Change Manager
harvey nashSeattle (WA)
About the role
Client is looking for someone who has personally delivered cybersecurity change, can bring lessons from comparable programs, and has the executive presence to advise senior security and IT leaders. This is a role for a practitioner who can move between risk discussions, implementation details, and employee adoption.
Key responsibilities:
Build and execute a change management plan for cybersecurity changes affecting teams across the Foundation. Partner with security and IT leaders to understand the seven risks, associated controls, implementation priorities, and decisions employees will need to act on. Assess how new or revised controls will affect employee workflows, access to systems, use of information, and use of tools, including AI tools where relevant. Identify affected groups, sponsors, dependencies, and likely barriers to adoption. Advise senior leaders on change readiness, rollout risks, employee impact, and decisions needed to support implementation. Develop clear communications, leader guidance, training, and support materials tailored to different audiences. Coordinate with technical teams so employee guidance reflects how controls and systems actually work. Gather feedback during rollout, address adoption issues, and measure whether the intended practices are being followed. Share progress and recommendations with cybersecurity and IT leadership.
Required experience:
Demonstrated experience leading the rollout and adoption of cybersecurity controls or security-related technology changes across a complex organization. Practical understanding of cybersecurity risk and how security controls affect systems, data, access, and employee behavior. Examples of working directly with security and IT leaders to turn technical decisions into workable organizational changes. Strong executive communication skills, including the ability to present concerns and recommendations to senior leaders. Experience creating and delivering change plans, stakeholder engagement, communications, training, and adoption measures. Ability to work through ambiguity and make progress while technical decisions and priorities evolve. Strong candidates will be able to explainA cybersecurity change they personally led, the risk it addressed, and what they did to achieve adoption. How they handled employee resistance or friction caused by a new security control. How they worked with technical teams to ensure communications and training matched the actual system behavior. What they measured to determine whether the change reduced risk and became part of everyday work.
What success looks like:
Senior security and IT leaders have a credible partner who can challenge assumptions, explain employee impact, and guide rollout decisions. Employees understand the new expectations and can follow them in their daily work. The Foundation can see whether the changes associated with risks and controls have been adopted and where further support is needed.
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
