Security Technical Program Manager
Summary
Leads Gusto’s security programs, designing vulnerability management and security operations workflows, setting roadmaps, and automating security tasks with AI while collaborating with engineering and compliance teams.
You define and deliver vulnerability management and security operations programs, establish roadmaps and metrics, coordinate security and infrastructure stakeholders, expand detection coverage, manage risks and dependencies, implement controls, oversee vendors and budgets, and use AI plugins to automate security workflows.
Responsibilities
- Set the vulnerability management and security operations strategy
- Define the multi-quarter security roadmap
- Prioritize initiatives with senior stakeholders
- Lead centralized vulnerability management delivery
- Lead security operations delivery
- Establish security-health and vulnerability-management dashboards
- Drive monthly vulnerability reporting
- Build AI-powered security workflows
- Manage scope, risk, milestones, audits, and regulatory commitments
- Roll out security controls and adoption programs
- Align stakeholders with regular updates
- Manage vendors and partners
- Track workstreams and resolve blockers
- Monitor program budgets and tooling costs
Requirements
- 5 to 8+ years leading cross-functional TPM or delivery work
- Security, infrastructure, or platform engineering experience
- Vulnerability management knowledge
- Security operations knowledge
- Detection engineering
- SIEM and monitoring
- Identity and privileged access
- AI plugin experience
- Security engineering, infrastructure, GRC, and R&D collaboration
- Security and asset scanner familiarity preferred
- Dependency and secret scanning familiarity preferred
- SOC 1/2 and ISO 27001 knowledge preferred
- Secure SDLC knowledge
- PM certification preferred
Benefits
- Equity (RSUs)