# Technical Program Manager

**Company:** [Taskrabbit](https://hotfix.jobs/companies/taskrabbit)
**Location:** San Francisco, CA
**Role:** Technical Program Management
**Salary:** $87k – $120k/yr
**Experience:** 3+ years
**Skills:** Technical Program Management, cis controls, soc2, Jira, Vulnerability Management, Cloud Infrastructure, SRE, infosec, wiz, hackerone, Datadog, Okta, GRC
**Posted:** 2026-06-25

> Technical Program Manager owning infrastructure and security compliance programs (CIS IG1, vulnerability management, intake governance). Drive cross-functional coordination, SLAs, audits, and operational processes so engineers can focus on implementation. Requires 3+ years TPM experience in security/infra environments and strong technical depth.

## Job Description

## Compliance & Security Program Ownership
- Own the end-to-end CIS IG1 program: intake, evidence collection, SLA enforcement, and periodic review cycles across all 18 control families
- Expand CIS controls from local engineering teams to the entire company, and build the roadmap for IG2 and IG3
- Maintain the CIS Crosswalk Tracker as a living record of audit readiness and control status
- Translate technical controls into actionable Jira workflows and enforceable remediation SLAs
- Manage the annual external Penetration Test program and track remediation of findings to closure

## Governance & Intake
- Design and operate a centralized intake process for security and infrastructure requests, ensuring engineers work only on vetted, prioritized work
- Standardize access-granting workflows for new hires, role changes, and tool requests—with full audit trails
- Establish and enforce SLAs for vulnerability remediation, PR reviews, and ticket response; report compliance to leadership

## Stakeholder & Cross-Functional Orchestration
- Serve as the primary interface between Engineering, Security, Legal, Finance, IT, and Procurement for security-related programs, vendor reviews, and audits
- Negotiate infrastructure and security work into team sprints; manage GIVE/GET dependency tracking with Engineering Directors
- Drive policy approvals and company-wide rollouts (e.g., Data Management, Secure Configuration, Access Control) from draft to operationalized and signed-off

## Operational Excellence (Run the Business)
- Operationalize recurring compliance work: quarterly access reviews, monthly vulnerability triage, bi-annual asset inventory updates, annual vendor reassessments, and tabletop BCP exercises
- Build and maintain dashboards and automated evidence pipelines to reduce manual compliance chores
- Report security posture, key metrics, and a "Security Score" to senior leadership in clear, business-readable terms
- Lead the BCP program: standardize templates, schedule tabletop exercises, document results, and drive remediation into engineering sprints

## Incident & Vulnerability Program Management
- Scale vulnerability management from local triage to a company-wide SLA-driven program using Wiz, HackerOne, and Jira
- Own the SLA—chasing teams to close critical findings within 7 days and reporting Days-to-Patch to leadership
- Manage the phishing response playbook and incident post-mortem process; ensure P0/P1 action items land in sprint

## Required Experience
- 3+ years of technical program management in an infrastructure, security, SRE, or compliance environment
- Demonstrated ability to translate security controls (e.g., CIS, SOC2) into actionable Jira workflows, SLAs, and repeatable operational processes
- Proven track record driving company-wide, cross-departmental initiatives through to completion—including securing stakeholder sign-offs and managing organizational resistance
- Experience operationalizing run-the-business processes: access reviews, vulnerability remediation tracking, audit evidence collection, and periodic compliance reviews
- Sufficient technical depth in cloud infrastructure, SRE, and infosec to coordinate credibly with engineers and translate findings for non-technical leaders
- Strong executive communication skills—able to synthesize technical risk into a business-readable security score and status report
- End-to-end program ownership: from intake governance and dependency tracking through leadership reporting

## Nice to Haves
- Familiarity with CIS Controls v8.1 and the IG1/IG2/IG3 framework
- Hands-on exposure to tools in our stack: Wiz, HackerOne, CrowdStrike, Datadog, Okta, JAMF, or KnowBe4
- Experience supporting SOC2 or PCI audits
- Jira workflow and dashboard configuration experience
- Background in GRC (Governance, Risk, and Compliance) or security program management
- Experience working in an organization operating under a parent- or partner-company compliance context

## Compensation & Benefits
Total compensation consists of base pay + annual bonus + benefits + perks. The base pay range for this position is $87,000 - $120,000.

## Similar roles

- [Implementation Manager I](https://hotfix.jobs/jobs/52662843-0251-49e9-8466-79ab0c0ffed4) - SmithRx - Remote - $88k – $124k/yr
- [Project Manager, Fleet Asset Management](https://hotfix.jobs/jobs/85ceced0-5169-4212-9b7a-441c6271a546) - Shield AI - Dallas, TX - $88k – $130k/yr
- [Project Manager, Demo (R4836)](https://hotfix.jobs/jobs/f017a089-2b19-4c50-bcc8-9914ced33f53) - Shield AI - Dallas, TX - $88k – $130k/yr
- [Program Manager, Claude Corps](https://hotfix.jobs/jobs/47ec0ea9-69dc-4bbd-8d29-e071c2f2117b) - CodePath - Remote - $85k – $110k/yr
- [Technical Project Manager](https://hotfix.jobs/jobs/1fd951ad-9ea1-43e3-abe5-187de55b22ef) - Vibes - Chicago, IL - $90k – $100k/yr

**Apply:** https://hotfix.jobs/jobs/56fa7384-4122-4268-9fe0-22242c69e6bc
**Canonical:** https://hotfix.jobs/jobs/56fa7384-4122-4268-9fe0-22242c69e6bc