Senior Security Program Manager

Flexhire

United States

On-site

USD 140,000 - 190,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

TinyFish is hiring a Senior Security Program Manager to run security and compliance as a program. You will own the operational backbone — audits, evidence collection, policy lifecycle, vendor risk, and customer security reviews — enabling the Security Lead to focus on architecture and threat work.

This IC role reports to the Staff Program Manager and is the first dedicated security program owner in the org, aligning enterprise deals with security requirements.

Qualifications

  • 4-7 years in security or GRC program management, ideally in B2B SaaS.
  • Experience running ISO 27001 and SOC 2 audits end-to-end, including auditor management.
  • Fluency with Vanta (or Drata/Tugboat) and ability to compensate manually where needed.
  • Comfort presenting to customer security teams and instilling confidence in the program.
  • Strong written communication and sound judgment on control gaps.
  • Ability to escalate issues quickly to the right audiences.

Responsibilities

  • Compliance lifecycle: maintain ISO 27001, prep for SOC 2 Type 1 & 2, manage auditors, collect evidence in Vanta.
  • Vulnerability management: own SLA dashboard, breach escalation, exception tracking; ensure timely fixes.
  • Policy lifecycle: annual reviews, policy updates, training rollout, attestation tracking.
  • People-ops security controls: onboarding/offboarding evidence, access reviews, training, background checks.
  • Vendor risk: inventory, pre-procurement assessments, re-assessments, DPA tracking.
  • Customer-facing security: questionnaires, CAIQs, RFPs, security calls; named SPM in trust center.
  • Policy update cadence for terms and privacy; cross-functional collaboration.
  • Risk and incident program ownership: maintain risk register, run quarterly reviews, run tabletop exercises.

Skills

Security program management
ISO 27001 / SOC 2
Vendor risk management
Security audits & evidence collection
Policy lifecycle & controls
Customer security reviews

Tools

Vanta
Drata
Tugboat

Job description

We're hiring a Senior Security Program Manager to run security and compliance as a program at TinyFish. You'll own the operational backbone — Vanta, audits, vulnerability SLAs, policy lifecycle, vendor risk, customer security reviews — so our Security Lead can stay focused on architecture and threat work, and security requirements run smoothly across our enterprise deals.

This is an IC role reporting to the Staff Program Manager, working closely with our Security Lead. You'll be the first hire whose full-time job is running the program rather than building the controls.

TinyFish builds browser-based AI agents that do real work on the open web for enterprise customers. We're a small, technical team shipping fast against serious enterprise buyers who ask serious security questions. We're mid-flight on ISO 27001 certification renewal (Schellman external, Alameda internal) and our security posture is moving from "small startup" to "we can answer a 400-line questionnaire without flinching."

Key Responsibilities
  • Compliance lifecycle. Maintain ISO 27001 certification, prep for SOC 2 Type 1 and 2, manage auditor relationships, own evidence collection in Vanta. You'll know what's failing before the dashboard turns red, and the forecast of when the next certification is anticipated to complete.
  • Vulnerability management as a program. Own the SLA layer — weekly dashboard, breach escalation, exception tracking, monthly view to leadership. Engineers fix the bugs; you make sure they fix them on time.
  • Policy lifecycle. Annual reviews, new policies as scope expands, training rollout, attestation tracking, exception requests. We run reviews through an adversarial AI pipeline today; you'll own the cadence and the human decisions inside it.
  • People-ops security controls. Onboarding/offboarding evidence, access reviews, security awareness training, background-check tracking, permission-management security groups. Partner with HR on the workflow, own the auditable artifact.
  • Vendor risk. Vendor inventory, pre-procurement assessments, annual reassessments, DPA and sub-processor tracking.
  • Customer-facing security. Security questionnaires, CAIQs, custom RFPs, customer security calls. You're the named SPM in our trust center.
  • Product Terms of Service and Privacy Policy. Own the update cadence and the cross-functional process when product changes trigger policy revisions.
  • Risk and incident program ownership. Maintain the risk register, run quarterly reviews, own the incident runbook artifact (technical response stays with Security Engineering), schedule and run tabletops.
Ideal Experience
  • 4-7 years in security or GRC program management, ideally at a B2B SaaS company that grew through early stages.
  • Lived experience running and owning ISO 27001 and SOC 2 audits end-to-end, including auditor management.
  • Deep fluency in Vanta (or Drata/Tugboat with willingness to switch). You know what the platforms do well and where you have to compensate manually.
  • Comfortable in front of customer security teams to both represent the capabilities of our security program as well as instill confidence in the team.
  • Strong written communication.
  • Good judgment on when a control gap is a real risk vs. a paperwork issue, and the ability to elevate issues quickly to the right audiences.
Bonus
  • AI/ML security experience, especially model providers, prompt injection, data handling in agentic systems.
  • Prior work at a company with a browser-based product (extensions, agents, scraping at scale).
  • Experience standing up an additional framework (HIPAA, FedRAMP, ISO 27017/27018, C5).
  • Background in pen-test coordination or bug bounty program management.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DevSecOps Engineer
Senior DevSecOps Engineer

Flexhire • United States

On-site
USD 120,000 - 180,000
Senior DevSecOps Engineer Hybrid (Los Altos, CA; Ho Chi Minh City, Viet Nam)
Senior DevSecOps Engineer Hybrid (Los Altos, CA; Ho Chi Minh City, Viet Nam)

S27a • Los Altos (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Remote work environment
Async-friendly
Competitive compensation
Head of Risk and Compliance
Head of Risk and Compliance

Applied Intuition • United States

On-site
USD 180,000 - 250,000
Health Insurance
Fitness Stipend
401(k) Match
+3
Security Program Manager (ISO 27001 & SOC 2) — GRC Lead
Security Program Manager (ISO 27001 & SOC 2) — GRC Lead

Flexhire • United States

On-site
USD 140,000 - 190,000
Security & Compliance Lead
Security & Compliance Lead

Opal • San Francisco (CA)

On-site
USD 150,000 - 190,000
Security Engineer
Security Engineer

Sperry Rail, Inc. • Shelton (CT)

Hybrid
USD 110,000 - 170,000
Technical Security Manager
Technical Security Manager

Cambium Learning Group • United States

On-site
USD 120,000 - 180,000
Senior Technical Program Manager (Security & Infrastructure)
Senior Technical Program Manager (Security & Infrastructure)

True Anomaly • United States

On-site
USD 150,000 - 210,000
Healthcare coverage
Generous time off
Equity options
+1
Compliance Manager
Compliance Manager

Anyscale • San Francisco (CA)

On-site
USD 180,000 - 240,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000