Program Manager – SecOps
Bright Defense · Now Hiring
Program Manager, Client Engagement & Compliance Delivery
Bright Defense helps organizations achieve and maintain continuous compliance across SOC 2, HIPAA, PCI DSS, CMMC, ISO 27001, and beyond. We’re looking for an operator who thrives on structure, owns process end-to-end, and can bring calm and clarity to a fast-moving client engagement environment.
About the role
The Program Manager, Client Engagement & Compliance Delivery is the connective tissue between sales handoff and long-term client success. You’ll own the kickoff experience for every new engagement, design and enforce the operational processes our delivery teams run on, and build the visibility tools that let leadership and clients trust the program is on track — at all times.
Core responsibilities
Client kickoff & onboarding
- Own the end-to-end new client kickoff process from contract close through first active sprint
- Develop and maintain a standardized kickoff playbook — scope confirmation, stakeholder mapping, tool access, initial risk review
- Lead kickoff calls with client technical and executive contacts
- Define program-level milestones and establish cadence expectations with each client
- Coordinate cross-functional handoffs between sales, delivery leads, and client POCs
Ongoing engagement oversight
- Build and operate a client health monitoring system — tracking milestone completion, open tasks, and program status across all active engagements
- Create and maintain client-facing dashboards and internal progress reports
- Identify and escalate engagement risks before they become client issues
- Run structured recurring touchpoints — QBRs, monthly check-ins, internal POD reviews
- Continuously improve delivery templates, task structures, and Asana project hygiene across all client workspaces
Process & systems development
- Design and document repeatable SOPs for kickoff, onboarding, and ongoing delivery
- Build workflow templates in Asana mirroring compliance framework milestones
- Establish intake and scoping forms that feed directly into project setup
- Define SLAs for internal task completion and client response turnaround
- Collaborate with technical leads to keep delivery aligned with framework timelines
- Maintain and evolve the internal Confluence knowledge base for delivery operations
Required qualifications
Process & PM
- 5+ years in program or project management with strong process ownership
- Proven ability to design operational systems and SOPs from scratch
- Expert-level Asana, ClickUp, or equivalent PM tooling
- Experience managing multiple concurrent client engagements
Compliance & security (preferred)
- Familiarity with SOC 2, HIPAA, PCI DSS, ISO 27001, or CMMC frameworks
- Prior experience as part of an information security program or GRC function
- Ability to read and interpret compliance control requirements
- Experience in an MSSP, consulting, or audit-adjacent environment
Communication
- Confident facilitating kickoff calls with CTO/CISO-level stakeholders
- Strong written communication for documentation and async coordination
- Able to translate audit requirements into clear client-facing language
Tools & tech
- Asana for project and task management
- Confluence (or similar wiki) for documentation
- Google Workspace or Microsoft 365 proficiency
- Drata, Vanta, or equivalent GRC platforms (a plus)
What success looks like in year one
Compensation & perks
- Competitive base salary commensurate with experience — range shared during screening
- Remote-first position with flexible working hours
- Certification reimbursement (CISA, PMP, CISSP, CISM, and others)
- Direct access to Bright Defense co-founders and meaningful ownership of program operations
- Front-row seat to a growing cybersecurity compliance practice across defense, healthcare, and fintech verticals
Bright Defense is an equal opportunity employer. We build diverse, high-trust teams.