# Security Technical Program Manager

**Company**: Gusto
**Location**: Denver, CO;San Francisco, CA
**Work arrangement**: hybrid
**Experience**: senior
**Job type**: full-time
**Salary**: $138,000-156,000 in Denver, and $168,000–189,000 in the San Francisco Bay Area
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/gusto/jobs/8068218?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_906456f8-0c1

## Description

### About the Role:

Gusto is becoming an AI-native company, and that only works if our security posture keeps pace. As the Security TPM, you'll own the definition and delivery of Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk.

### Responsibilities:

- Set the strategy and roadmap for vulnerability management and security operations

- Define what good vulnerability management and security operations look like for an AI-first business

- Run intake and prioritization with senior stakeholders

- Decide where security should clear the way for AI speed and where it needs to hold the line

- Put AI plugins to work to pull together stakeholder input and keep the roadmap grounded

### Day-to-Day Tasks:

- Lead delivery of the centralized vulnerability management program

- Lead security operations delivery

- Stand up daily security-health and vulnerability-management metrics dashboards

- Build security workflows that run on AI plugins by default

- Manage stakeholders and vendors

### Requirements:

- A history of taking programs from ambiguous to shipped in regulated environments

- 5 to 8+ years leading cross-functional TPM or delivery work

- Solid handle on vulnerability management and security operations

- Experience working with AI plugins to drive delivery

- Ability to speak the language of security engineering, infrastructure, GRC, and R&D

### Nice to Have:

- Familiarity with modern security stack

- Hands-on experience using AI clients and plugins

- Working knowledge of control frameworks like SOC 1/2 and ISO 27001

- PM certification and experience in high-growth fintech or regulated industries

### Benefits:

- Competitive base pay

- Benefits

- Equity (RSUs)

- Physical office spaces in Denver, San Francisco, and New York City

- Flexible work arrangements

## Skills

### Required
- vulnerability management
- security operations
- AI plugins
- security engineering
- infrastructure
- GRC
- R&D

### Nice to have
- modern security stack
- AI clients and plugins
- control frameworks
- PM certification

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/gusto/jobs/8068218?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
