Senior Technical Program Manager
Location: Kansas City metro (hybrid)
Type: Full-time
Reports to the Founder & CEO
Compensation: $115k-$145k; Travel Required
WHY THIS ROLE EXISTS
Cyber 429 delivers enterprise-grade security and compliance programs with a deliberately small, senior team. Our active portfolio spans multi-year, multi-workstream framework remediation programs (NIST 800-53, NIST 800-171/CMMC, SOX ITGC) for enterprise clients, physical security assessments, vCISO engagements at multiple institutions, a student-powered SOC, and two annual security events. The CEO leads these programs. Your job is to make sure nothing under them slips: every deliverable tracked, every dependency visible, every status report accurate, every client seeing a program that simply runs. This is not a coordinator role. You will own the operating system of our delivery practice and represent it directly to client executives and leadership teams.
WHAT YOU WILL OWN
• Program execution — run the integrated project plans, workstream schedules, dependency maps, and milestone tracking for all active client programs; surface schedule risk before it becomes slippage.
• Systems of record — own the POA&M registers, risk registers, control trackers (NIST 800-53, NIST 800-171/CMMC, SOX ITGC), and evidence libraries that serve as each program's system of record; keep them current weekly, not quarterly.
• Governance cadence — produce the weekly written status, monthly executive readouts, and board/audit-committee-ready reporting packages; maintain decision logs, action trackers, and rolling document request lists for every engagement.
• Atlassian platform — administer and continuously improve our Jira/Confluence program workspaces and dashboards; build the templates, automations, and intake workflows that let a small team run enterprise-grade programs.
• Deliverable lifecycle — manage the pipeline of client deliverables through drafting, internal QA, client review cycles, and formal acceptance; enforce the review SLAs we commit to in engagement letters.
• Vendor and stakeholder accountability — track partner-delivered and client-internal workstreams against their commitments; prepare the accountability materials our engagement leads use to keep vendors and internal owners on schedule.
• Client-side orchestration — coordinate client counterparts, site SPOCs, interview schedules, DRL collection, and travel logistics for on-site work including physical security assessments.
• Commercial hygiene — keep engagement scope, assumptions, and fee milestones aligned with what is actually being delivered; flag scope creep and change-order triggers early; support invoicing against milestones.
WHAT GOOD LOOKS LIKE IN YEAR ONE
• Every active program has a current integrated plan, register, and dashboard a client executive could read cold and trust.
• Weekly status ships on time, every week, without the CEO writing it.
• Zero deliverables missed for reasons we could see coming; dependencies and blockers escalated with runway to act.
• Partner-delivered and client-internal workstreams tracked to the same standard as our own — with the documentation to prove it.
• A repeatable program playbook (templates, workflows, cadences) that lets Cyber 429 onboard the next enterprise client without reinventing anything.
WHAT YOU BRING
• 8+ years of technical program or project management, including 3+ years running multi-workstream programs for external clients (consulting, MSSP, or professional services strongly preferred).
• Working fluency in security and compliance frameworks — NIST 800-53/800-171, CMMC, SOX ITGC — enough to speak credibly about controls, evidence, and remediation without an interpreter.
• Deep, hands-on Jira and Confluence skills: workflows, dashboards, automation, and structure design — you build the workspace, not just live in it.
• Executive-grade written communication. Your status reports, readouts, and meeting notes go to CIOs, CFOs, and audit committees as-is.
• Composure and follow-through in ambiguity: you close loops, chase owners, and escalate with judgment rather than waiting to be told.
• PMP, PgMP, or equivalent scar tissue. CISSP, CISA, CISM, or Security+ a plus. Prior work in regulated or compliance-heavy environments a plus.
• Kansas City metro based or willing to relocate; periodic travel to client sites (roughly monthly during active assessment windows).
• Currently or previously held a US Security Clearance a plus; applicants must be eligible to obtain a US Security clearance
HOW WE WORK
Cyber 429 is a bootstrapped, founder-led security firm with an intelligence-community DNA and a “fans, not customers” standard for client experience. We serve organizations from regulated enterprises to colleges, schools, and under-resourced institutions, and we operate with the urgency that mission implies. Small team, no bureaucracy, high trust, high accountability. You will see the whole business, sit close to the CEO, and your work will be visible to client leadership within your first month.
COMPENSATION
Base salary of $115,000–$145,000 depending on experience, plus an annual performance bonus of up to 10% tied to program milestone delivery and client retention. Health benefits, and the standard Cyber 429 flexibility that comes with being trusted to run your own calendar. Other benefits come with this role and which we will discuss during the hiring process.
By continuing you agree to our Terms & Privacy Policy.