Orienta is a global leader in Human Capital Management technology, providing secure cloud solutions to enterprise customers. They are seeking an experienced Technical Program Manager to drive execution and maturity of an enterprise Vulnerability Management program, requiring strong program ownership and executive communication skills.
Responsibilities:
- Lead and coordinate enterprise Vulnerability Management program initiatives across commercial accounts
- Build and maintain program roadmaps, milestones, risk registers, and dependency tracking
- Drive remediation SLA accountability across engineering, cloud, and infrastructure teams
- Manage full vulnerability lifecycle — detection through validation and closure
- Identify and mitigate program risks to maintain delivery timelines
- Develop executive-level dashboards and presentations for Director, VP, and CISO stakeholders
- Create clear, data-driven narratives on vulnerability trends, risk exposure, and remediation performance
- Provide program visibility using Jira, ServiceNow, PowerBI, and Excel
- Drive alignment between technical teams and business leadership
- Identify opportunities to enhance vulnerability workflows and reporting automation
- Standardize processes across application, cloud, and infrastructure scanning programs
- Support long-term VM roadmap development and enterprise security transformation efforts
- Improve metrics and KPIs to strengthen security posture transparency
Requirements:
- 5-7+ years in technical program management, project management, or security program delivery
- Experience in cybersecurity or vulnerability management programs
- Strong understanding of vulnerability lifecycle management (detection to remediation to validation)
- Advanced PowerPoint and executive storytelling capabilities
- Hands-on experience with Jira, ServiceNow, PowerBI, and Excel
- Ability to work independently in fast-paced, regulated SaaS environments
- Strong cross-functional stakeholder management and communication skills
- Experience working within cloud-native SaaS organizations
- Experience with vulnerability aggregation tools (e.g., Nucleus)
- Experience with scanning platforms such as Defender, CrowdStrike, Qualys, or Tenable
- Ability to leverage AI tools in day-to-day operations and workflows