# Security Technical Program Manager

**Company**: Gusto
**Location**: Denver, CO;San Francisco, CA
**Work arrangement**: hybrid
**Experience**: senior
**Job type**: full-time
**Salary**: $138,000-156,000 in Denver, $168,000-189,000 in San Francisco Bay Area
**Category**: Engineering
**Industry**: Technology

**Apply**: https://job-boards.greenhouse.io/gusto/jobs/8068218?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_b5670e8f-44d

## Description

### Job Overview

As a Security Technical Program Manager at Gusto, you will own the definition and delivery of Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk.

### Responsibilities

- Set the strategy and roadmap for vulnerability management and security operations, aligning with Gusto's AI-native goals.

- Collaborate with leaders across departments to define what good vulnerability management and security operations look like for an AI-first business.

- Prioritize and manage intake with senior stakeholders, making decisions on what gets built first.

- Drive the delivery of centralized vulnerability management and security operations programs, including:

+ Vulnerability management: coverage across code, cloud, data, and edge; CSPM/DSPM, container scanning, dependency and secrets detection, and owner-based remediation routing to closure.   + Security operations: expand high-risk detection and alerting, impersonation and privileged-access logging, SIEM integration, insider-risk telemetry, and logging of agentic activity.

- Develop security metrics and dashboards for leadership, driving monthly vulnerability reporting.

- Implement AI plugins to automate security workflows, coverage checks, and evidence collection.

- Manage stakeholders, vendors, and budgets, ensuring successful program execution.

### Requirements

- 5-8+ years of experience leading cross-functional TPM or delivery work, with a focus on security, infrastructure, or platform engineering.

- Strong understanding of vulnerability management and security operations, including scanning coverage, remediation SLAs, detection engineering, SIEM/monitoring, and identity and privileged access.

- Experience working with AI plugins to drive delivery and help others work efficiently.

- Ability to communicate effectively with security engineering, infrastructure, GRC, and R&D teams.

### Nice to Have

- Familiarity with modern security stacks, including vulnerability and asset scanners, code security, SIEM/detection, and identity/JIT access.

- Hands-on experience using AI clients and plugins to generate program artifacts.

- Knowledge of control frameworks like SOC 1/2 and ISO 27001, plus secure SDLC practices.

- PM certification (PMP, CAPM, Scrum, or Prosci) and experience in high-growth fintech or a regulated industry.

### Compensation and Benefits

- Cash compensation: $138,000-156,000 in Denver, $168,000-189,000 in San Francisco Bay Area.

- Stock equity is additional.

- Competitive base pay, benefits, and equity (RSUs) for all full-time employees.

## Skills

### Required
- vulnerability management
- security operations
- AI plugins
- security engineering
- infrastructure
- GRC
- R&D

### Nice to have
- modern security stacks
- AI clients and plugins
- control frameworks
- PM certification

---

Source: [Apply at job-boards.greenhouse.io](https://job-boards.greenhouse.io/gusto/jobs/8068218?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
