7+ years of professional experience in software development projects and management
5+ years of experience in large scale Project/Program management
Proven track record in complex projects with global, distributed teams
People management experience for 20+ FTEs
Good understanding of program financials and reporting
Good understanding of project manager areas of responsibility:
Backlog prioritization, detailing and decomposition
Understanding of SDLC and ability to build/optimize project processes
Communication with the team, client
Understanding of motivation factors
Working with feedback: provide and receive
Demonstrable experience running IT risk, security, or compliance-driven programmes
not only feature delivery
Ability to build and maintain a risk register: identification, qualification, scoring, mitigation planning, ownership assignment, and escalation
Experience coordinating remediation programmes across multiple engineering teams (patching, vulnerability closure, control implementation) and tracking them to measurable closure
Comfortable operating with audit, InfoSec, and compliance stakeholders; experience preparing evidence and status for governance forums or steering committees
Working knowledge of at least one control or risk framework (NIST CSF/RMF, ISO 27001, CIS Controls, SOC 2, or similar)
Ability to translate technical findings into business impact and risk-based prioritization for senior stakeholders
Soft skills and education:
Verbal and written business communication skills
Presentation skills, including to executive and risk-committee audiences
Master's Degree in computer science or similar education
Certification advantage: PMP / PRINCE2 / SAFe, plus one of CISSP, CISM, CRISC, or CISA
Familiarity with security vulnerability management: CVE/CVSS, severity triage, SLA-based remediation cycles
Exposure to penetration testing engagements
scoping, vendor coordination, findings review, retest tracking
Understanding of AI/GenAI risk: model and data governance, AI risk scans and assessments, prompt injection and data leakage exposure, third-party AI tooling review
Awareness of emerging AI governance and regulation (EU AI Act, NIST AI RMF) and how it lands on delivery teams
Understanding of secure SDLC practices: SAST/DAST/SCA, dependency and supply chain risk, threat modelling