Technical Program Manager owning infrastructure and security compliance programs (CIS IG1, vulnerability management, intake governance). Drive cross-functional coordination, SLAs, audits, and operational processes so engineers can focus on implementation. Requires 3+ years TPM experience in security/infra environments and strong technical depth.
87k – 120k/yr
Hybrid3+ YOETechnical Program Management
About the role
Compliance & Security Program Ownership
Own the end-to-end CIS IG1 program: intake, evidence collection, SLA enforcement, and periodic review cycles across all 18 control families
Expand CIS controls from local engineering teams to the entire company, and build the roadmap for IG2 and IG3
Maintain the CIS Crosswalk Tracker as a living record of audit readiness and control status
Translate technical controls into actionable Jira workflows and enforceable remediation SLAs
Manage the annual external Penetration Test program and track remediation of findings to closure
Governance & Intake
Design and operate a centralized intake process for security and infrastructure requests, ensuring engineers work only on vetted, prioritized work
Standardize access-granting workflows for new hires, role changes, and tool requests—with full audit trails
Establish and enforce SLAs for vulnerability remediation, PR reviews, and ticket response; report compliance to leadership
Stakeholder & Cross-Functional Orchestration
Serve as the primary interface between Engineering, Security, Legal, Finance, IT, and Procurement for security-related programs, vendor reviews, and audits
Negotiate infrastructure and security work into team sprints; manage GIVE/GET dependency tracking with Engineering Directors
Drive policy approvals and company-wide rollouts (e.g., Data Management, Secure Configuration, Access Control) from draft to operationalized and signed-off
Build and maintain dashboards and automated evidence pipelines to reduce manual compliance chores
Report security posture, key metrics, and a "Security Score" to senior leadership in clear, business-readable terms
Lead the BCP program: standardize templates, schedule tabletop exercises, document results, and drive remediation into engineering sprints
Incident & Vulnerability Program Management
Scale vulnerability management from local triage to a company-wide SLA-driven program using Wiz, HackerOne, and Jira
Own the SLA—chasing teams to close critical findings within 7 days and reporting Days-to-Patch to leadership
Manage the phishing response playbook and incident post-mortem process; ensure P0/P1 action items land in sprint
Required Experience
3+ years of technical program management in an infrastructure, security, SRE, or compliance environment
Demonstrated ability to translate security controls (e.g., CIS, SOC2) into actionable Jira workflows, SLAs, and repeatable operational processes
Proven track record driving company-wide, cross-departmental initiatives through to completion—including securing stakeholder sign-offs and managing organizational resistance
Sufficient technical depth in cloud infrastructure, SRE, and infosec to coordinate credibly with engineers and translate findings for non-technical leaders
Strong executive communication skills—able to synthesize technical risk into a business-readable security score and status report
End-to-end program ownership: from intake governance and dependency tracking through leadership reporting
Nice to Haves
Familiarity with CIS Controls v8.1 and the IG1/IG2/IG3 framework
Hands-on exposure to tools in our stack: Wiz, HackerOne, CrowdStrike, Datadog, Okta, JAMF, or KnowBe4
Experience supporting SOC2 or PCI audits
Jira workflow and dashboard configuration experience
Background in GRC (Governance, Risk, and Compliance) or security program management
Experience working in an organization operating under a parent- or partner-company compliance context
Compensation & Benefits
Total compensation consists of base pay + annual bonus + benefits + perks. The base pay range for this position is $87,000 - $120,000.
Skills
Technical Program Managementcis controlssoc2JiraVulnerability ManagementCloud InfrastructureSREinfosecwizhackeroneDatadogOktaGRC
Coordinates end-to-end client implementations, including requirements, project planning, cross-functional delivery, issue resolution, and go-live support. Requires a bachelor’s degree or equivalent experience, 5–8 years of related experience, and strong communication and problem-solving skills.
88k – 124k/yrRemote5+ YOETechnical Program Management
Project Manager, Fleet Asset Management
Shield AIDallas, TX
Manages fleet configuration updates and retrofit projects for V-BAT unmanned systems, coordinating across Engineering, Logistics, and Operations to maintain configuration integrity.
88k – 130k/yrOn-siteTechnical Program Management
Project Manager, Demo (R4836)
Shield AIDallas, TX
Drive planning, coordination, and execution of complex demonstration programs and sustainment logistics for unmanned aerial systems. Manage schedules, budgets, risks, customer support, regulatory compliance, and cross-functional teams to ensure on-time, high-impact technology deployments.
88k – 130k/yrOn-site4+ YOETechnical Program Management
Program Manager, Claude Corps
CodePathUnited States
Own the master program plan, drive cross-functional alignment, and build scalable systems for Claude Corps, a national AI fellowship placing fellows at nonprofits. Requires 3+ years managing complex multi-stakeholder programs, entrepreneurial experience, exceptional communication, and AI-first operations.
85k – 110k/yrRemote3+ YOETechnical Program Management
Technical Project Manager
VibesChicago, IL
Own 15-20 concurrent client-facing technical delivery projects for Vibes' Professional Services team. Manage scope, timelines, budgets, stakeholders, Jira workflows, financial tracking, and cross-functional coordination between clients, developers, TAMs, CS, Sales, and Finance.
90k – 100k/yrHybrid3+ YOETechnical Program Management