Security Technical Program Manager
Own the definition and delivery of Gusto's vulnerability management and security operations programs. Drive centralized vulnerability scorecard, expand detection coverage, harden SDLC, and deliver security metrics while using AI plugins to accelerate delivery across Security, Infrastructure, and GRC teams.
About the job
Responsibilities
- Set the strategy and roadmap for vulnerability management and security operations as Gusto becomes an AI-native company.
- Define what good vulnerability management and security operations look like for an AI-first business.
- Run intake and prioritization with senior stakeholders.
- Lead delivery of the centralized vulnerability management program: coverage across code, cloud, data, and edge; CSPM/DSPM, container scanning, dependency and secrets detection, and owner-based remediation routing to closure.
- Lead security operations delivery: expand high-risk detection and alerting across systems and vendors, impersonation and privileged-access logging, SIEM integration, insider-risk telemetry, and logging of agentic activity.
- Stand up the daily security-health and vulnerability-management metrics dashboards leadership uses to run the business, and drive monthly vulnerability reporting.
- Build security workflows that run on AI plugins by default.
- Build the plans, manage scope and risk, track milestones, and deliver against every audit and regulatory commitment.
- Roll out new controls, like risk-scored PR review, JIT privileged access, and secrets management.
- Manage stakeholders and vendors, hold them to commitments, watch program budget, tooling spend, and implementation costs.
Requirements
- History of taking programs from ambiguous to shipped in regulated environments.
- 5 to 8+ years leading cross-functional TPM or delivery work, with real time spent on security, infrastructure, or platform engineering.
- Solid handle on vulnerability management and security operations, from scanning coverage and remediation SLAs to detection engineering, SIEM/monitoring, and identity and privileged access.
- Way of working where AI plugins drive everyday delivery.
- Ability to speak the language of security engineering, infrastructure, GRC, and R&D.
Nice-to-Haves
- Familiarity with the modern security stack, including vulnerability and asset scanners (e.g., Wiz, Axonius), code security (dependency and secret scanning), SIEM/detection (e.g., Panther), and identity/JIT access (e.g., Opal).
- Hands-on experience using AI clients and plugins (MCPs) to generate program artifacts.
- Working knowledge of control frameworks like SOC 1/2 and ISO 27001, plus secure SDLC practices.
- PM certification (PMP, CAPM, Scrum, or Prosci).
- Time spent in high-growth fintech or another regulated, fast-paced industry.
Compensation
- Cash compensation targeted at $138,000-156,000 in Denver and $168,000–189,000 in the San Francisco Bay Area. Stock equity is additional.
Skills
Vulnerability Management, Security Operations, SIEM, Cspm, Dspm, Container Scanning, Dependency Scanning, Secrets Detection, Privileged Access Management, Jit Access, Secure Sdlc, SOC 2, ISO 27001, Ai Plugins, Wiz
Similar jobs
Technical Program Management jobsLeads cross-functional delivery of AI/ML solutions for national security customers, combining technical program management, stakeholder leadership, analytics, and customer success. Requires an active TS/SCI clearance, generative AI/ML fluency, and regular work at a cleared Boston-area facility.
Leads cross-functional delivery of AI/ML solutions and agentic workflows for public sector and national security customers. Requires technical program management, stakeholder leadership, generative AI expertise, an active TS/SCI clearance, and customer-facing problem-solving experience.
Design Program Manager establishing operating systems, planning processes, readiness standards, and reporting for a product design team building AI-powered litigation tools. Requires 5+ years in design program management or operations, strong cross-functional coordination, and experience with Figma and Jira.
Leads complex cross-functional technology programs, managing dependencies, risks, technical alignment, and delivery practices across business and technology teams. Requires 5+ years of program or project management experience in a cloud/SaaS environment and strong collaboration skills.
Leads technical alignment and operational programs across Engineering by coordinating roadmaps, dependencies, and stakeholders while building automation, self-service tools, and business intelligence workflows. Requires technical program management experience, software engineering knowledge, Python, and familiarity with engineering and data platforms.