{"schemaVersion":"jobsearcher.job.v1","id":"bd978b8d0a9a1e836f968e1d","url":"https://jobsearcher.com/jobs/bd978b8d0a9a1e836f968e1d","canonicalUrl":"https://jobsearcher.com/jobs/bd978b8d0a9a1e836f968e1d","title":"Cyber Security Program Manager","description":"About Ceribell\nCeribell is a medical technology company focused on transforming the diagnosis and management of patients with serious neurological conditions. The Ceribell System is a novel, point-of-care electroencephalography (\"EEG\") platform specifically designed to address the unmet needs of patients in the acute care setting, and is being used in hundreds of community hospitals, large academic facilities and major IDN's across the country. Our entire team is driven by a shared commitment to transforming the landscape of critical care through our rapid seizure detection technology, come join the movement!\nPosition Overview:\nCybersecurity Program Management\nLead coordination efforts with Information Security and Governance Risk & Compliance (GRC) leadership to strategically plan, execute, and oversee cybersecurity initiatives, ensuring alignment with company-wide objectives and regulatory compliance.\nDirect and refine ongoing continuous monitoring requirements to ensure effectiveness and audit readiness.\nHelp lead and participate in FedRAMP audits, driving documentation strategy, POA&M tracking, and interdepartmental reporting between vendors, internal teams, and Security leadership.\nGuide the team in identifying and prioritizing improvements for NIST 800-53 control effectiveness and maturity.\nCoordination of risk assessments, vulnerability management activities, and security training schedules in collaboration with key stakeholders\nIT Program Management\nPartner and collaborate across the organization to align on strategic objectives and shape roadmaps IT and Security navigating complex, high-impact projects, with agility to re-prioritize as needed.\nDrive initiatives to streamline operational efficiency, and maximize software utilization across the enterprise.\nGovernance, Risk, and Compliance (GRC)\nCollaboration with the GRC team to ensure policies, procedures, and standards are proactively updated to maintain alignment with evolving compliance frameworks.\nFacilitate security risk assessments, ensuring thorough documentation of critical risks and establishing measurable strategies to drive risk mitigation and accountability\nIncident Response\nProvide strategic input in incident response planning and execution, contributing to the design of response processes and assisting in escalation and resolution of security incidents as needed.\nProject Management\nDrive delivery of complex, cross-functional projects—from requirements gathering through implementation—defining schedules, scopes, and mitigation plans for enterprise-level initiatives.\nDemonstrate expert-level capability in managing multiple, concurrent initiatives with conflicting priorities and tight deadlines, ensuring alignment with organizational goals.\nOptimize use of project management tools such as Jira or Notion to enhance transparency, reporting, and collaboration.\nWhat We're Looking For:\n10+ years of progressive experience in cybersecurity, FedRAMP, or IT program management with a proven track record of leading large-scale security or compliance programs.\nDemonstrated leadership in Program Management related activities, including continuous monitoring, documentation, and third-party assessments.\nDeep expertise in NIST frameworks (800-53, 800-30, 800-161) with the ability to advise teams and influence policy and control implementation.\nExperience overseeing multiple compliance programs (e.g., SOC 2 Type 2, HIPAA, SOX ITGC) and ensuring cross-functional coordination for audit readiness.\nStrong executive communication skills with the ability to present complex security topics to both technical and non-technical audiences.\nAdvanced problem-solving, strategic thinking, and decision-making abilities in complex IT environments.\nU.S. citizenship required due to federal compliance.\nMust meet identification verification requirements prior to start.\nDemonstrated ability to thrive in high-pressure, fast-paced environments while managing competing priorities.\nOpen to Remote candidates.\nPreferred\nIndustry-recognized certifications such as CISA, CISSP, or PMP.\nExperience with security and monitoring tools such as Jira, Splunk, Tenable, and Trend Micro.\nStrong knowledge of cloud architectures, especially AWS and associated services.\n\nA candidate's final salary offer will be based on their skills, education, work location and experience, and thus it may differ from the posted range. Compensation may also include bonuses consistent with Ceribell's corporate compensation plan. Note, the above description is not all-encompassing and Ceribell reserves the right to change or modify job duties and assignments at any time.\nIn addition to your base compensation, Ceribell offers eligible employees the following:\nPerformance-based incentive compensation (varies by role)\nEquity opportunities\n100% Employer paid Health Benefits for Employees\n50% - 70% Employer paid Health, Dental & Vision for dependents (depending on plan selection)\n100% paid Life and Long-Term Disability Insurance\n401(k) with a generous company match\nEmployee Stock Purchase Plan (ESPP) with a discount\nMonthly cell phone stipend\nFlexible paid time off\n13 Paid Holidays + 3 Company Wellness Days\nExcellent parental leave policy\nFantastic culture with tremendous career advancement opportunities\nJoining a mission-minded organization!\nApplication Deadline: Ongoing\nOther Job Details\nCeribell reports transfers of value to health care providers (HCPs) as required by federal and state transparency laws. These laws and implementing regulations require Ceribell to provide government agencies with HCPs' names, addresses and the type of payments or other value received, generally for public disclosure. If you are an HCP and we pay or reimburse your recruiting expenses as a result of interviewing with Ceribell, your name, address and the amount of payments made may be reported to the government.\nEqual Opportunity Employer\nCeribell is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth and related medical conditions), sexual orientation, gender identity or expression, national origin, age, marital status, disability, veteran status or any other characteristic protected by law. Ceribell complies with all applicable national, state and local laws governing nondiscrimination in employment as well as work authorization and employment eligibility verification requirements of the Immigration and Nationality Act and IRCA. Ceribell is an E-Verify employer. Any applicant with a disability who requires an accommodation during the application process should contact talent@ceribell.com to request reasonable accommodation.\nPrivacy Statement\nFor information on how Ceribell processes personal data of job applicants, please review our Privacy Policy.\nCompliance Disclaimer\nIf you believe this job posting is non-compliant, please submit a report to legal@ceribell.com. Please note that we will not respond to inquiries unrelated to job posting compliance.","company":"Ceribell","rawCompany":"ceribell","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-08-15T13:13:17.765Z","occupations":[{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"11-3013.01","title":"Security Managers","slug":"security-managers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"541519","title":"Other Computer Related Services","slug":"other-computer-related-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Cyber Security Program Manager","description":"About Ceribell\nCeribell is a medical technology company focused on transforming the diagnosis and management of patients with serious neurological conditions. The Ceribell System is a novel, point-of-care electroencephalography (\"EEG\") platform specifically designed to address the unmet needs of patients in the acute care setting, and is being used in hundreds of community hospitals, large academic facilities and major IDN's across the country. Our entire team is driven by a shared commitment to transforming the landscape of critical care through our rapid seizure detection technology, come join the movement!\nPosition Overview:\nCybersecurity Program Management\nLead coordination efforts with Information Security and Governance Risk & Compliance (GRC) leadership to strategically plan, execute, and oversee cybersecurity initiatives, ensuring alignment with company-wide objectives and regulatory compliance.\nDirect and refine ongoing continuous monitoring requirements to ensure effectiveness and audit readiness.\nHelp lead and participate in FedRAMP audits, driving documentation strategy, POA&M tracking, and interdepartmental reporting between vendors, internal teams, and Security leadership.\nGuide the team in identifying and prioritizing improvements for NIST 800-53 control effectiveness and maturity.\nCoordination of risk assessments, vulnerability management activities, and security training schedules in collaboration with key stakeholders\nIT Program Management\nPartner and collaborate across the organization to align on strategic objectives and shape roadmaps IT and Security navigating complex, high-impact projects, with agility to re-prioritize as needed.\nDrive initiatives to streamline operational efficiency, and maximize software utilization across the enterprise.\nGovernance, Risk, and Compliance (GRC)\nCollaboration with the GRC team to ensure policies, procedures, and standards are proactively updated to maintain alignment with evolving compliance frameworks.\nFacilitate security risk assessments, ensuring thorough documentation of critical risks and establishing measurable strategies to drive risk mitigation and accountability\nIncident Response\nProvide strategic input in incident response planning and execution, contributing to the design of response processes and assisting in escalation and resolution of security incidents as needed.\nProject Management\nDrive delivery of complex, cross-functional projects—from requirements gathering through implementation—defining schedules, scopes, and mitigation plans for enterprise-level initiatives.\nDemonstrate expert-level capability in managing multiple, concurrent initiatives with conflicting priorities and tight deadlines, ensuring alignment with organizational goals.\nOptimize use of project management tools such as Jira or Notion to enhance transparency, reporting, and collaboration.\nWhat We're Looking For:\n10+ years of progressive experience in cybersecurity, FedRAMP, or IT program management with a proven track record of leading large-scale security or compliance programs.\nDemonstrated leadership in Program Management related activities, including continuous monitoring, documentation, and third-party assessments.\nDeep expertise in NIST frameworks (800-53, 800-30, 800-161) with the ability to advise teams and influence policy and control implementation.\nExperience overseeing multiple compliance programs (e.g., SOC 2 Type 2, HIPAA, SOX ITGC) and ensuring cross-functional coordination for audit readiness.\nStrong executive communication skills with the ability to present complex security topics to both technical and non-technical audiences.\nAdvanced problem-solving, strategic thinking, and decision-making abilities in complex IT environments.\nU.S. citizenship required due to federal compliance.\nMust meet identification verification requirements prior to start.\nDemonstrated ability to thrive in high-pressure, fast-paced environments while managing competing priorities.\nOpen to Remote candidates.\nPreferred\nIndustry-recognized certifications such as CISA, CISSP, or PMP.\nExperience with security and monitoring tools such as Jira, Splunk, Tenable, and Trend Micro.\nStrong knowledge of cloud architectures, especially AWS and associated services.\n\nA candidate's final salary offer will be based on their skills, education, work location and experience, and thus it may differ from the posted range. Compensation may also include bonuses consistent with Ceribell's corporate compensation plan. Note, the above description is not all-encompassing and Ceribell reserves the right to change or modify job duties and assignments at any time.\nIn addition to your base compensation, Ceribell offers eligible employees the following:\nPerformance-based incentive compensation (varies by role)\nEquity opportunities\n100% Employer paid Health Benefits for Employees\n50% - 70% Employer paid Health, Dental & Vision for dependents (depending on plan selection)\n100% paid Life and Long-Term Disability Insurance\n401(k) with a generous company match\nEmployee Stock Purchase Plan (ESPP) with a discount\nMonthly cell phone stipend\nFlexible paid time off\n13 Paid Holidays + 3 Company Wellness Days\nExcellent parental leave policy\nFantastic culture with tremendous career advancement opportunities\nJoining a mission-minded organization!\nApplication Deadline: Ongoing\nOther Job Details\nCeribell reports transfers of value to health care providers (HCPs) as required by federal and state transparency laws. These laws and implementing regulations require Ceribell to provide government agencies with HCPs' names, addresses and the type of payments or other value received, generally for public disclosure. If you are an HCP and we pay or reimburse your recruiting expenses as a result of interviewing with Ceribell, your name, address and the amount of payments made may be reported to the government.\nEqual Opportunity Employer\nCeribell is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth and related medical conditions), sexual orientation, gender identity or expression, national origin, age, marital status, disability, veteran status or any other characteristic protected by law. Ceribell complies with all applicable national, state and local laws governing nondiscrimination in employment as well as work authorization and employment eligibility verification requirements of the Immigration and Nationality Act and IRCA. Ceribell is an E-Verify employer. Any applicant with a disability who requires an accommodation during the application process should contact talent@ceribell.com to request reasonable accommodation.\nPrivacy Statement\nFor information on how Ceribell processes personal data of job applicants, please review our Privacy Policy.\nCompliance Disclaimer\nIf you believe this job posting is non-compliant, please submit a report to legal@ceribell.com. Please note that we will not respond to inquiries unrelated to job posting compliance.","datePosted":"2026-08-15T13:13:17.765Z","dateModified":"2026-08-15T13:13:17.765Z","hiringOrganization":{"@type":"Organization","name":"Ceribell","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"bd978b8d0a9a1e836f968e1d"},"url":"https://jobsearcher.com/jobs/bd978b8d0a9a1e836f968e1d"}}