Onit is seeking a Technical Program Manager to lead the delivery of world-class security and compliance solutions across our SaaS platforms. This role will collaborate closely with Security & Compliance, Infrastructure, and Product teams to drive initiatives that ensure our systems and services meet the highest standards of security and regulatory compliance
Key Responsibilities-
Project Leadership: Drive cross-functional initiatives to deliver security and compliance solutions, including resource planning, timeline management, and coordination with external vendors.
-
Remediation Tracking: Monitor and manage remediation efforts across applications and infrastructure for issues identified via scans, assessments, and customer feedback.
-
Managed Security and Compliance BAU activities: Manage and track the execution of key security and compliance such as access reviews, WAF reviews, and other quarterly and yearly BAU activities required by our security and compliance certifications and customer contracts.
-
Security Champion Program: Facilitate the rollout and adoption of the program across teams to level up security knowledge for security champions, increase security visibility with tooling, and other key practices.
-
Vanta Adoption and Implementation: Oversee the continued adoption and integration of Vanta for automated compliance monitoring.
-
Vendor Management: Support selection, onboarding, and coordination of vendors for penetration testing, audits, and other security services.
-
Security Reviews: Facilitate and participate in technical discussions and evaluate system designs for security strengths and weaknesses.
-
Product Ownership: Act as product owner for security and compliance initiatives. This includes creating user stories, prioritizing work, and guiding teams through grooming and delivery.
-
Global Collaboration: Work with teams across India, the U.S., and other regions to define, design, and deliver secure SaaS solutions.
-
Process Improvements: Assist with process improvements with incident response, training, runbook definition, and other key areas of the security and compliance program.
-
Security and Compliance Reporting: Maintain, track and report key performance indicators/metrics for various activities in security and compliance.
-
Documentation and Training: Assist with documenting key practices within the security and compliance function to improve visibility and adoption
-
10+ years in technical project management or similar leadership roles.
-
5+ years in security and compliance domains.
-
Strong technical background in the cybersecurity domain which includes experience with security tooling, vulnerability management, 3rd party penetration testing, incident response, thread detection, etc.
-
Proven track record executing security and compliance projects for Enterprise SaaS solutions.
-
Extensive experience managing the security of cloud-based applications (AWS preferred)
-
Ability to navigate trade-offs and prioritize across multiple teams.
-
Proficiency in agile methodologies and tools (e.g., Jira, Scrum, Kanban).
-
Experience with security and compliance frameworks such as SOC2, NIST, and ISO 27001.
-
Strong communication, problem-solving, and collaboration skills.
-
Experience with EDR, CSPM, and SEIM security tooling
-
Relevant certifications (CISSP, CCSP, CISM, AWS Security Specialty) are a plus
-
Regulatory, compliance, or legal experience is a plus
-
Experience with containerized applications is a plus
hjdhmUSf5U