7+ years IT program/project management, audit, risk, or compliance5+ years leading multi-workstream programsAgile / Waterfall / Hybrid methodologiesNIST CSF / NIST SP 800-53GRC & audit liaison experiencePolicy lifecycle managementEvidence & audit managementAuditBoard & SharePointSOC / PCI / FFIEC familiarityCybersecurity & IT auditing knowledgeBachelor's degree in Business, IS, or related fieldPMP certificationCISA / CRISC / CISSP / CIA / CGEIT
Job Description
Lennar seeks a Security Program Manager to lead and manage the enterprise assurance program, overseeing policy lifecycle management, evidence collection, and audit responses aligned with NIST Cybersecurity Framework controls. The role involves coordinating multi-workstream initiatives, maintaining policy and evidence libraries, serving as liaison to audit teams, and reporting to the Director of Resilience and Security Services.
Overview
Lennar is one of the nation's leading homebuilders, dedicated to making an impact and creating an extraordinary experience for their Homeowners, Communities, and Associates by building quality homes and providing exceptional customer service. Lennar has been recognized as a Fortune 500 company and consistently ranked among the top homebuilders in the United States.
Role Summary
Lennar has an opportunity for a Security Program Manager within the Resilience and Security Services organization, working in close partnership with Security, primarily comprised of Governance, Risk, and Compliance (GRC) and Privacy. This role runs the enterprise program that keeps Lennar's NIST Cybersecurity Framework (CSF) controls backed by clear, current policy and verifiable evidence of adherence. The role reports directly to the Director, Resilience and Security Services.
The Security Program Manager is Lennar's primary point of contact for internal and external audit engagements and regulatory inquiries, and the trusted advisor to the federation of control owners across Lennar IT who author and maintain policy. This is a program management role at its core: setting the annual cadence, managing cross-functional workstreams, and holding every deliverable, policy review, evidence request, and audit response to a disciplined program plan.
Responsibilities
•Lead and manage the enterprise assurance program as a structured, multi-workstream initiative, applying disciplined program and project management practices (Agile, Waterfall, or hybrid) to keep every deliverable on time and within scope.
•Build and maintain the year-long assurance calendar, aligning evidence-gathering activity, policy reviews, and audit response with Lennar's regulatory and audit calendars.
•Own the enterprise policy library: maintain an accurate, current inventory of every policy tied to an enforced NIST CSF control, manage the policy lifecycle on an annual review cadence, and read every policy closely for clarity, completeness, and fidelity to the intent of the underlying control.
•Design and maintain the standard process flow that governs how a policy moves from draft through review, giving control owners a clear, repeatable path to a compliant policy.
•Own the evidence library: ensure evidence is properly cataloged, stored, and retrievable, and that evidence approaching the end of its one-year validity window is refreshed before it expires.
•Serve as Lennar's primary liaison to internal and external audit teams and regulatory bodies, leading the response to audit and regulatory evidence requests with a service-oriented, no-surprises approach.
•Partner directly with control and policy owners across the LTG federation, providing patient, constructive guidance and facilitating solution-oriented working sessions.
•Lead the evaluation and selection of the system(s) of record for the policy and evidence libraries, anticipated to be a combination of SharePoint and AuditBoard.
•Identify and help assess security and compliance risks surfacing from policy gaps, control weaknesses, or stale evidence, applying working knowledge of relevant frameworks (NIST CSF, SOC, PCI, FFIEC) to escalate substantive issues.
•Communicate program status, risks, and issues to stakeholders and senior management, including VP/SVP-level leadership, in clear, concise, executive-ready formats.
•Mentor and guide program contributors, including a proposed Security Analyst II role, fostering a culture of continuous improvement and disciplined execution.
•Analyze multi-domain assurance trend data, including audit findings, evidence turnaround, and policy currency, to institutionalize process fixes and improve reliability at scale.
•Maintain the assurance program's source of truth in Lennar's management platforms, ensuring all artifacts meet global security and audit control standards.
•Define program requirements by managing milestones, forming working teams with control owners, and establishing budgets where applicable; monitor progress by tracking activity, resolving problems, and publishing progress reports.
Requirements
•7+ years of professional experience spanning IT project/program management, audit, risk, compliance, or governance, including at least 5 years leading multi-workstream projects or programs.
•Proven program/project management discipline: experience with Agile (Scrum, XP), Waterfall/Predictive, and hybrid methodologies; PMP certification preferred.
•Extremely detail-oriented and hyper-organized, comfortable owning a portfolio of concurrent, time-sensitive deliverables without dropping a thread.
•Experience interacting with internal or external audit teams, with a service-oriented mindset and the presence to represent Lennar credibly in audit and regulatory conversations.
•Demonstrated ability to read, interpret, and translate the intent of a policy into practical guidance for control owners.
•Working knowledge of the NIST Cybersecurity Framework (CSF) and NIST SP 800-53 control families, or a comparable enterprise control framework; familiarity with SOC, PCI, and FFIEC compliance requirements is a strong plus.
•Additional insight into cybersecurity and IT auditing, including security risk and vulnerability identification, is a major plus.
•Experience selecting, implementing, or administering security and document management platforms; direct experience with AuditBoard and SharePoint preferred.
•Exceptional written and verbal communication skills, with an emphasis on facilitating solution-oriented meetings and briefing VP/SVP-level stakeholders.
•Bachelor's degree in Business, Information Systems, Risk Management, or a related field; Master's degree preferred, or equivalent experience.
•Certifications a plus: PMP, CISA, CRISC, CIA, CGEIT, CISSP, or equivalent.
Benefits
•Comprehensive health insurance plans including Medical, Dental, and Vision coverage.
•401(k) Retirement Plan with a dollar-for-dollar company match up to 5%.
•Paid Parental Leave and an Associate Assistance Plan.
•Education Assistance Program and up to $30,000 in Adoption Assistance.
•Up to three weeks of vacation annually from date of hire, plus Holiday, Sick Leave, and Personal Day policies.
•New Hire Referral Bonus Program and significant Home Purchase Discounts.
Resume Intelligence
Assess your experience against this job and tailor your bullet points instantly.
Sign in required
Please sign in to assess your resume alignment and generate custom copyable work bullets.