Senior Technical Program Manager, Product Security
$190,000–$261,800 year
HybridRedwood City, California, United States
Job Summary
Conceive, design, and improve security tooling, automation, and frameworks that enable enterprise teams to deliver applications with appropriate security controls. Identify and eliminate classes of security problems by shifting detection and prevention left into the development workflow, while providing just-in-time, actionable technical guidance to application and service teams. Drive end-to-end execution of technical security projects, including requirements gathering, scoping, status updates, and delivery milestones, ensuring prioritization and timely delivery within a changing business environment. Establish metrics to track compliance, program health, and ongoing risk posture, and coordinate with third-party vendors and auditors to augment internal capabilities. Serve as a subject matter expert on infrastructure, architecture, and application security, supporting security reviews, threat modeling, and incident response efforts for production infrastructure.
Required Qualifications
- 5+ years of technical program management or equivalent experience, with a specific focus on security or application security
- Demonstrated proficiency with secure SDLC processes and best practices for integrating security throughout the software development lifecycle
- Hands-on experience designing and managing security controls within CI/CD pipelines, using automation frameworks to enable secure code delivery and rapid remediation
- Familiarity with threat modeling, static and dynamic application security testing (SAST/DAST), and software composition analysis (SCA) tools
- Deep understanding of DevSecOps principles, security automation, and infrastructure-as-code security
- Experience driving the adoption of vulnerability management, architectural best practices, and incident response for cloud-native and distributed applications
- Knowledge of container security (Docker, Kubernetes), microservices architectures, and cloud platform security (AWS, Azure, GCP)
- Experience leading end-to-end security architecture design and governance across complex, cloud-native, and hybrid enterprise environments, aligning security capabilities to business and risk objectives
- Proven ability to define and maintain reference architectures, security patterns, and control standards spanning network, identity, data protection, and application security domains
- Skilled in conducting architecture risk assessments and design reviews, ensuring new and existing solutions meet zero trust, defense-in-depth, and compliance requirements in regulated industries
- This role is a hybrid position requiring you to be onsite for at least 60% of the working month, approximately 3 days a week
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.