Description
Job Overview
As a Security Technical Program Manager at Gusto, you will own the definition and delivery of Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk.
Responsibilities
- Set the strategy and roadmap for vulnerability management and security operations, aligning with Gusto's AI-native goals.
- Collaborate with leaders across departments to define what good vulnerability management and security operations look like for an AI-first business.
- Prioritize and manage intake with senior stakeholders, making decisions on what gets built first.
- Drive the delivery of centralized vulnerability management and security operations programs, including:
+ Vulnerability management: coverage across code, cloud, data, and edge; CSPM/DSPM, container scanning, dependency and secrets detection, and owner-based remediation routing to closure. + Security operations: expand high-risk detection and alerting, impersonation and privileged-access logging, SIEM integration, insider-risk telemetry, and logging of agentic activity.
- Develop security metrics and dashboards for leadership, driving monthly vulnerability reporting.
- Implement AI plugins to automate security workflows, coverage checks, and evidence collection.
- Manage stakeholders, vendors, and budgets, ensuring successful program execution.
Requirements
- 5-8+ years of experience leading cross-functional TPM or delivery work, with a focus on security, infrastructure, or platform engineering.
- Strong understanding of vulnerability management and security operations, including scanning coverage, remediation SLAs, detection engineering, SIEM/monitoring, and identity and privileged access.
- Experience working with AI plugins to drive delivery and help others work efficiently.
- Ability to communicate effectively with security engineering, infrastructure, GRC, and R&D teams.
Nice to Have
- Familiarity with modern security stacks, including vulnerability and asset scanners, code security, SIEM/detection, and identity/JIT access.
- Hands-on experience using AI clients and plugins to generate program artifacts.
- Knowledge of control frameworks like SOC 1/2 and ISO 27001, plus secure SDLC practices.
- PM certification (PMP, CAPM, Scrum, or Prosci) and experience in high-growth fintech or a regulated industry.
Compensation and Benefits
- Cash compensation: $138,000-156,000 in Denver, $168,000-189,000 in San Francisco Bay Area.
- Stock equity is additional.
- Competitive base pay, benefits, and equity (RSUs) for all full-time employees.
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://job-boards.greenhouse.io/gusto/jobs/8068218