Information Security Program Manager

Mainstay Technologies, Inc.Manchester, NH
Hybrid

About The Position

The Information Security Program Manager (ISPM) serves as a strategic security advisor and primary governance lead for assigned clients. The ISPM is responsible for developing, managing, and maturing client information security programs with a strong emphasis on Cybersecurity Maturity Model Certification (CMMC), NIST compliance, risk management, governance, policy development, and assessment readiness. This position works closely with clients, technical teams, Security Operations personnel, external assessors, and executive leadership to ensure security programs align with business objectives, compliance obligations, and industry best practices. The ISPM serves as a trusted advisor to client leadership and is accountable for the successful execution of security governance activities, compliance initiatives, risk management processes, and security program outcomes.

Requirements

  • Experience supporting CMMC readiness initiatives.
  • Experience assisting clients through audits or certification assessments.
  • Experience in consulting or managed services environments.
  • Experience presenting to executive leadership teams.
  • Creative problem-solving skills with the ability to take multiple components and pull them together into recommendations.
  • Strong decision-making skills and comfortable in situations where there is no “right” answer.
  • Strong organization and project management skills.
  • Business acumen- understanding business process, data flows, and system application use in a variety of business settings.
  • Technical aptitude- the ability to understand technical concepts, tools, and the IT landscape.
  • Strong written and oral communication skills with the ability to coordinate and run successful meetings.
  • Life-long learner with a growth mindset that enjoys the pursuit of knowledge and is eager to stay updated in security policies and skill.
  • Prolonged periods of sitting at a desk and working on a computer.
  • Must be able to lift 15 pounds at times.
  • Travel between offices and to client sites.
  • Applicants must live within driving distance of our clients, offices, and team events to support client relationships, onboarding, and ongoing collaboration.

Nice To Haves

  • CISA
  • CISM
  • CMMC Certified Professional (CCP)
  • CISSP

Responsibilities

  • Lead client governance meetings and security program reviews.
  • Develop and manage client security roadmaps and strategic initiatives.
  • Provide security guidance to executive leadership and key stakeholders.
  • Track program goals, projects, milestones, and security initiatives.
  • Coordinate activities between clients, technical teams, security operations, and third-party partners.
  • Present security posture, compliance status, risks, and recommendations to client leadership.
  • Drive continuous improvement of client security programs.
  • Serve as a subject matter expert on CMMC, NIST 800-171, HIPAA, and related security frameworks.
  • Conduct compliance assessments, gap analyses, and readiness reviews.
  • Interpret security, regulatory, and contractual requirements.
  • Develop remediation plans to address compliance gaps.
  • Guide clients through CMMC assessment preparation and readiness activities.
  • Coordinate evidence collection, assessment planning, and audit support.
  • Stay current on evolving compliance requirements and industry best practices.
  • Provide compliance recommendations and implementation guidance.
  • Conduct security risk assessments and program reviews.
  • Maintain oversight of client risk registers and remediation activities.
  • Identify, evaluate, and prioritize business, operational, and security risks.
  • Develop risk treatment and mitigation recommendations.
  • Facilitate risk review discussions and risk acceptance decisions.
  • Provide strategic recommendations to improve security maturity and resilience.
  • Support vulnerability, application, vendor, and operational risk review activities.
  • Develop and maintain System Security Plans (SSP), Written Information Security Programs (WISP), Plans of Action & Milestones (POA&M), Policies, Procedures, and Standards, and Governance and assessment documentation.
  • Align documentation with implemented controls and compliance requirements.
  • Maintain traceability between requirements, risks, controls, findings, and remediation activities.
  • Review and update documentation based on regulatory, business, and technology changes.
  • Support standardization and continuous improvement of security program documentation.
  • Lead security awareness and compliance training initiatives.
  • Facilitate tabletop exercises and security program testing.
  • Oversee incident response planning and program readiness.
  • Participate in significant security incidents as an advisor and coordinator.
  • Conduct post-incident reviews and lessons-learned activities.
  • Ensure incidents, findings, and corrective actions are incorporated into risk management and governance processes.
  • Support application security reviews, vendor risk reviews, and continuous monitoring initiatives.
  • Promote security best practices across client organizations.

Benefits

  • A flexible and fun work environment with events, lunch+ learns, ping pong, snacks, games, and books
  • 3 weeks of PTO (4 weeks after 2 years) per year
  • A 2-week sabbatical at 5 years and a 5-week sabbatical at 10 years
  • Health, Dental, and Vision Insurance
  • Disability Insurance
  • Group and Supplemental Life Insurance
  • Paid Family Leave
  • 401(k) with 3% match
  • ESOP!
  • Team Profit Sharing
  • Training program (including paid certifications, tuition reimbursement, and bonuses on achieving certs)
  • Paid Volunteer Time Off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service