription Drug, Improvement, and Modernization Act.

Success in this role means establishing a transformation program with a sustainable operating cadence, producing executive and board-grade reporting, improving visibility into maturity and risk reduction, and ultimately transitioning the established program to an internal Project Management Office.

What You’ll Do

  • Own program management for the cybersecurity transformation portfolio, including planning, sequencing, dependency management, milestone tracking, and critical path management.
  • Build and maintain a multi-year cybersecurity transformation roadmap, integrated program plan, and RAID log.
  • Convert identified cybersecurity assessment gaps into a single, prioritized, owned, and dependency-mapped remediation register.
  • Normalize and validate security gaps with named owners and map remediation activities to relevant NIST Cybersecurity Framework, NIST SP 800-53, and applicable Section 912 control areas.
  • Design, build, and operate a cybersecurity metrics and reporting framework that measures maturity improvement and risk reduction using available organizational data.
  • Produce executive, leadership, and Audit Committee reporting materials, including board-grade cybersecurity transformation reporting.
  • Establish and operate lightweight program governance, including forums, agendas, decision capture, accountability mechanisms, and follow-through without creating unnecessary administrative burden.
  • Coordinate transformation activities across Enterprise Cyber Resilience functions spanning cyber risk and assurance, business enablement, compliance, trust and architecture, and threat management.
  • Align the cybersecurity transformation roadmap with the annual Section 912 audit cycle so remediation activities can be efficiently planned, executed, and evidenced.
  • Build a resource and capacity model that supports evidence-based staffing and budget decisions.
  • Establish a program charter and sustainable governance model that enables clear ownership, decision-making, and execution.
  • Develop and manage a wave-sequenced, multi-year transformation plan that reflects priorities, dependencies, capacity constraints, regulatory obligations, and risk.
  • Ensure metrics and reporting operate through repeatable collection and reporting cycles using live data.
  • Return meaningful capacity to Enterprise Security leadership by independently driving program operations, coordination, reporting, and follow-through.
  • Maintain appropriate separation between transformation program management and operational cybersecurity responsibilities, including audit ownership, security architecture and engineering decisions, incident response, security tool administration, vendor operations, and control approval responsibilities.
  • Prepare and execute comprehensive knowledge transfer and transition of the established transformation program to the internal Project Management Office.

What You’ll Bring

  • Minimum of 8 years of program or project management experience, including at least 5 years specifically managing cybersecurity programs.
  • Demonstrated ownership of at least one cybersecurity transformation or security maturity improvement program from assessment findings and roadmap development through execution.
  • Working fluency in the NIST Cybersecurity Framework and NIST SP 800-53, including the ability to independently interpret security control findings.
  • Experience operating within FISMA, HIPAA, federal healthcare, or similarly regulated security environments.
  • Experience building cybersecurity metrics, Key Risk Indicator (KRI) frameworks, and related measurement programs and operating them through repeated reporting cycles.
  • Demonstrated experience producing cybersecurity or transformation reporting consumed by executive committees, Audit Committees, boards, or comparable senior leadership groups.
  • Experience delivering complex programs in regulated environments subject to external audits and assessments.
  • Strong program governance, risk management, dependency orchestration, critical path management, and change control capabilities.
  • Ability to translate cybersecurity assessment findings into structured, prioritized, measurable, and actionable transformation initiatives.
  • Excellent communication, stakeholder management, and negotiation skills across technical, business, executive, and compliance audiences.
  • Experience leading complex transformation initiatives through ambiguity and competing priorities.
  • Experience transitioning an established program to an internal PMO or similar delivery organization.
  • Direct experience supporting a Medicare Administrative Contractor, federal healthcare contractor, or another FISMA-regulated organization is preferred.
  • Familiarity with CMS information security requirements and the MMA Section 912 evaluation process is preferred.
  • Familiarity with CMMC is preferred.
  • CISSP, CISM, or CRISC certification is preferred.
  • Proficiency across multiple execution methodologies, including Agile, with familiarity with scaled delivery frameworks preferred.
  • PMP, CSM, SAFe, LeSS, PgMP, and/or PfMP certification is preferred.

Carex Consulting Group is an equal opportunity employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender identity, or Veteran status.

#LI-WR1

Attach a Resume file. Accepted file types are DOC, DOCX, PDF, HTML, and TXT.

We are uploading your application. It may take a few moments to read your resume. Please wait!