Security Program Manager

FujifilmValhalla, NY

About The Position

The Security Program Manager is responsible for leading and governing customer‑facing security programs for externally delivered and managed services, with an initial focus on Managed Services contracts. This role serves as the single accountable owner for customer security relationships, ensuring that contractual, regulatory, and risk management requirements are met through effective coordination of internal teams and third‑party service providers. The SPM balances external customer leadership with internal security coordination, providing oversight of Security Operations services delivered by a Managed Security Service Provider while retaining accountability for security outcomes, risk posture, and customer trust. Over time, this role is expected to expand to manage security programs across all enterprise customer relationships. This position emphasizes program ownership, governance, communication, and execution, rather than hands‑on security operations.

Requirements

  • Strong knowledge of information security governance, risk management, and compliance in customer‑facing or regulated environments.
  • Broad understanding of enterprise and cloud security domains, including infrastructure security, application security, identity and access management, logging and monitoring, and incident response.
  • Experience overseeing or coordinating security services delivered through Managed Security Service Providers or shared service models.
  • Demonstrated ability to lead cross‑functional initiatives and influence stakeholders without direct authority.
  • Excellent written and verbal communication skills, with the ability to convey complex security topics to non‑technical and executive audiences.
  • Familiarity with common security frameworks and standards (e.g., ISO 27001, SOC 2, NIST).
  • Bachelor’s degree in Information Security, Computer Science, Systems Engineering, or a related field, or equivalent experience.
  • 8+ years of experience in information security governance, risk management, and compliance, particularly in customer-facing or regulated environments.
  • 5+ years of experience overseeing or coordinating security services delivered through Managed Security Service Providers or shared service models.

Nice To Haves

  • Experience supporting externally hosted, SaaS, or managed service offerings.
  • Direct experience working with external customers on security assurance, audits, and risk management.
  • Experience operating in a shared services or enterprise security model supporting multiple business units or customers.
  • Relevant certifications such as CISSP, CISM, or equivalent .

Responsibilities

  • Serve as the primary security point of contact for external customers, owning the end‑to‑end customer security relationship.
  • Lead customer security programs for managed services, ensuring alignment with contractual obligations, regulatory requirements, and enterprise security standards.
  • Translate customer security requirements into actionable security objectives, coordinating delivery across internal Information Security, Engineering, Cloud Platform, and Application Security teams.
  • Provide oversight and governance of MSSP‑delivered Security Operations, including monitoring, incident detection, response coordination, and SLA adherence.
  • Own and coordinate customer‑specific governance, risk, and compliance (GRC) activities, including risk assessments, control mapping, and remediation tracking.
  • Lead customer security governance forums, periodic security reviews, and executive‑level briefings.
  • Coordinate customer security questionnaires, audits, certifications, and assurance activities in partnership with internal GRC and compliance teams.
  • Ensure timely and effective communication of security posture, risks, incidents, and remediation plans to customers and executive stakeholders.
  • Oversee security incident coordination affecting customer environments, ensuring appropriate response, customer communication, and post‑incident follow‑
  • Track and manage customer security risks, exceptions, and remediation activities through formal governance processes.
  • Support the continuous improvement and scalability of the enterprise customer security program model.
  • Perform additional duties as assigned by the Director of Information Security.

Benefits

  • Medical
  • Dental
  • Vision
  • Life Insurance
  • 401k
  • Paid Time Off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service