Vulnerability Management Technical Lead

Jobtailor

San Francisco (CA)

On-site

USD 180,000 - 230,000

Full time

41 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Gusto seeks a Senior TPM to own the vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk.

You will set strategy and roadmaps, lead cross-functional delivery across code, cloud, and data, and drive audits and regulatory commitments with AI-enabled workflows.

Qualifications

  • History of taking programs from ambiguous to shipped in regulated environments.
  • 5 to 8+ years leading cross-functional TPM or delivery work.
  • Real time spent on security, infrastructure, or platform engineering.
  • Solid understanding of vulnerability management and security operations, including scanning coverage, remediation SLAs, detection engineering, SIEM/monitoring, identity, and privileged access.
  • AI plugins drive everyday delivery, with ability to help others work the same way.
  • Ability to speak the language of security engineering, infrastructure, GRC, and R&D.
  • Familiarity with vulnerability and asset scanners such as Wiz and Axonius.
  • Experience with dependency and secret scanning.
  • Familiarity with SIEM/detection tools such as Panther.
  • Familiarity with identity/JIT access tools such as Opal.
  • Hands-on experience using AI clients and plugins (MCPs).
  • Working knowledge of SOC 1/2 and ISO 27001 control frameworks.
  • Secure SDLC practices.
  • PM certification and fintech/regulatory experience nice to have.

Responsibilities

  • Own the definition and delivery of vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk.
  • Set the strategy, roadmap, multi-quarter vision, intake, and prioritization for vulnerability management and security operations.
  • Lead delivery of centralized vulnerability management across code, cloud, data, and edge.
  • Deliver CSPM/DSPM, container scanning, dependency and secrets detection, and owner-based remediation routing through closure.
  • Expand high-risk security detection and alerting across systems and vendors.
  • Implement impersonation and privileged-access logging, SIEM integration, insider-risk telemetry, and agentic-activity logging.
  • Establish daily security-health and vulnerability-management dashboards and drive monthly reporting.
  • Build AI-plugin-driven security workflows for automated coverage checks and evidence collection.
  • Build plans, manage scope and risk, track milestones, and deliver audit and regulatory commitments.
  • Roll out controls including risk-scored PR review, JIT privileged access, and secrets management.
  • Support adoption through training, communications, and runbooks.
  • Align stakeholders through clear updates, manage vendors and partners, monitor workstreams, budgets, tooling spend, and implementation costs.

Skills

Vulnerability Management
Security Operations
Cross-Functional Leadership
SIEM Integration
Detection Engineering
Remediation SLAs
Scanning Coverage
Secure SDLC Practices
Dependency Scanning
Secrets Management
Privileged Access Management
Risk Management

Education

PM Certification (PMP/CAPM/Scrum/Prosci)

Tools

CSPM
DSPM
SIEM Tools
Wiz
Axonius
Panther
Opal
AI Clients
MCPs
Dashboards

Job description


  • Own the definition and delivery of Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk

  • Set the strategy, roadmap, multi-quarter vision, intake, and prioritization for vulnerability management and security operations

  • Lead delivery of centralized vulnerability management across code, cloud, data, and edge

  • Deliver CSPM/DSPM, container scanning, dependency and secrets detection, and owner-based remediation routing through closure

  • Expand high-risk security detection and alerting across systems and vendors

  • Implement impersonation and privileged-access logging, SIEM integration, insider-risk telemetry, and agentic-activity logging

  • Establish daily security-health and vulnerability-management dashboards and drive monthly reporting

  • Build AI-plugin-driven security workflows for automated coverage checks and evidence collection

  • Build plans, manage scope and risk, track milestones, and deliver audit and regulatory commitments

  • Roll out controls including risk-scored PR review, JIT privileged access, and secrets management

  • Support adoption through training, communications, and runbooks

  • Align stakeholders through clear updates, manage vendors and partners, monitor workstreams, budgets, tooling spend, and implementation costs


Requirements


  • History of taking programs from ambiguous to shipped in regulated environments

  • 5 to 8+ years leading cross-functional TPM or delivery work

  • Real time spent on security, infrastructure, or platform engineering

  • Solid understanding of vulnerability management and security operations, including scanning coverage, remediation SLAs, detection engineering, SIEM/monitoring, identity, and privileged access

  • AI plugins drive everyday delivery, with ability to help others work the same way

  • Ability to speak the language of security engineering, infrastructure, GRC, and R&D

  • Familiarity with vulnerability and asset scanners such as Wiz and Axonius

  • Experience with dependency and secret scanning

  • Familiarity with SIEM/detection tools such as Panther

  • Familiarity with identity/JIT access tools such as Opal

  • Hands-on experience using AI clients and plugins (MCPs)

  • Working knowledge of SOC 1/2 and ISO 27001 control frameworks

  • Secure SDLC practices

  • PM certification (PMP, CAPM, Scrum, or Prosci) and experience in high-growth fintech or another regulated, fast-paced industry are nice to have


Core Competencies

Demonstrates expertise in vulnerability management and security operations, with a strong focus on strategy development, cross-functional leadership, and regulatory compliance. Proficient in implementing security controls, managing risk, and utilizing AI-driven tools for enhanced security workflows.


Highest-signal resume keywords


  • Vulnerability Management

  • Security Operations

  • Cross-Functional Leadership

  • SIEM Integration

  • PM Certification


Hard Skills


  • Vulnerability Management

  • Security Operations

  • Detection Engineering

  • Remediation SLAs

  • Scanning Coverage

  • Secure SDLC Practices

  • Dependency Scanning

  • Secrets Management

  • Privileged Access Management

  • Risk Management


Soft Skills


  • Stakeholder Alignment

  • Communication

  • Training

  • Vendor Management

  • Cross-Functional Collaboration


Certifications & Qualifications


  • PMP

  • CAPM

  • Scrum

  • Prosci


Industry Keywords


  • Regulated Environments

  • Fintech

  • SOC 1/2

  • ISO 27001

  • Risk Scoring


Tools & Technologies


  • CSPM

  • DSPM

  • SIEM Tools

  • Wiz

  • Axonius

  • Panther

  • Opal

  • AI Clients

  • MCPs

  • Dashboards

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Corporate Security Engineer
Staff Corporate Security Engineer

Jobtailor • Lehi (UT)

On-site
USD 120,000 - 180,000
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Open Source Software Security Engineer – Software Supply Chain
Open Source Software Security Engineer – Software Supply Chain

Jobtailor • North Carolina

On-site
USD 120,000 - 180,000
Penetration Testing Engineer II
Penetration Testing Engineer II

Jobtailor • Bentonville (AR)

On-site
USD 80,000 - 110,000
Director of Cyber Security
Director of Cyber Security

Jobtailor • Concord (MA)

Hybrid
USD 180,000 - 260,000
Senior Information Security Analyst – CSIRT
Senior Information Security Analyst – CSIRT

Jobtailor • Mount Laurel Township (NJ)

On-site
USD 110,000 - 170,000
Senior Product Security
Senior Product Security

Jobtailor • California (MO)

On-site
USD 150,000 - 210,000
Sr Cyber Security Vulnerability Management Analyst
Sr Cyber Security Vulnerability Management Analyst

Constellation • Baltimore (MD)

On-site
USD 123,000 - 137,000
Bonus program
401(k) with company match
Employee stock purchase program
+3
Sr Cyber Security Vulnerability Management Analyst
Sr Cyber Security Vulnerability Management Analyst

Constellation • Houston (TX)

On-site
USD 123,000 - 137,000
Senior Product Manager – Falcon Privileged Access
Senior Product Manager – Falcon Privileged Access

Jobtailor • California (MO)

On-site
USD 140,000 - 210,000