Skip to content
TaskrabbitTaskrabbitSan Francisco, CA

Technical Program Manager

Technical Program Manager owning infrastructure and security compliance programs (CIS IG1, vulnerability management, intake governance). Drive cross-functional coordination, SLAs, audits, and operational processes so engineers can focus on implementation. Requires 3+ years TPM experience in security/infra environments and strong technical depth.

87k – 120k/yr
Hybrid3+ YOETechnical Program Management

About the role

Compliance & Security Program Ownership

  • Own the end-to-end CIS IG1 program: intake, evidence collection, SLA enforcement, and periodic review cycles across all 18 control families
  • Expand CIS controls from local engineering teams to the entire company, and build the roadmap for IG2 and IG3
  • Maintain the CIS Crosswalk Tracker as a living record of audit readiness and control status
  • Translate technical controls into actionable Jira workflows and enforceable remediation SLAs
  • Manage the annual external Penetration Test program and track remediation of findings to closure

Governance & Intake

  • Design and operate a centralized intake process for security and infrastructure requests, ensuring engineers work only on vetted, prioritized work
  • Standardize access-granting workflows for new hires, role changes, and tool requests—with full audit trails
  • Establish and enforce SLAs for vulnerability remediation, PR reviews, and ticket response; report compliance to leadership

Stakeholder & Cross-Functional Orchestration

  • Serve as the primary interface between Engineering, Security, Legal, Finance, IT, and Procurement for security-related programs, vendor reviews, and audits
  • Negotiate infrastructure and security work into team sprints; manage GIVE/GET dependency tracking with Engineering Directors
  • Drive policy approvals and company-wide rollouts (e.g., Data Management, Secure Configuration, Access Control) from draft to operationalized and signed-off

Operational Excellence (Run the Business)

  • Operationalize recurring compliance work: quarterly access reviews, monthly vulnerability triage, bi-annual asset inventory updates, annual vendor reassessments, and tabletop BCP exercises
  • Build and maintain dashboards and automated evidence pipelines to reduce manual compliance chores
  • Report security posture, key metrics, and a "Security Score" to senior leadership in clear, business-readable terms
  • Lead the BCP program: standardize templates, schedule tabletop exercises, document results, and drive remediation into engineering sprints

Incident & Vulnerability Program Management

  • Scale vulnerability management from local triage to a company-wide SLA-driven program using Wiz, HackerOne, and Jira
  • Own the SLA—chasing teams to close critical findings within 7 days and reporting Days-to-Patch to leadership
  • Manage the phishing response playbook and incident post-mortem process; ensure P0/P1 action items land in sprint

Required Experience

  • 3+ years of technical program management in an infrastructure, security, SRE, or compliance environment
  • Demonstrated ability to translate security controls (e.g., CIS, SOC2) into actionable Jira workflows, SLAs, and repeatable operational processes
  • Proven track record driving company-wide, cross-departmental initiatives through to completion—including securing stakeholder sign-offs and managing organizational resistance
  • Experience operationalizing run-the-business processes: access reviews, vulnerability remediation tracking, audit evidence collection, and periodic compliance reviews
  • Sufficient technical depth in cloud infrastructure, SRE, and infosec to coordinate credibly with engineers and translate findings for non-technical leaders
  • Strong executive communication skills—able to synthesize technical risk into a business-readable security score and status report
  • End-to-end program ownership: from intake governance and dependency tracking through leadership reporting

Nice to Haves

  • Familiarity with CIS Controls v8.1 and the IG1/IG2/IG3 framework
  • Hands-on exposure to tools in our stack: Wiz, HackerOne, CrowdStrike, Datadog, Okta, JAMF, or KnowBe4
  • Experience supporting SOC2 or PCI audits
  • Jira workflow and dashboard configuration experience
  • Background in GRC (Governance, Risk, and Compliance) or security program management
  • Experience working in an organization operating under a parent- or partner-company compliance context

Compensation & Benefits

Total compensation consists of base pay + annual bonus + benefits + perks. The base pay range for this position is $87,000 - $120,000.

Skills

Technical Program Managementcis controlssoc2JiraVulnerability ManagementCloud InfrastructureSREinfosecwizhackeroneDatadogOktaGRC
SmithRx

Implementation Manager I

SmithRxUnited States

Coordinates end-to-end client implementations, including requirements, project planning, cross-functional delivery, issue resolution, and go-live support. Requires a bachelor’s degree or equivalent experience, 5–8 years of related experience, and strong communication and problem-solving skills.

88k – 124k/yrRemote5+ YOETechnical Program Management
Shield AI

Project Manager, Fleet Asset Management

Shield AIDallas, TX

Manages fleet configuration updates and retrofit projects for V-BAT unmanned systems, coordinating across Engineering, Logistics, and Operations to maintain configuration integrity.

88k – 130k/yrOn-siteTechnical Program Management
Shield AI

Project Manager, Demo (R4836)

Shield AIDallas, TX

Drive planning, coordination, and execution of complex demonstration programs and sustainment logistics for unmanned aerial systems. Manage schedules, budgets, risks, customer support, regulatory compliance, and cross-functional teams to ensure on-time, high-impact technology deployments.

88k – 130k/yrOn-site4+ YOETechnical Program Management
CodePath

Program Manager, Claude Corps

CodePathUnited States

Own the master program plan, drive cross-functional alignment, and build scalable systems for Claude Corps, a national AI fellowship placing fellows at nonprofits. Requires 3+ years managing complex multi-stakeholder programs, entrepreneurial experience, exceptional communication, and AI-first operations.

85k – 110k/yrRemote3+ YOETechnical Program Management
Vibes

Technical Project Manager

VibesChicago, IL

Own 15-20 concurrent client-facing technical delivery projects for Vibes' Professional Services team. Manage scope, timelines, budgets, stakeholders, Jira workflows, financial tracking, and cross-functional coordination between clients, developers, TAMs, CS, Sales, and Finance.

90k – 100k/yrHybrid3+ YOETechnical Program Management