Security Technical Program Manager

Gusto

San Francisco, Denver (CA, CO)

Hybrid

USD 168,000 - 189,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Gusto is seeking a Security TPM to own vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk. You'll drive the centralized vulnerability scorecard, expand detection and monitoring coverage, and harden the SDLC to keep pace with AI-driven platform modernization.

You will lead cross-functional delivery, set strategy and roadmaps, monitor risk, and build AI-driven security workflows.

Qualifications

  • Experience taking programs from ambiguous to shipped in regulated environments.
  • 5 to 8+ years leading cross-functional TPM or delivery work involving security, infrastructure, or platform engineering.
  • Strong handle on vulnerability management and security operations, including SIEM/monitoring and privileged access.
  • Ability to leverage AI plugins to drive delivery and automate processes.
  • Ability to communicate across security engineering, GRC, R&D, and infrastructure teams.

Responsibilities

  • Set the strategy and roadmap for vulnerability management and security operations as Gusto becomes AI-native.
  • Lead delivery of centralized vulnerability management across code, cloud, data, and edge.
  • Expand high-risk detection and alerting; drive security metrics and monthly vulnerability reporting.
  • Roll out AI-driven security workflows and maintain alignment with stakeholders.
  • Manage budgets, milestones, and audits; push for secure SDLC practices.

Skills

Strategy execution
Cross-functional leadership
Security operations
Vulnerability management
AI plugin workflows

Education

PM certification (PMP CAPM Scrum Prosci)

Tools

Wiz
Axonius
Panther
Opal
SIEM/monitoring

Job description

About the Role

Gusto is becoming an AI‑native company, and that only works if our security posture keeps pace. As the Security TPM, you'll own the definition and delivery of Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk. You'll drive the centralized vulnerability scorecard, expand detection and monitoring coverage, harden the SDLC, and stand up the security metrics that leadership relies on. You'll manage timelines, dependencies, and risk, leveraging AI plugins so security helps Gusto move faster instead of slowing it down.

About the Team

The TPM organization is part of our AIT, Risk, and Security team. We deliver the cross‑functional work that lets Gusto securely accelerate its AI and platform modernization. The vulnerability management and security operations programs sit at the intersection of security engineering, infrastructure, and GRC, and are foundational to how Gusto scales its AI ambitions safely. You'll lead it across a complex, fast‑moving group of stakeholders.

Responsibilities
Set the strategy and the roadmap
  • Work with leaders across Security, AIT, R&D, Infrastructure, GRC, and Risk to shape the direction for vulnerability management and security operations as Gusto becomes AI‑native.
  • Define what good vulnerability management and security operations look like for an AI‑first business, and set the multi‑quarter vision that gets us there.
  • Run intake and prioritization with senior stakeholders, making decisions on what gets built first.
  • Determine where security should accelerate AI speed and where it needs to hold the line, bringing leaders along on the reasoning.
  • Use AI plugins to pull together stakeholder input, map dependencies, and keep the roadmap grounded in current reality.
Run the programs and the change
  • Lead delivery of the centralized vulnerability management program: coverage across code, cloud, data, and edge; CSPM/DSPM, container scanning, dependency and secrets detection, and owner‑based remediation routing to closure.
  • Lead security operations delivery: expand high‑risk detection and alerting across systems and vendors, impersonation and privileged‑access logging, SIEM integration, insider‑risk telemetry, and logging of agentic activity.
  • Stand up daily security‑health and vulnerability‑management metrics dashboards leadership uses to run the business, and drive monthly vulnerability reporting.
  • Build security workflows that run on AI plugins by default, automating coverage checks and evidence collection.
  • Build the plans, manage scope and risk, track milestones, and deliver against every audit and regulatory commitment.
  • Roll out new controls—risk‑scored PR review, JIT privileged access, and secrets management—and help teams adopt them through training, communications, and runbooks kept up to date by plugins.
  • Keep stakeholders aligned with clear, steady updates on program status.
Manage stakeholders and vendors
  • Hold vendors and partners to their commitments and push them toward AI‑forward ways of working.
  • Stay on top of every workstream’s progress, raise flags early, and help teams unstuck when they stall.
  • Monitor the program budget, tooling spend, and implementation costs.
Qualifications
  • A history of taking programs from ambiguous to shipped in regulated environments.
  • 5 to 8+ years leading cross‑functional TPM or delivery work, with real time spent on security, infrastructure, or platform engineering.
  • A solid handle on vulnerability management and security operations, from scanning coverage and remediation SLAs to detection engineering, SIEM/monitoring, and identity and privileged access, and a sense for how they help Gusto move faster on AI.
  • A way of working where AI plugins drive your everyday delivery, and you help the people around you work the same way.
  • The ability to speak the language of security engineering, infrastructure, GRC, and R&D, and keep everyone rowing together.
Nice to Have
  • Familiarity with the modern security stack, including vulnerability and asset scanners (e.g., Wiz, Axonius), code security (dependency and secret scanning), SIEM/detection (e.g., Panther), and identity/JIT access (e.g., Opal).
  • Hands‑on experience using AI clients and plugins (MCPs) to generate program artifacts and take the busywork off your plate.
  • A working knowledge of control frameworks like SOC 1/2 and ISO 27001, plus secure SDLC practices.
  • A PM certification (PMP, CAPM, Scrum, or Prosci) and time spent in high‑growth fintech or another regulated, fast‑paced industry.
Compensation

Our cash compensation amount for this role is targeted at $138,000-156,000 in Denver, and $168,000–189,000 in the San Francisco Bay Area. Stock equity is additional. Final offer amounts are determined by multiple factors including candidate experience and expertise and may vary from the amounts listed above.

Location and Remote Policy

Gusto has physical office spaces in Denver, San Francisco, and New York City. Employees who are based in those locations will be expected to work from the office on designated days approximately 2-3 days per week (or more depending on role). The same office expectations apply to all Symmetry roles, Gusto's subsidiary, whose physical office is in Scottsdale. When approved to work from a location other than a Gusto office, a secure, reliable, and consistent internet connection is required. This includes non‑office days for hybrid employees.

Equal Opportunity Employer

Gusto is proud to be an equal‑opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Gusto considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Gusto is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. We want to see our candidates perform to the best of their ability. If you require a medical or religious accommodation at any time throughout your candidate journey, please fill out this form and a member of our team will get in touch with you.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Technical Program Manager
Security Technical Program Manager

Monograph • San Francisco (CA)

Hybrid
USD 168,000 - 189,000
Equity (RSUs)
Hybrid work model
Security Technical Program Manager
Security Technical Program Manager

Socket.dev • Denver (CO)

Hybrid
USD 138,000 - 156,000
Equity (RSUs)
Security Technical Program Manager
Security Technical Program Manager

Gusto, Inc. • Denver (CO)

On-site
USD 138,000 - 156,000
Equity (RSUs)
Hybrid work
Office in Denver
Data Governance Technical Program Manager
Data Governance Technical Program Manager

Gusto, Inc. • Denver (CO)

On-site
USD 151,580 - 180,000
Senior Staff Security Engineer (Network Security)
Senior Staff Security Engineer (Network Security)

Monograph • San Francisco (CA)

On-site
USD 230,000 - 270,000
Competitive base pay
Benefits and equity (RSUs)
Flexibility in remote work policies
Staff Software Engineer, AI Security
Staff Software Engineer, AI Security

Gusto • Seattle (WA)

Hybrid
USD 181,000 - 260,000
Security Engineer - Cloud and Network Security
Security Engineer - Cloud and Network Security

Gusto • San Francisco (CA)

Hybrid
USD 210,000 - 270,000
Senior Staff Network Engineer - Network Security
Senior Staff Network Engineer - Network Security

Monograph • San Francisco (CA)

On-site
USD 230,000 - 270,000
Senior Staff Security Engineer - Cloud and Network Security
Senior Staff Security Engineer - Cloud and Network Security

Gusto, Inc. • San Francisco (CA)

On-site
USD 230,000 - 270,000
Equity (RSUs)
Competitive base pay
Flexible remote work options
Security Engineer - Cloud and Network Security
Security Engineer - Cloud and Network Security

Gusto • San Francisco (CA)

Hybrid
USD 230,000 - 270,000
Stock equity
Office spaces in Denver, San Francisco, and New York City