# Senior Technical Program Manager, Security

**Company:** [Replit](https://hotfix.jobs/companies/replit)
**Location:** Foster City, CA
**Role:** Technical Program Management
**Salary:** $190k – $250k/yr
**Experience:** 6+ years
**Skills:** Technical Program Management, Vulnerability Management, bug bounty, gcp security, Cloud Security, SAST, DAST, sca, cvss, risk prioritization, Jira, Tableau, SOC 2, ISO 27001
**Posted:** 2026-07-31

> Own and improve Replit's end-to-end vulnerability management program across bug bounty, GCP cloud, code/supply chain, and SaaS vendors. Drive intake, triage, remediation, SLA compliance, reporting, and automation while partnering with engineering, security, and leadership teams.

## Job Description

## What you'll do

**Program Ownership:** Own and continuously improve the vulnerability management program, including intake, severity scoring (CVSS/risk-based), SLA definition, and remediation tracking across all asset types.

**Bug Bounty Operations:** Manage the triage/payouts/rewards workflow, and report on program health and trends.

**Cloud Remediation (GCP):** Drive remediation of vulnerabilities found in GCP infrastructure — IAM, networking, Compute/GKE, storage, and logging/monitoring configuration — by partnering with security, cloud, and platform engineering teams.

**Code & Supply Chain Security:** Coordinate remediation of vulnerabilities surfaced through SAST/DAST/SCA tooling (Wiz Code, Snyk, Dependabot, code scanning, secret scanning) across engineering repos, including dependency and supply-chain risk.

**SaaS Vendor Risk:** Build and manage the process for assessing and tracking security posture across third-party SaaS applications.

**Escalation & Exceptions:** Define and enforce escalation paths for overdue or critical/high-severity findings, including risk acceptance and exception processes with appropriate sign-off.

**Cross-Team Accountability:** Partner with engineering managers and tech leads to embed remediation work into sprint planning and hold teams accountable to remediation SLAs.

**Reporting & Alerting:** Establish and maintain a single source of truth for vulnerability status, aging, SLA compliance, and risk trends, with dashboards for engineering leadership, security leadership, and executives.

**Audit & Compliance Support:** Support audit and compliance efforts (SOC 2, ISO 27001, customer security questionnaires) by keeping vulnerability management evidence and metrics audit-ready.

**Process & Automation:** Drive process improvements and automation to reduce manual triage effort and improve time-to-remediation across all vulnerability sources.

## Required Skills & Experience

- 4–6+ years of experience in technical program management, security program management, or security operations, with direct ownership of a vulnerability management or application security program.
- Hands-on experience running a bug bounty program (e.g., HackerOne, Bugcrowd, Intigriti), including triage and payout workflows.
- Working knowledge of GCP security fundamentals: IAM, VPC/networking, Security Command Center, Cloud Logging/Monitoring, and common cloud misconfiguration risks.
- Familiarity with GitHub-based development workflows and code security tooling (Wiz Code, Dependabot, SAST/DAST/SCA tools such as Snyk, Semgrep, or CodeQL).
- Strong grasp of vulnerability scoring frameworks (CVSS) and risk-based prioritization.
- Excellent cross-functional communication skills — able to translate technical vulnerability data into business risk for executive audiences and hold engineering teams accountable without owning the code themselves.
- Proven ability to build reporting/dashboards (e.g., Linear, Jira, ServiceNow, Tableau, Looker) that give leadership real-time visibility into program health.
- Experience supporting compliance frameworks such as SOC 2, ISO 27001, PCI-DSS, or FedRAMP.

## What we value

- Systems Thinking: The ability to see the “big picture” and understand how vulnerability management decisions impact the entire stack — cloud, code, and vendor ecosystem alike.
- Technical Influence: The ability to drive alignment across engineering and security through expertise and collaboration rather than direct authority.
- Autonomy: Comfortable owning a program end to end and driving outcomes with minimal oversight.
- Bias for Action: A track record of closing the gap between finding a vulnerability and actually getting it fixed.

## Similar roles

- [Senior Technical Program Manager, Services Tools & Diagnostics](https://hotfix.jobs/jobs/953c2fb6-68f9-4b9f-9876-410d24deb0ef) - Twilio - Remote - $188k – $277k/yr
- [Technical Program Manager, Platform & Infrastructure](https://hotfix.jobs/jobs/d81fd699-f83c-4ec8-aac8-b3648affef7e) - Harvey - San Francisco, CA - $188k – $278k/yr
- [GFCO Program Manager](https://hotfix.jobs/jobs/aa7d4794-1d49-4409-8e09-2b28a024ebd1) - Coinbase - Remote - $194k – $228k/yr
- [Senior Technical Program Manager](https://hotfix.jobs/jobs/899153da-ddd3-4e2a-8772-bf14b7e3926a) - Zoox - Foster City, CA - $186k – $233k/yr
- [Senior Technical Program Manager, Operational Excellence](https://hotfix.jobs/jobs/3361944c-c88f-4580-936c-a32c0e16a428) - Zoox - Hayward, CA - $186k – $223k/yr

**Apply:** https://hotfix.jobs/jobs/eef83e31-58fa-42d6-b8ba-b2ebfc5efd02
**Canonical:** https://hotfix.jobs/jobs/eef83e31-58fa-42d6-b8ba-b2ebfc5efd02