08 Aug
|
Purview Services
|
Noida
08 Aug
Purview Services
Noida
Role: Programme Manager
Exp: 8-12 Years
Location: Hyderabad/ Pune
Job Description:
Role purpose
Lead one or more cyber/security programmes end-to-end, translating security strategy and risk outcomes into
deliverable roadmaps. Youll coordinate engineering, architecture, operations and risk stakeholders to deliver secure
by-design capabilities at pace, with clear governance and measurable risk reduction.
Key responsibilities
Programme leadership and delivery
- Own programme scope, outcomes, plan, budget, RAID, dependencies and delivery cadence.
- Build and run integrated delivery plans across multiple workstreams (product, engineering, security,
operations).
- Drive delivery governance: steering forums, status reporting, milestone tracking and decision logs.
- Manage third parties/vendors where applicable (contracts, deliverables, performance).
Cyber and risk outcomes
- Translate cyber risk requirements into actionable epics/features for engineering teams.
- Ensure alignment to security controls (e.g., IAM, logging/monitoring, vulnerability management, encryption,
secure SDLC).
- Track risk reduction and control effectiveness using agreed metrics (KRIs/KPIs).
- Support audits, regulatory responses and evidence collection with clear traceability.
Engineering partnership (core differentiator)
- Work closely with software engineers, SRE/DevOps and architects to shape feasible delivery approaches.
- Drive adoption of secure engineering practices: threat modelling, SAST/DAST, dependency scanning,
secrets management, CI/CD hardening.
- Manage technical debt and remediation backlogs (e.g., CVEs, end-of-life technology, misconfigurations) with
prioritisation based on risk and impact.
- Coordinate release planning and change management to minimise service disruption.
Stakeholder management
- Engage senior stakeholders across Technology, CISO/Security, Risk/Compliance and business owners.
- Communicate complex technical topics in plain language, with clear options and trade-offs.
- Build a “one team” culture across functions and geographies.
Financials and commercial
- Own programme financials: forecasting, benefits tracking, resource planning and cost control.
- Support business cases and investment proposals tied to risk reduction and resilience outcomes.
Required experience
- Proven programme management experience delivering cyber/security or technology risk programmes.
- Strong software engineering/SDLC background (hands-on development, engineering lead, or delivery in
engineering-heavy environments).
- Experience delivering across Agile/DevOps at scale (multiple squads/streams).
- Track record managing complex dependencies, legacy constraints and remediation programmes.
- Experience working with security teams on controls,
assurance and audit evidence.
Technical knowledge (expected)
- Secure SDLC concepts and common tooling (CI/CD, code scanning, artefact repositories).
- Cloud and platform fundamentals (e.g., AWS/Azure/GCP concepts), containers, APIs, microservices.
- Identity and access management basics (SSO, MFA, PAM), secrets management.
- Vulnerability management lifecycle (discovery triage remediation verification).
- Logging/monitoring and incident response concepts.
- Familiarity with common frameworks/standards (e.g., NIST CSF, ISO 27001, OWASP Top 10).
Skills and behaviours
- Strong delivery discipline: planning, governance and execution under pressure.
- Excellent written and verbal communication; confident presenting to senior forums.
- Pragmatic, outcome-focused, able to balance risk, cost and delivery timelines.
- Team-oriented leadership across diverse teams and cultures.
Qualifications (nice to have)
- Programme/project certifications: MSP, PRINCE2, PMP, Agile (SAFe/PSM).
- Security certifications: CISSP, CISM, CCSP (or equivalent experience).
Example deliverables you might own
- Enterprise vulnerability remediation programme (CVE SLAs, end-of-life technology removal).
- CI/CD and secure engineering uplift (SAST/DAST, SBOM, signing, pipeline controls).
- IAM/PAM rollout and privileged access reduction.
- Cloud security baseline implementation and control assurance.
- Centralised logging/SIEM onboarding programme and detection coverage uplift.
📌 Program Manager (Noida)
🏢 Purview Services
📍 Noida