Senior Security Program Manager - Vulnerability & Cloud

Triwill Group

Foster City (CA)

Hybrid

USD 140,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Salary & equity
401(k)
Health insurance
Disability insurance
Parental leave
Flexible PTO
Commuter benefits
Wellness stipend
Autonomous work environment
Office setup reimbursement
Quarterly gatherings
Office amenities

Job summary

Replit is seeking a Senior Technical Program Manager to own our vulnerability management program end to end, overseeing intake, triage, remediation, and reporting across GCP, GitHub, and third‑party SaaS. You will partner with security, engineering, IT, legal, and vendors to ensure vulnerabilities are found fast, triaged accurately, and closed within SLA.

You will drive automation to scale responsibilities while providing clear risk visibility to executives and stakeholders across the

Qualifications

  • 4–6+ years in technical program management, security program management, or security operations with direct vulnerability management ownership.
  • Hands-on experience running a bug bounty program (e.g., HackerOne, Bugcrowd, Intigriti), including triage and payouts.
  • Working knowledge of GCP security fundamentals: IAM, VPC, Security Command Center, Cloud Logging/Monitoring.
  • Familiarity with GitHub workflows and code security tooling (Wiz Code, Dependabot, Snyk, Semgrep, or CodeQL).
  • Strong grasp of CVSS and risk-based prioritization.
  • Excellent cross-functional communication to translate vulnerability data into business risk.
  • Experience building dashboards (Looker, Tableau, Jira, ServiceNow) for leadership.
  • Experience supporting SOC2, ISO27001, PCI-DSS, or FedRAMP.

Responsibilities

  • Own and continuously improve the vulnerability management program end to end.
  • Manage triage/payouts/rewards workflow and report program health.
  • Drive remediation in GCP IAM, networking, Compute/GKE, storage, and logging/monitoring.
  • Coordinate remediation of vulnerabilities surfaced through SAST/DAST/SCA tooling across repos.
  • Build and manage risk tracking across third‑party SaaS applications.
  • Define escalation paths for overdue or high severity findings with sign‑off.
  • Embed remediation work into sprint planning and hold teams to SLAs.
  • Establish dashboards and a single source of truth for status and trends.
  • Support audit/compliance efforts with vulnerability evidence.
  • Drive process improvements and automation to reduce manual triage.

Skills

Program ownership
Cross-functional communication
Autonomy
Bias for action
Risk prioritization
Security program management
Executive reporting

Tools

Wiz Code
Dependabot
Snyk
CodeQL
Semgrep

Job description

Replit is seeking a Senior Technical Program Manager to own our vulnerability management program end to end, overseeing intake, triage, remediation, and reporting across GCP, GitHub, and third‑party SaaS. You will partner with security, engineering, IT, legal, and vendors to ensure vulnerabilities are found fast, triaged accurately, and closed within SLA.

You will drive automation to scale responsibilities while providing clear risk visibility to executives and stakeholders across the

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Program Manager: Vulnerability & Cloud Risk
Senior Security Program Manager: Vulnerability & Cloud Risk

Neura Market • Foster City (CA)

Hybrid
USD 140,000 - 180,000
Health Insurance
401(k) Program with match
Paid Parental Leave
+1
Remote Security Program Manager — Lead Vulnerability Strategy
Remote Security Program Manager — Lead Vulnerability Strategy

Bugcrowd • United States

Remote
Vulnerability & Cloud Security Program Leader
Vulnerability & Cloud Security Program Leader

NinjaOne • Town of Texas (WI)

Hybrid
USD 180,000 - 220,000
Medical insurance
401(k) plan
Unlimited PTO
Lead Vulnerability & Patch Program Manager
Lead Vulnerability & Patch Program Manager

Mphasis • Georgia

On-site
USD 90,000 - 174,000
Senior Cloud AppSec Analyst - Vulnerability & Cloud Security
Senior Cloud AppSec Analyst - Vulnerability & Cloud Security

PowerPlan, Inc. • Atlanta (GA)

Hybrid
USD 110,000 - 160,000
Health insurance
401(k) or equivalent
Senior Technical Program Manager, Security
Senior Technical Program Manager, Security

Replit • United States

Hybrid
USD 140,000 - 200,000
401(k) Match (US)
Health, Dental, Vision
Parental and Caregiver Leave
+3
Lead, Vulnerability Management | AI-Driven Cloud Security
Lead, Vulnerability Management | AI-Driven Cloud Security

Vanguard • Charlotte (NC)

Hybrid
USD 140,000 - 180,000
Hybrid work model
Senior Security Engineer, Vulnerability Management & Automation
Senior Security Engineer, Vulnerability Management & Automation

Slack • Atlanta (GA)

On-site
USD 172,000 - 261,000
Senior InfoSec Program Manager: Risk & Cloud Delivery
Senior InfoSec Program Manager: Risk & Cloud Delivery

Veriipro • United States

On-site
USD 150,000 - 190,000
Senior Cloud Security Engineer, GCP Vulnerability Management
Senior Cloud Security Engineer, GCP Vulnerability Management

Google • San Jose (CA)

On-site
USD 174,000 - 253,000