Home / Current Issue / Paper 1710083
The Program Manager?s Role in Cyber Security
Subject area: Management and Commerce · Area of research: Program Management
Abstract
As cyber threats evolve in complexity and frequency, cybersecurity has become a pivotal concern across organizations. While technical specialists often receive most attention, the Program Manager (PM) has emerged as equally critical in ensuring robust cybersecurity governance. PMs align cybersecurity initiatives with organizational goals, translating technical risks into business-relevant insights for executive leadership (Associated Press, 2025). They oversee program implementation?ensuring delivery on time, within budget, and in compliance with frameworks such as NIST, GDPR, HIPAA, or ISO-27001 (Associated Press, 2025; University of Tennessee, 2024). Moreover, PMs act as the bridge between cybersecurity teams and non-technical stakeholders, facilitating communication and coordination to enhance cyber resilience across departments (McKesson, 2025; University of Tennessee, 2024). They are expected to possess a working knowledge of cybersecurity domains?such as vulnerability management, incident response, threat modeling, and supply-chain security?to anticipate and mitigate risks during project planning and execution (University of Tennessee, 2024; U.S. Department of Defense, 2023). With increasing digitization through cloud computing, IoT, and remote work, PMs lead cross-functional teams to build adaptive and resilient security frameworks, ensuring governance and compliance (McKesson, 2025; Edstellar, 2024). Through real-world case studies and best practices, PMs demonstrate their ability to minimize cybersecurity breaches, maintain regulatory compliance, and promote a culture of security awareness. In roles like the GDIT Cybersecurity Program Manager, PMs manage risk visibility, stakeholder collaboration, and strategic alignment to strengthen security postures and build trust across the organization (GDIT, 2025). In summary, effective Program Management is indispensable to organizational cybersecurity?making the PM not just an operational role, but a strategic leader in safeguarding digital assets and maintaining stakeholder trust in a hostile cyber landscape.
Keywords
Cybersecurity leadership, Program management, Security integration, Business risk mitigation, Cross-functional alignment
References
[1] Associated Press. (2025). Cybersecurity program manager. Associated Press Careers. https://careers.ap.org/job/NewYorkCybersecurit y-Program-Manager-NY-10281/1307672700/
[2] Edstellar. (2024). Program manager roles and responsibilities.Edstellar.https://www.edstellar.c om/blog/programmanagerrolesandresponsibiliti es
[3] GDIT. (2025). Cybersecurity program manager. General Dynamics Information Technology Careers.https://www.gdit.com/careers/job/e9037 9949/cybersecurity-program-manager/
[4] McKesson. (2025). MTA lead program manager,cybersecurity.McKessonCareers.https: //careers.mckesson.com/en/job/irving/mta-lead- program-manager- cybersecurity/733/84721042464
[5] University of Tennessee. (2024). What does a cybersecurity project manager do? Master of Science in Business Cybersecurity Online. https://msbc-online.utk.edu/articles/what-does- a-cybersecurity-project-manager-do/
[6] U.S. Department of Defense. (2023). Program manager work role. Defense Cyber Workforce Framework. https://public.cyber.mil/dcwf-work- role/program-manager/
[7] Olejnik, J. (2025, January 22). Cybersecurity is a financial issue, not just an IT issue. Wipfli. https://www.wipfli.com/insights/articles/racyber security-is-a-financial-issue
[8] Peris. (2025, February 11). Cybersecurity is no longer an IT problem – It’s a business problem. Peris.ai.https://www.peris.ai/post/cybersecurity- is-no-longer-an-it-problem---its-a-business- problem
[9] Symphonise Consulting. (2025, March 6). Why cybersecurity is a boardroom issue: What executives need to know. Symphonise Consulting. https://symphonise.consulting/why- cybersecurity-is-a-boardroom-issue-what- executives-need-to-know/
[10] World Economic Forum. (2023, April 13). Strategizing cybersecurity: Why a risk-based approach is key. World Economic Forum. https://www.weforum.org/agenda/2023/04/strat egizing-cybersecurity-why-a-risk-based- approach-is-key/
[11] BlueVoyant. (2025). 7 types of cyber threats and how to prevent them: 2025 guide. https://www.bluevoyant.com/knowledge- center/7-types-of-cyber-threats-how-to-prevent- them-2022-guide
[12] Canadian Centre for Cyber Security. (n.d.). An introduction to the cyber threat environment. https://www.cyber.gc.ca/en/guidance/introducti on-cyber-threat-environment
[13] Microsoft. (n.d.). What is cybersecurity?. https://www.microsoft.com/enus/security/busine ss/security-101/what-is-cybersecurity
[14] Cognixia. (2025, February 17). The project manager as a bridge: Connecting business and development teams.Cognixia.Cognixia
[15] DVMS Institute. (2024, August 7). Business relationship managers: The bridge to cybersecurity. DVMS Institute. DVMS institute
[16] Adeyinka, A. (2024). The role of program managers in ensuring successful cybersecurity initiatives. International Journal of Innovative Science and Research Technology, 9(5), 2942. https:// 50 IJISRT
[17] Tedeschi, S., Marzi, G., Balzano, M., & Costa, G. (2025). Managerial insights on investment strategy in cybersecurity: Findings from multi- country research [Preprint]. arXiv. https://arxiv.org/abs/2505.11549 arXiv
[18] Harvard Business Review. (2021). The Strategic Program Manager: Leading Cybersecurity Initiatives. HBR. https://hbr.org/2021/05/the- strategic-program-manager-in-cybersecurity
[19] CISA. (2024). Cybersecurity oversight and alignment [Blog post]. Cybersecurity & Infrastructure Security Agency. Retrieved August 2025, from https://www.cisa.gov IIL - Thought Leadership Newsletter
[20] World Economic Forum. (2023). Cybersecurity: A strategic priority. https://www.weforum.org IT Pro
[21] Smith, J. (2024). Prioritizing security in project timelines. Journal of Cyber Project Management, 15(2),45–55.
[22] NIST. (2023). NIST Cybersecurity Framework (CSF) 2.0. National Institute of Standards and Technology. https://www.nist.gov/cyberframeworkISACA
[23] ISACA. (2020). Essential functions of a cybersecurity program. ISACA Journal, 4. https://www.isaca.org/resources/isacajournal/iss ues/2020/volume-4/essential-functions-of-a- cybersecurity-programISACA
[24] Lemieux, R. (2024, July 24). The Project Manager’s role in cybersecurity risk management. DVMS Institute. https://blog.iil.com/the-project-managers- roleincybersecurityriskmanagement/IILThought LeadershipNewsletter
[25] Forrester Research. (2022). Program Managers as Security Enablers: Trends and Recommendations. Forrester.https://go.forrester.com/report/progra m-managers-security-enablers
How to cite this paper
@article{1710083,
author = {Geetha Aradhyula},
title = {The Program Manager?s Role in Cyber Security},
journal = {Iconic Research And Engineering Journals},
year = {2025},
volume = {9},
number = {2},
pages = {354-362},
issn = {2456-8880},
url = {https://www.irejournals.com/formatedpaper/1710083.pdf},
abstract = {As cyber threats evolve in complexity and frequency, cybersecurity has become a pivotal concern across organizations. While technical specialists often receive most attention, the Program Manager (PM) has emerged as equally critical in ensuring robust cybersecurity governance. PMs align cybersecurity initiatives with organizational goals, translating technical risks into business-relevant insights for executive leadership (Associated Press, 2025). They oversee program implementation?ensuring delivery on time, within budget, and in compliance with frameworks such as NIST, GDPR, HIPAA, or ISO-27001 (Associated Press, 2025; University of Tennessee, 2024). Moreover, PMs act as the bridge between cybersecurity teams and non-technical stakeholders, facilitating communication and coordination to enhance cyber resilience across departments (McKesson, 2025; University of Tennessee, 2024). They are expected to possess a working knowledge of cybersecurity domains?such as vulnerability management, incident response, threat modeling, and supply-chain security?to anticipate and mitigate risks during project planning and execution (University of Tennessee, 2024; U.S. Department of Defense, 2023). With increasing digitization through cloud computing, IoT, and remote work, PMs lead cross-functional teams to build adaptive and resilient security frameworks, ensuring governance and compliance (McKesson, 2025; Edstellar, 2024). Through real-world case studies and best practices, PMs demonstrate their ability to minimize cybersecurity breaches, maintain regulatory compliance, and promote a culture of security awareness. In roles like the GDIT Cybersecurity Program Manager, PMs manage risk visibility, stakeholder collaboration, and strategic alignment to strengthen security postures and build trust across the organization (GDIT, 2025). In summary, effective Program Management is indispensable to organizational cybersecurity?making the PM not just an operational role, but a strategic leader in safeguarding digital assets and maintaining stakeholder trust in a hostile cyber landscape.},
keywords = {Cybersecurity leadership, Program management, Security integration, Business risk mitigation, Cross-functional alignment},
month = {August},
}