Kubota logo

Program Manager, Security & Privacy - Kubota Credit Corporation

Kubota
2 hours ago
Full-time
On-site
Grapevine, Texas, United States
Manager

For Earth For Life

Weekly onsite required a few days a week - Grapevine TX. 

This position is not fully remote. 

 

The Program Manager, Security & Privacy position is an individual contributor on the Kubota Credit Corporation Security & Privacy team, reporting to the Security & Privacy Manager.  

This role owns both the product management function and Agile delivery execution for the Security & Privacy program, operating across security operations, privacy compliance, and governance, risk & compliance (GRC) domains.

In the product management capacity, this role maintains and prioritizes the Security & Privacy program backlog, translating regulatory obligations, control gaps, and audit findings into actionable initiatives, and owns the program roadmap from intake through closure, ensuring alignment with NYDFS CYRR Part 500, CCPA, and KCC’s broader risk posture.  In the Agile delivery capacity, this role serves as servant-leader for Security & Privacy delivery services, facilitating ceremonies, removing impediments, and driving Kanban execution with rigor and transparency.

The ideal candidate combines strategic program ownership with hands-on Agile facilitation expertise, is versed in regulatory and compliance contexts, and brings the analytical discipline to translate complex, cross-functional security and privacy requirements into well-structured, Jira-ready work that the program owners can execute with confidence.

KEY RESPONSIBILITIES

This position does the following in accordance with all applicable Federal, State and local laws / regulations and the Company’s policies, procedures and guidelines:

Program & Product Management

  • Own and maintain the Security & Privacy program backlog, translating requirements, audit and penetration test findings, risk register items, and privacy compliance obligations into clearly scoped, prioritized initiatives with defined acceptance criteria and measurable outcomes.
  • Develop and manage the Security & Privacy program roadmap, partnering with the Manager, Security & Privacy, risk owners, KCC-IT, and business stakeholders to sequence initiatives against regulatory deadlines, remediation commitments, and resource capacity.
  • Lead initiative planning from intake through closure: defining objectives, success metrics, scope, resource alignment, dependencies, and timelines, ensuring each initiative maps to an organizational or regulatory outcome.
  • Prepare and lead status updates, briefings, and decision forums, producing clear reporting on program performance, and open risks with recommendations.
  • Support capacity planning across the Security & Privacy portfolio, partnering with KCC-IT leadership and delivery leads to balance demand, prioritizing remediation stories, and sequence compliance initiatives against operational security work.
  • Identify, escalate, and manage program-level risks and issues; maintain risk logs and dependency maps; drive resolutions with clear ownership and documented outcomes.

Agile Delivery & Facilitation

  • Facilitate daily standups, sprint planning, sprint reviews and demos, and retrospectives for Security & Privacy delivery squads; ensure ceremonies are purposeful, time-efficient, and outcome-oriented.
  • Partner with security product owners and control owners to structure and maintain healthy backlogs, ensuring work items, including remediation stories, compliance initiatives, and security architecture tasks that are well-defined, estimated, and prioritized.
  • Design, configure, and maintain Jira projects, kanban boards, workflows for Security & Privacy delivery.
  • Monitor and report on team delivery metrics and produce clear sprint and release reporting; leverage data-informed insights to drive continuous improvement in delivery practices.
  • Identify and remove impediments across technical, organizational, and vendor dimensions; coordinate with KCC-IT delivery teams, and affiliate partners to unblock work, escalate with clear context when required.
  • Provide the Manager of Cybersecurity & Privacy with timely, data-informed visibility into delivery progress, risks, dependencies, and compliance milestone status to support reporting and executive-level communication.

Governance, Compliance & Responsible Tool Use

  • Ensure Security & Privacy program artifacts, including Jira stories, remediation evidence, and status reports, and meet documentation standards required to support NYDFS CYRR Part 500 examinations, internal audits, and regulatory submissions.
  • Support governance over security program documentation, ensuring policy and procedure documentation, runbooks, and control evidence libraries are current, version-controlled, and audit-ready.
  • Leverage AI and standard productivity tools to improve personal effectiveness and delivery outcomes, including streamlining portfolio reporting, automating sprint metrics, and enhancing governance workflows.
  • Uphold safe and policy-compliant use of AI and data in day-to-day program work, ensuring human judgment remains central to prioritization and risk decisions.
  • Other duties as assigned.

 

QUALIFICATIONS

  • Bachelor’s degree from an accredited institution in Information Systems, Business, Computer Science, or a related discipline, with 5 years of professional experience in program or project management, Agile delivery, or a related function.
  • 5 years of experience in cybersecurity, privacy, GRC, or technology risk context, with direct exposure to regulatory compliance programs (NYDFS CYRR Part 500, CCPA, or equivalent).
  • Proven ability to manage both strategic program ownership and hands-on Agile facilitation concurrently, with demonstrated experience in both capacities on security or compliance-related workstreams.
  • Hands-on Jira Cloud experience, including project configuration, workflow design, dashboard creation, and reporting, proficiency with Confluence for documentation and knowledge management.
  • Strong analytical and problem-solving skills, able to synthesize complex regulatory, technical, and operational inputs into clear program priorities and actionable delivery plans.
  • Excellent facilitation, listening, and written communication skills, with the ability to translate security and compliance concepts for executive, business, and technical audiences.
  • Ability to maintain discretion and handle highly sensitive information, including NPI, audit findings, incident records, and regulatory correspondence, in compliance with applicable policies and regulations.
  • Demonstrated ability to leverage AI and standard productivity tools to improve personal effectiveness and team delivery outcomes, with a clear understanding of appropriate boundaries in regulated environments.
  • Familiarity with risk management and governance requirements for tools and data in regulated financial services environments.

 

PHYSICAL REQUIREMENTS

  • Requires sufficient personal mobility and physical reflexes, to permit the employee to function in a general office environment and accomplish tasks and duties as outlined above.

 

DISCLAIMER:

The information provided in the description has been designed to indicate the general nature and level of work performed by incumbents within the classification.  This description is not intended to be a comprehensive inventory of all duties, responsibilities, qualifications and working conditions required of employees assigned to this job/classification.  This job is intended to include the current essential functions of the job.  Management reserves the right to add or modify the duties and responsibilities and to designate other functions as essential at any time.

 Kubota is an equal opportunity at will employer and does not discriminate against any employee or applicant for employment because of age, race, religion, color, disability, sex, sexual orientation or national origin.