Senior Technical Program Manager, Security

Triwill Group

Foster City (CA)

Hybrid

USD 140,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Salary & equity
401(k)
Health insurance
Disability insurance
Parental leave
Flexible PTO
Commuter benefits
Wellness stipend
Autonomous work environment
Office setup reimbursement
Quarterly gatherings
Office amenities

Job summary

Replit is seeking a Senior Technical Program Manager to own our vulnerability management program end to end, overseeing intake, triage, remediation, and reporting across GCP, GitHub, and third‑party SaaS. You will partner with security, engineering, IT, legal, and vendors to ensure vulnerabilities are found fast, triaged accurately, and closed within SLA.

You will drive automation to scale responsibilities while providing clear risk visibility to executives and stakeholders across the

Qualifications

  • 4–6+ years in technical program management, security program management, or security operations with direct vulnerability management ownership.
  • Hands-on experience running a bug bounty program (e.g., HackerOne, Bugcrowd, Intigriti), including triage and payouts.
  • Working knowledge of GCP security fundamentals: IAM, VPC, Security Command Center, Cloud Logging/Monitoring.
  • Familiarity with GitHub workflows and code security tooling (Wiz Code, Dependabot, Snyk, Semgrep, or CodeQL).
  • Strong grasp of CVSS and risk-based prioritization.
  • Excellent cross-functional communication to translate vulnerability data into business risk.
  • Experience building dashboards (Looker, Tableau, Jira, ServiceNow) for leadership.
  • Experience supporting SOC2, ISO27001, PCI-DSS, or FedRAMP.

Responsibilities

  • Own and continuously improve the vulnerability management program end to end.
  • Manage triage/payouts/rewards workflow and report program health.
  • Drive remediation in GCP IAM, networking, Compute/GKE, storage, and logging/monitoring.
  • Coordinate remediation of vulnerabilities surfaced through SAST/DAST/SCA tooling across repos.
  • Build and manage risk tracking across third‑party SaaS applications.
  • Define escalation paths for overdue or high severity findings with sign‑off.
  • Embed remediation work into sprint planning and hold teams to SLAs.
  • Establish dashboards and a single source of truth for status and trends.
  • Support audit/compliance efforts with vulnerability evidence.
  • Drive process improvements and automation to reduce manual triage.

Skills

Program ownership
Cross-functional communication
Autonomy
Bias for action
Risk prioritization
Security program management
Executive reporting

Tools

Wiz Code
Dependabot
Snyk
CodeQL
Semgrep

Job description

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.

About the Role

We are seeking a Senior Technical Program Manager to own our vulnerability management program end to end. In this role, you will drive vulnerability intake, triage, remediation, and reporting across our bug bounty program, our Google Cloud Platform (GCP) infrastructure, source code hosted on GitHub, and a broad portfolio of third‑party SaaS services. You will partner closely with platform engineering, product engineering, SRE, security, IT, legal, and vendor management to make sure vulnerabilities are found fast, triaged accurately, and closed within SLA - and that leadership always has a clear, current picture of the organization's risk posture. The ideal candidate uses AI and automation aggressively to scale themselves, but understands that the core value is clarity, tradeoffs, and execution, not just tooling.

What you'll do
  • Program Ownership: Own and continuously improve the vulnerability management program, including intake, severity scoring (CVSS/risk-based), SLA definition, and remediation tracking across all asset types.
  • Bug Bounty Operations: Manage the triage/payouts/rewards workflow, and report on program health and trends.
  • Cloud Remediation (GCP): Drive remediation of vulnerabilities found in GCP infrastructure - IAM, networking, Compute/GKE, storage, and logging/monitoring configuration - by partnering with security, cloud, and platform engineering teams.
  • Code & Supply Chain Security: Coordinate remediation of vulnerabilities surfaced through SAST/DAST/SCA tooling (Wiz Code, Snyk, Dependabot, code scanning, secret scanning) across engineering repos, including dependency and supply‑chain risk.
  • SaaS Vendor Risk: Build and manage the process for assessing and tracking security posture across third‑party SaaS applications.
  • Escalation & Exceptions: Define and enforce escalation paths for overdue or critical/high‑severity findings, including risk acceptance and exception processes with appropriate sign‑off.
  • Cross‑Team Accountability: Partner with engineering managers and tech leads to embed remediation work into sprint planning and hold teams accountable to remediation SLAs.
  • Reporting & Alerting: Establish and maintain a single source of truth for vulnerability status, aging, SLA compliance, and risk trends, with dashboards for engineering leadership, security leadership, and executives.
  • Audit & Compliance Support: Support audit and compliance efforts (SOC2, ISO27001, customer security questionnaires) by keeping vulnerability management evidence and metrics audit‑ready.
  • Process & Automation: Drive process improvements and automation to reduce manual triage effort and improve time‑to‑remediation across all vulnerability sources.
Required Skill & Experience
  • Experience: 4-6+ years of experience in technical program management, security program management, or security operations, with direct ownership of a vulnerability management or application security program.
  • Bug Bounty Expertise: Hands‑on experience running a bug bounty program (e.g., HackerOne, Bugcrowd, Intigriti), including triage and payout workflows.
  • Cloud Security Knowledge (GCP): Working knowledge of GCP security fundamentals: IAM, VPC/networking, Security Command Center, Cloud Logging/Monitoring, and common cloud misconfiguration risks.
  • Code Security Familiarity: Familiarity with GitHub‑based development workflows and code security tooling (Wiz Code, Dependabot, SAST/DAST/SCA tools such as Snyk, Semgrep, or CodeQL).
  • Risk Prioritization: Strong grasp of vulnerability scoring frameworks (CVSS) and risk‑based prioritization.
  • Communication: Excellent cross‑functional communication skills - able to translate technical vulnerability data into business risk for executive audiences and hold engineering teams accountable without owning the code themselves.
  • Reporting Tools: Proven ability to build reporting/dashboards (e.g., Linear, Jira, ServiceNow, Tableau, Looker) that give leadership real‑time visibility into program health.
  • Compliance Awareness: Experience supporting compliance frameworks such as SOC2, ISO27001, PCI‑DSS, or FedRAMP.
What we value
  • Systems Thinking: The ability to see the "big picture" and understand how vulnerability management decisions impact the entire stack - cloud, code, and vendor ecosystem alike.
  • Technical Influence: The ability to drive alignment across engineering and security through expertise and collaboration rather than direct authority.
  • Autonomy: Comfortable owning a program end to end and driving outcomes with minimal oversight.
  • Bias for Action: A track record of closing the gap between finding a vulnerability and actually getting it fixed.

This is a full‑time role that can be held from our Foster City, CA office. The hybrid role has an in‑office requirement of Monday, Wednesday, and Friday.

Full‑Time Employee Benefits Include
  • Competitive Salary & Equity
  • 401(k) Program with a 4% match (US Only)
  • Health, Dental, Vision and Life Insurance
  • Short Term and Long Term Disability
  • Paid Parental, Medical, Caregiver Leave
  • Flexible Time Off (FTO) + Holidays
  • Commuter Benefits (In‑Office Only)
  • Monthly Wellness Stipend
  • Autonomous Work Environment
  • In Office Set‑Up Reimbursement (In‑Office Only)
  • Quarterly Team Gatherings
  • In Office Amenities (In‑Office Only)
Want to learn more about what we are up to?
  • Meet the Replit Agent https://www.youtube.com/watch?v=IYiVPrxY8-Y
  • Replit: Make an app for that https://www.youtube.com/watch?v=4zd9hzngFwY
  • Replit Blog https://blog.replit.com/
  • Amjad TED Talk https://youtu.be/kCudFI4tcpg?si=l4ViCejV_f2RZkDi
Interviewing + Culture at Replit
  • Operating Principles https://blog.replit.com/operating-principles
  • Reasons not to work at Replit https://blog.replit.com/reasons-not-to-join-replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world.

We welcome your unique perspective and experiences in shaping this product.

We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non‑traditional backgrounds.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Technical Program Manager, Security Replit Foster City, CA
Senior Technical Program Manager, Security Replit Foster City, CA

Neura Market • Foster City (CA)

Hybrid
USD 140,000 - 180,000
Health Insurance
401(k) Program with match
Paid Parental Leave
+1
Senior Technical Program Manager, Security
Senior Technical Program Manager, Security

Replit • United States

Hybrid
USD 140,000 - 200,000
401(k) Match (US)
Health, Dental, Vision
Parental and Caregiver Leave
+3
Security Engineer - Vuln Management (Code)
Security Engineer - Vuln Management (Code)

Replit, Inc. • Foster City (CA)

On-site
USD 110,000 - 130,000
Competitive Salary & Equity
401(k) Program with a 4% match
Health, Dental, Vision and Life Insurance
+4
Senior Software Engineer, Risk
Senior Software Engineer, Risk

Replit • Foster City (CA)

On-site
USD 140,000 - 200,000
Equity
401(k) match
Health insurance
+7
Data Scientist, Trust & Safety
Data Scientist, Trust & Safety

Replit, Inc. • Foster City (CA)

On-site
USD 140,000 - 210,000
Competitive Salary & Equity
401(k) with 4% match (US Only)
Health, Dental, Vision insurance
+3
Staff Software Engineer, Trust & Safety
Staff Software Engineer, Trust & Safety

Replit • Foster City (CA)

On-site
USD 180,000 - 240,000
Competitive Salary & Equity
401(k) Program with a 4% match (US)
Health, Dental, Vision and Life Ins
+9
Recruiting Coordinator Replit Foster City, CA
Recruiting Coordinator Replit Foster City, CA

Neura Market • Foster City (CA), Northern (KY)

Hybrid
USD 70,000 - 90,000
Competitive Salary & Equity
401(k) Program
Health, Dental, Vision Insurance
+2
Software Engineer, Compute Platform
Software Engineer, Compute Platform

Replit • Foster City (CA)

On-site
USD 120,000 - 160,000
Flexible Work Hours
Competitive Salary & Equity
Health, Dental, Vision and Life Insurance
+1
Senior Software Engineer, Enterprise Platform
Senior Software Engineer, Enterprise Platform

Replit, Inc. • Foster City (CA)

On-site
USD 120,000 - 160,000
Competitive Salary & Equity
401(k) Program
Health, Dental, Vision and Life Insurance
+9
Software Engineering Intern (Summer 2027)
Software Engineering Intern (Summer 2027)

Triwill Group • Foster City (CA)

On-site
USD 16,531,000 - 23,144,000
Competitive Salary & Equity
401(k) Program with a 4% match (US)
Health, Dental, Vision and Life Ins
+6