Sr Program Manager, Cybersecurity
Hayward Holdings
Job description
Hayward Holdings Inc. (NYSE "HAYW") is one of the leading manufacturers of residential swimming pool equipment in the world, with a significant presence in the commercial pool market that is continuously growing. Hayward designs, manufactures, and markets a full line of residential and commercial pool and spa equipment including pumps, filters, heating, cleaners, salt chlorinators, automation, lighting, safety, flow control and energy solutions at our company owned facilities. Headquartered in Charlotte, North Carolina, Hayward also has facilities in Tennessee, Arizona, and Rhode Island, Georgia, as well as Canada, Spain, France, Australia, and China.
** Position Overview:**
Hayward is seeking an experienced Senior Program Manager (PM) contractor to lead a strategic, multi-year cybersecurity transformation initiative. This role is responsible for overseeing complex, cross-functional programs that strengthen the organization's security posture across Enterprise IT, Operational Technology (OT), and Internet of Things (IoT) environments; manage technology risk; support regulatory and compliance requirements; and drive the remediation of security incidents, vulnerabilities, audit findings, and control deficiencies.
The Senior PM will partner closely with Cybersecurity, Infrastructure, Enterprise Applications, Legal, Internal Audit, Operations, Engineering, and other business stakeholders to develop and execute the cybersecurity transformation roadmap. This individual will establish program governance, manage executive communications, and provide regular status updates, risk assessments, and strategic recommendations to Hayward's Senior Leadership Team.
Key responsibilities include leading a comprehensive cybersecurity assessment and vendor selection process (RFP); developing and executing a multi-year cybersecurity improvement roadmap; managing cross-functional initiatives across IT, OT, and IoT environments; and coordinating incident response, risk mitigation, and remediation efforts across the enterprise. The successful candidate will possess exceptional leadership, communication, and stakeholder management skills, along with deep experience delivering large-scale cybersecurity programs and a strong understanding of cybersecurity frameworks, governance practices, and enterprise technology environments.
Major Tasks and Responsibilities:
Cybersecurity Program Leadership:
-
Lead enterprise cybersecurity programs, initiatives, and strategic roadmaps that align with business objectives and organizational risk management priorities.
-
Establish and manage program governance, integrated plans, dependencies, decision logs, metrics, executive reporting, and escalation processes.
-
Coordinate security initiatives spanning infrastructure, cloud platforms, enterprise applications, identity and access management, data protection, vulnerability management, and third-party risk.
-
Drive the implementation and continuous improvement of security controls aligned with applicable industry standards and frameworks, such as NIST Cybersecurity Framework, ISO 27001, CIS Controls, and SOC requirements
Incident Response and Remediation Management :
-
Provide program leadership during cybersecurity incidents by coordinating cross-functional workstreams, communications, escalations, decision-making, and recovery activities.
-
Lead post-incident remediation programs by translating findings into clearly owned corrective actions, milestones, dependencies, and measurable closure criteria.
-
Manage security findings, vulnerability remediation efforts, risk treatment plans, and audit action plans through completion and validation.
-
Facilitate post-incident reviews and lessons-learned sessions, identify root causes and control gaps, and drive sustainable process and technology improvements.
-
Prepare concise executive updates that communicate incident impact, remediation status, risks, decisions, and blockers without exposing unnecessary sensitive technical detail.
RFP, Sourcing, and Vendor Management:
-
ยท Lead full Cybersecurity Assessment Requests for Proposal (RFP), and vendor selection processes from requirements definition through recommendation and contracting.
-
Develop evaluation criteria, scoring models, use cases, due diligence requirements, and stakeholder review processes that support objective supplier selection.
-
Coordinate vendor demonstrations, reference checks, security assessments, commercial evaluations, and final recommendation packages.
-
Partner with Senior Leadership, IT leadership, Cybersecurity, Infrastructure, Enterprise Applications, Legal, Operations, Engineering, and other business stakeholders on contract negotiations, Statements of Work (SOWs), service-level expectations, implementation commitments, and risk provisions.
-
Manage strategic vendor relationships, performance, risks, issues, and delivery expectations throughout the program lifecycle.
Program and Portfolio Management:
-
Define program scope, objectives, success measures, deliverables, workstreams, dependencies, resources, budgets, and milestones.
-
Identify and mitigate delivery, operational, cybersecurity, compliance, third-party, and organizational change risks.
-
Provide executive-level reporting and recommendations on program health, key decisions, financial status, risks, issues, dependencies, and expected outcomes.
-
Facilitate alignment across business and technical teams and hold workstream owners accountable for commitments, decisions, and timely escalation.
-
Ensure effective change management, communications, training, operational readiness, and benefits realization are incorporated into program plans.
Audit, Compliance, and Risk Management:
-
Coordinate program activities supporting internal audits, external audits, risk assessments, penetration tests, control reviews, and compliance assessments.
-
Track remediation plans related to audit findings, security assessments, policy exceptions, control gaps, and identified risks.
-
Partner with Legal, Compliance, Internal Audit, Privacy, and Cybersecurity teams to support applicable regulatory, contractual, and policy requirements.
-
Maintain clear evidence, decision records, and status documentation to support governance reviews and remediation closure.
-
Promote a culture of security awareness, accountability, and risk-based decision-making across the organization.
Requirements:
Required:
-
Bachelor's degree in Information Technology, Computer Science, Information Security, Business Administration, Project Management, or a related field.
-
15+ years of experience managing complex technology programs, enterprise initiatives, or cybersecurity-related projects, including multiple interdependent workstreams.
-
Proven experience leading cross-functional programs involving cybersecurity, infrastructure, cloud technologies, enterprise applications, third-party vendors, OT, and IoT.
-
Demonstrated experience leading enterprise RFP processes, vendor evaluations, contract and SOW development, and strategic sourcing initiatives.
-
Experience coordinating cybersecurity incident response, crisis management, vulnerability remediation, audit remediation, or risk reduction programs.
-
Strong understanding of cybersecurity principles, technology risk management, security governance, control frameworks, and compliance practices.
-
Experience developing executive-level communications and presenting complex technical, security, and risk topics to business leaders.
-
Advanced leadership, facilitation, negotiation, conflict resolution, and stakeholder management skills.
-
Proven ability to manage multiple concurrent programs, ambiguity, sensitive information, and competing priorities in a global enterprise environment.
-
Working knowledge of both predictive and adaptive delivery approaches, including waterfall, agile, and hybrid program management.
Additional Preferred Qualifications:
-
Project Management Professional (PMP), Program Management Professional (PgMP), or comparable program management certification.
-
CISSP, CISM, CRISC, Security+, or another recognized cybersecurity or technology risk certification.
-
Experience with NIST Cybersecurity Framework, ISO 27001, CIS Controls, SOC reporting, and related security or control standards.
-
Experience supporting internal and external audits, regulatory assessments, cyber insurance reviews, or customer security requirements.
-
Experience leading global programs involving multiple business units, vendors, and geographically distributed teams.
Location: Remote (needs ability to travel)
#LI-LS1