Cyber Technical Program Manager

Eli Lilly Eli Lilly · Pharma · Indianapolis, IN · Remote

This role is for a Cyber Technical Program Manager at Eli Lilly, focusing on managing cybersecurity programs that address current and emerging threats, including those related to AI. The role requires deep understanding of cybersecurity domains, attacker TTPs, and the ability to drive program execution, manage risks, and communicate technical concepts to various stakeholders. It involves understanding threats like AI supply chain risks, identity exploitation, and attack surface management, and applying knowledge of regulatory frameworks.

What you'd actually do

  1. You will own programs end-to-end, challenge assumptions, surface risks, and hold technical teams accountable to outcomes.
  2. You will embed in the work alongside security engineers, architects, and Cyber leaders to bring structure to complex delivery, and translate program health into executive-ready intelligence for Cyber leadership.
  3. Develop and own program charters grounded in the cyber context driving each initiative as well as business requirements.
  4. Drive gate-validated execution through the program lifecycle, ensuring planning rigor, resource readiness, dependency resolution, and architecture review before execution begins.
  5. Own assigned programs through the full lifecycle: intake, charter, detailed planning, execution, and closeout with rigor and accountability at each stage.

Skills

Required

  • Cybersecurity program management
  • Technical program management
  • Risk management
  • Stakeholder management
  • Communication skills
  • Understanding of attacker TTPs
  • Knowledge of AI-related cybersecurity threats (prompt injection, data poisoning, supply chain risks)
  • Identity and access management
  • Cloud security architecture
  • Network security
  • Application security
  • Security operations
  • NIST CSF
  • MITRE ATT&CK
  • Zero Trust principles
  • Regulatory frameworks (FDA, GxP, SOX, HIPAA, GDPR, PCI)

Nice to have

  • Experience with Mythos-class threats

What the JD emphasized

  • genuine technical depth across security domains
  • understand the adversarial context driving each program
  • AI supply chain and model integrity threats
  • prompt injection
  • data poisoning in enterprise AI deployments
  • identity and privilege exploitation
  • enterprise attack surface expansion
  • threat-informed risks
  • Engage directly with threat intelligence, red team, and detection engineering teams
  • Maintain fluency in current and emerging threat actor behaviors
  • AI-augmented adversarial techniques
  • Mythos-class actors
  • applicable regulatory frameworks (FDA cybersecurity guidance, GxP, SOX, HIPAA, GDPR, PCI)