Security Technical Program Manager
$138,000–$156,000 year
HybridDenver, Colorado, United States
Job Summary
Set the strategy and roadmap for Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk, defining multi-quarter visions for an AI-native business. Lead delivery of centralized vulnerability coverage and security operations, including expanding detection, SIEM integration, and automated workflows driven by AI plugins. Stand up daily metrics dashboards, manage audit and regulatory commitments, and roll out new controls like risk-scored PR reviews while keeping stakeholders aligned. Manage vendor commitments, track program budgets, and use AI tools to map dependencies and pull stakeholder input.
Required Qualifications
- A history of taking programs from ambiguous to shipped in regulated environments
- 5 to 8+ years leading cross-functional TPM or delivery work, with real time spent on security, infrastructure, or platform engineering
- A solid handle on vulnerability management and security operations, from scanning coverage and remediation SLAs to detection engineering, SIEM/monitoring, and identity and privileged access, and a sense for how they help Gusto move faster on AI
- A way of working where AI plugins drive your everyday delivery, and you help the people around you work the same way
- The ability to speak the language of security engineering, infrastructure, GRC, and R&D, and keep everyone rowing together
- Must be able to work from the office on designated days approximately 2-3 days per week (or more depending on role)
- When approved to work from a location other than a Gusto office, a secure, reliable, and consistent internet connection is required
Desired Qualifications
- Familiarity with the modern security stack, including vulnerability and asset scanners (e.g., Wiz, Axonius), code security (dependency and secret scanning), SIEM/detection (e.g., Panther), and identity/JIT access (e.g., Opal)
- Hands-on experience using AI clients and plugins (MCPs) to generate program artifacts and take the busywork off your plate
- A working knowledge of control frameworks like SOC 1/2 and ISO 27001, plus secure SDLC practices
- A PM certification (PMP, CAPM, Scrum, or Prosci) and time spent in high-growth fintech or another regulated, fast-paced industry
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.