Skip to content
GustoGustoDenver, CO

Security Technical Program Manager

Own the definition and delivery of Gusto's vulnerability management and security operations programs. Drive centralized vulnerability scorecard, expand detection coverage, harden SDLC, and deliver security metrics while using AI plugins to accelerate delivery across Security, Infrastructure, and GRC teams.

138k – 189k/yr
Hybrid5+ YOETechnical Program Management

About the role

Responsibilities

  • Set the strategy and roadmap for vulnerability management and security operations as Gusto becomes an AI-native company.
  • Define what good vulnerability management and security operations look like for an AI-first business.
  • Run intake and prioritization with senior stakeholders.
  • Lead delivery of the centralized vulnerability management program: coverage across code, cloud, data, and edge; CSPM/DSPM, container scanning, dependency and secrets detection, and owner-based remediation routing to closure.
  • Lead security operations delivery: expand high-risk detection and alerting across systems and vendors, impersonation and privileged-access logging, SIEM integration, insider-risk telemetry, and logging of agentic activity.
  • Stand up the daily security-health and vulnerability-management metrics dashboards leadership uses to run the business, and drive monthly vulnerability reporting.
  • Build security workflows that run on AI plugins by default.
  • Build the plans, manage scope and risk, track milestones, and deliver against every audit and regulatory commitment.
  • Roll out new controls, like risk-scored PR review, JIT privileged access, and secrets management.
  • Manage stakeholders and vendors, hold them to commitments, watch program budget, tooling spend, and implementation costs.

Requirements

  • History of taking programs from ambiguous to shipped in regulated environments.
  • 5 to 8+ years leading cross-functional TPM or delivery work, with real time spent on security, infrastructure, or platform engineering.
  • Solid handle on vulnerability management and security operations, from scanning coverage and remediation SLAs to detection engineering, SIEM/monitoring, and identity and privileged access.
  • Way of working where AI plugins drive everyday delivery.
  • Ability to speak the language of security engineering, infrastructure, GRC, and R&D.

Nice-to-Haves

  • Familiarity with the modern security stack, including vulnerability and asset scanners (e.g., Wiz, Axonius), code security (dependency and secret scanning), SIEM/detection (e.g., Panther), and identity/JIT access (e.g., Opal).
  • Hands-on experience using AI clients and plugins (MCPs) to generate program artifacts.
  • Working knowledge of control frameworks like SOC 1/2 and ISO 27001, plus secure SDLC practices.
  • PM certification (PMP, CAPM, Scrum, or Prosci).
  • Time spent in high-growth fintech or another regulated, fast-paced industry.

Compensation

  • Cash compensation targeted at $138,000-156,000 in Denver and $168,000–189,000 in the San Francisco Bay Area. Stock equity is additional.

Skills

Vulnerability Managementsecurity operationsSIEMcspmdspmcontainer scanningdependency scanningsecrets detectionprivileged access managementjit accesssecure sdlcSOC 2ISO 27001ai pluginswiz
Skydio

Program Manager

SkydioNew York, NY

Lead implementation and delivery for Law Enforcement customers as a customer-facing Program Manager. Manage cost, schedule, technical execution, and risk while translating requirements to engineering teams.

140k – 175k/yr
RemoteTechnical Program Management
Axle

Clinical Program Manager

AxleBethesda, MD

Oversee and coordinate complex clinical research portfolios for the National Cancer Institute at NIH. Manage timelines, budgets, regulatory compliance, risks, and stakeholder communications for multi-center trials.

140k – 150k/yr
On-site5+ YOETechnical Program Management
Limble

Agile Delivery Manager

LimbleCharlotte, NC

Agile Delivery Manager scaling engineering delivery for a growing SaaS company (~45 engineers). Own JIRA as source of truth, track flow metrics, coach agile ceremonies, manage regulated release processes, and drive visibility with a servant-leader mindset. Requires 4+ years experience, JIRA admin expertise, and regulated environment background.

140k – 150k/yr
Remote4+ YOETechnical Program Management
Eightsleep

Engineering Program Manager, Hardware

EightsleepSan Francisco, CA

Lead hardware product development programs from concept to mass production at Eight Sleep. Requires 3+ years program management experience, engineering degree, and track record of successful product launches. Onsite in San Francisco.

140k – 230k/yr
On-site3+ YOETechnical Program Management
CodePath

Engineering Project and QA Manager

CodePathUnited States

Manage engineering projects, own QA testing and bug pipelines, and serve as the bridge between engineers, product, and internal teams at CodePath's small engineering organization building their learner platform. Requires 4+ years PM/QA experience, technical debugging skills, and comfort in ambiguous small-team settings.

140k – 178k/yr
Remote4+ YOETechnical Program Management