Security Technical Program Manager

Gusto is becoming an AI-native company, and that only works if our security posture keeps pace. As the Security TPM, you'll own the definition and delivery of Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk. You'll drive the centralized vulnerability scorecard, expand detection and monitoring coverage, harden the SDLC, and stand up the security metrics leadership runs the business on. You'll drive the timelines, manage the dependencies, head off the risk, and use AI plugins to do the work itself, so security becomes something that helps Gusto move faster instead of slowing it down.

The TPM organization is part of our AIT, Risk, and Security team. We deliver the cross-functional work that lets Gusto securely accelerate its AI and platform modernization. The vulnerability management and security operations programs sit right at the intersection of security engineering, infrastructure, and GRC, and they're foundational to how Gusto scales its AI ambitions safely. This is one of the most strategic programs on the team, and you'll lead it across a complex, fast-moving group of stakeholders.

Here's what you'll do day-to-day:

  • Set the strategy and the roadmap
  • Run the programs and the change
  • Manage stakeholders and vendors

Here's what we're looking for:

  • A history of taking programs from ambiguous to shipped in regulated environments.
  • 5 to 8+ years leading cross-functional TPM or delivery work, with real time spent on security, infrastructure, or platform engineering.
  • A solid handle on vulnerability management and security operations, from scanning coverage and remediation SLAs to detection engineering, SIEM/monitoring, and identity and privileged access, and a sense for how they help Gusto move faster on AI.
  • A way of working where AI plugins drive your everyday delivery, and you help the people around you work the same way.
  • The ability to speak the language of security engineering, infrastructure, GRC, and R&D, and keep everyone rowing together.

Nice to have:

  • Familiarity with the modern security stack, including vulnerability and asset scanners (e.g., Wiz, Axonius), code security (dependency and secret scanning), SIEM/detection (e.g., Panther), and identity/JIT access (e.g., Opal).
  • Hands-on experience using AI clients and plugins (MCPs) to generate program artifacts and take the busywork off your plate.
  • A working knowledge of control frameworks like SOC 1/2 and ISO 27001, plus secure SDLC practices.
  • A PM certification (PMP, CAPM, Scrum, or Prosci) and time spent in high-growth fintech or another regulated, fast-paced industry.

Our cash compensation amount for this role is targeted at $138,000-156,000 in Denver, and $168,000189,000 in the San Francisco Bay Area. Stock equity is additional. Final offer amounts are determined by multiple factors including candidate experience and expertise and may vary from the amounts listed above.

Similar jobs

Security Technical Program Manager

Apply Now
Back to search page