Senior Security Program Manager
KeyRock
AI Summary
The vacancy is well-defined in terms of tasks and requirements but lacks compensation details and company information.
Description
KeyRock is hiring a Senior Security Program Manager to lead security initiatives in a fast-paced trading environment.
The role involves program leadership, security governance, and cross-functional influence.
As a Senior Security Program Manager, you will drive execution of Keyrock’s highest-priority security initiatives across a fast-moving, always-on trading environment.
You’ll build structure, visibility, and predictable delivery across security programs—partnering with Engineering, Infrastructure/Cloud, Trading/Quant Engineering, IT, Risk/Compliance, and leadership to reduce risk while enabling business velocity.
## What you'll do
- •Own a portfolio of security programs including planning, resourcing, milestones, dependencies, risk/issue management, and outcomes.
- •Create and maintain multi-quarter roadmaps aligned to Keyrock’s business and operating model.
- •Establish governance and operating cadence: steering meetings, status reporting, program reviews, and executive updates.
- •Support the CISO in delivering firmwide initiatives.
- •Partner with Security and Engineering teams to drive key initiatives such as access governance, secrets management, vulnerability remediation, and more.
- •Partner with the Director of GRC to support GRC and audit initiatives.
- •Partner with Security Operations to improve incident preparedness.
Requirements
- •7+ years in security program management or related fields.
- •Experience running cross-functional programs across engineering and operations.
- •Strong technical fluency in cloud/infra, identity/access, vulnerability management, security monitoring, and incident processes.
- •Excellent written/verbal communication skills.
- •Experience in fintech, trading, payments, or digital assets is preferred.
- •Familiarity with security frameworks (NIST CSF, ISO 27001) and audit/assurance concepts.
- •Relevant certifications (e.g., CISM, CISSP, CISA, CRISC, PMP) are a plus.