Cybersecurity Program Manager
We are seeking an experienced Cybersecurity Program Manager to lead and coordinate a broad portfolio of cybersecurity initiatives across multiple domains, including Identity & Access Management, Network Security, Data Protection, Application & AI Security, Endpoint Security, Security Operations, Governance/Risk/Compliance, Physical Security, and Infrastructure Engineering transitions.
In this role, you will drive program governance, cross-functional execution, and stakeholder alignment across complex security programs. The ideal candidate is highly organized, technically conversant in cybersecurity domains, and capable of producing executive leadership-ready reporting that supports strategic decision-making.
You will work closely with engineering, security, infrastructure, compliance, and executive stakeholders to ensure cybersecurity initiatives are delivered effectively and aligned with organizational priorities.
About First Factory
We are a software development company with over two decades of experience, boasting a dynamic team of 175+ professionals actively engaged in diverse projects across various industries. We invite you to join us on this journey as we thrive and embrace fresh challenges.
Key Responsibilities
Portfolio & Program Governance
Lead a multi-domain cybersecurity portfolio with multiple parallel workstreams.
Define program scope, success metrics, program charters, and cross-functional roadmaps.
Maintain governance artifacts such as RAID logs, dashboards, and program readiness reports.
Develop executive-level presentations summarizing program status, risks, dependencies, and recommendations.
Prepare materials for steering committees and executive leadership forums.
Cross-Functional Leadership
Coordinate closely with engineering, operations, product, compliance, legal, cloud, infrastructure teams, and external partners.
Facilitate alignment on priorities, timelines, dependencies, and risks.
Lead planning sessions, architecture discussions, risk workshops, and program integration checkpoints.
Ensure program decisions are clearly documented and communicated to stakeholders.
Execution & Delivery Management
Build and manage end-to-end program schedules, milestones, and critical paths.
Track delivery progress across multiple cybersecurity domains.
Identify risks, resolve issues, and manage program changes through structured change control processes.
Translate complex technical updates into clear executive-level summaries for leadership.
Vendor & Partner Coordination
Manage external vendors and partners supporting security assessments, engineering initiatives, testing, infrastructure, or compliance programs.
Ensure partner deliverables and timelines align with program goals.
Consolidate partner updates into clear stakeholder reporting and leadership-ready presentations.
Technical Program Support
Support security and engineering teams across initiatives such as:
Security architecture reviews, penetration testing, and security assessments.
Cloud security enhancements, identity modernization, and network segmentation initiatives.
Data protection improvements and resiliency exercises.
Security operations modernization, monitoring, detection, and incident-response readiness.
Application, platform, AI, and infrastructure security improvements.
Governance, Risk & Compliance
Coordinate initiatives related to risk assessments, privacy, compliance certifications, policy lifecycle management, and exception processes.
Ensure alignment with security frameworks such as NIST, ISO, SOC, Zero Trust, and other industry standards.
Produce executive-level dashboards summarizing security posture, risks, and compliance gaps.
Executive Communication
Develop executive communications and presentations, including:
- Quarterly Business Reviews (QBRs)
- Steering committee presentations
- Program strategy reviews
- Risk and compliance summaries
- Portfolio roadmaps and funding proposals
Translate technical concepts into clear visuals and narratives suitable for senior leadership and C-suite stakeholders.
Provide leadership with decision options, trade-offs, and strategic recommendations.
Requirements
7+ years of experience in program or project management, with several years focused on cybersecurity or technology programs.
Proven experience managing large, multi-workstream enterprise programs.
Experience leading major initiatives such as cloud migrations, infrastructure modernization, M&A transitions, or enterprise technology transformations.
Strong understanding of cybersecurity domains, including identity, network security, cloud security, data protection, security operations, and governance/risk/compliance.
Experience working in regulated or compliance-driven environments.
Exceptional communication and executive presentation skills, including the ability to translate complex technical topics for leadership audiences.
Experience using program management tools, dashboards, and reporting platforms such as PowerBI, PowerPoint, or other data visualization tools.
Strong ability to lead cross-functional teams and influence stakeholders without direct authority.
Excellent organizational, analytical, and problem-solving skills.
Nice to have
Experience using AI tools to enhance program management workflows.
Certifications such as PMP, PgMP, CISSP, CISM, CISA, or Agile/SAFe certifications.
Experience leading large-scale cybersecurity transformation programs.
Experience supporting cloud migrations or enterprise-scale technology transitions.
Background collaborating closely with engineering, DevOps, IT operations, or security operations teams.
Experience developing executive-level materials for board, audit, or regulatory reviews.
- Department
- Project & Product Management
- Role
- Cybersecurity Program Manager
- Locations
- Heredia
- Remote status
- Hybrid
About First Factory
For over 25 years, First Factory has been a place where collaborative excellence meets modern technologies. We’re a strong team building exceptional software solutions from Costa Rica and LATAM for primarily US-based clients. With industry-low turnover, top eNPS globally, and 5 consecutive Inc. 5000 awards, we foster an environment where talented engineers thrive on challenging projects using modern tech stacks.