Skip to content
← Back to job listings

Security Technical Program Manager

Gusto · San Francisco, United States

External listingfull-time6 days ago

About The Role

Join Gusto, an AI-native company, as a Security Technical Program Manager. In this role, you will define and deliver Gusto's vulnerability management and security operations programs, driving timelines, managing dependencies, and using AI plugins to enhance security efficiency. You will work with leaders across various departments to shape the future of vulnerability management and security operations, ensuring Gusto's AI ambitions are pursued safely.

  • Defining and delivering Gusto's vulnerability management and security operations programs across various departments.
  • Driving the centralized vulnerability scorecard, expanding detection and monitoring coverage, and hardening the SDLC.
  • Leading the delivery of the centralized vulnerability management program, including coverage across code, cloud, data, and edge.
  • A history of taking programs from ambiguous to shipped in regulated environments
  • A way of working where AI plugins drive your everyday delivery, and you help the people around you work the same way
  • The ability to speak the language of security engineering, infrastructure, GRC, and R&D, and keep everyone rowing together
  • A solid handle on vulnerability management and security operations, from scanning coverage and remediation SLAs to detection engineering, SIEM/monitoring, and identity and privileged access, and a sense for how they help Gusto move faster on AI
  • 5 to 8+ years leading cross-functional TPM or delivery work, with real time spent on security, infrastructure, or platform engineering
  • Familiarity with the modern security stack, including vulnerability and asset scanners (e.g., Wiz, Axonius), code security (dependency and secret scanning), SIEM/detection (e.g., Panther), and identity/JIT access (e.g., Opal)
  • Hands-on experience using AI clients and plugins (MCPs) to generate program artifacts and take the busywork off your plate
  • A working knowledge of control frameworks like SOC 1/2 and ISO 27001, plus secure SDLC practices
  • A PM certification (PMP, CAPM, Scrum, or Prosci) and time spent in high-growth fintech or another regulated, fast-paced industry

This is an external listing. JobSpring does not represent or verify the employer. Report this listing