Security Technical Program Manager
Gusto- Base salary
- $168k–$189k Published base salary range
- Location
- Hybrid - San Francisco, CA, 2-3 days/week Remote eligibility
- Employment
- Full-time Mid-level
About the job
About Gusto
Gusto is on a mission to grow the small business economy, handling payroll, health insurance, 401(k)s, and HR for over 500,000 small businesses nationwide. With teams in Denver, San Francisco, and New York, Gusto is building a workplace that reflects the people it serves. All full-time employees receive competitive base pay, benefits, and equity (RSUs).
About the Role
As the Vulnerability Management Technical Lead, you will own the definition and delivery of Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk. You will drive the centralized vulnerability scorecard, expand detection and monitoring coverage, harden the SDLC, and stand up security metrics dashboards. You will drive timelines, manage dependencies, and use AI plugins to automate work, making security an enabler for Gusto's AI-native transformation.
About the Team
The TPM organization is part of the AIT, Risk, and Security team, delivering cross-functional work that lets Gusto securely accelerate its AI and platform modernization. The vulnerability management and security operations programs sit at the intersection of security engineering, infrastructure, and GRC.
What You'll Do Day-to-Day
- Set the strategy and roadmap for vulnerability management and security operations as Gusto becomes AI-native.
- Run intake and prioritization with senior stakeholders, deciding what gets built first.
- Lead delivery of the centralized vulnerability management program: coverage across code, cloud, data, and edge; CSPM/DSPM, container scanning, dependency and secrets detection, and owner-based remediation routing.
- Lead security operations delivery: expand high-risk detection and alerting, impersonation and privileged-access logging, SIEM integration, insider-risk telemetry, and logging of agentic activity.
- Stand up daily security-health and vulnerability-management metrics dashboards and drive monthly vulnerability reporting.
- Build security workflows that run on AI plugins by default, automating coverage checks and evidence collection.
- Manage scope, risk, milestones, and deliver against audit and regulatory commitments.
- Roll out new controls like risk-scored PR review, JIT privileged access, and secrets management, with training and runbooks.
- Manage stakeholders and vendors, track program budget and tooling spend.
What We're Looking For
- 5 to 8+ years leading cross-functional TPM or delivery work, with time spent on security, infrastructure, or platform engineering.
- Solid handle on vulnerability management and security operations, from scanning coverage and remediation SLAs to detection engineering, SIEM/monitoring, and identity and privileged access.
- AI plugins drive your everyday delivery, and you help others work the same way.
- Ability to speak the language of security engineering, infrastructure, GRC, and R&D.
Nice to Have
- Familiarity with modern security stack: Wiz, Axonius, Panther, Opal.
- Hands-on experience using AI clients and plugins (MCPs) to generate program artifacts.
- Working knowledge of control frameworks like SOC 1/2 and ISO 27001, plus secure SDLC practices.
- PM certification (PMP, CAPM, Scrum, or Prosci) and time in high-growth fintech or regulated industry.
Compensation & Benefits
Cash compensation is targeted at $138,000-156,000 in Denver, and $168,000–189,000 in the San Francisco Bay Area. Stock equity is additional. Final offers vary by candidate experience and location. All full-time employees receive competitive base pay, benefits, and equity (RSUs).
Location & Work Style
This role is based in San Francisco, CA with a hybrid work schedule. Employees based in Denver, San Francisco, or New York City are expected to work from the office on designated days approximately 2-3 days per week (or more depending on role). The San Francisco office expectations encompass both San Francisco and San Jose metro areas. When approved to work remotely, a secure, reliable, and consistent internet connection is required.
Application Instructions
Apply through the Gusto Greenhouse job posting.
Skills & tags
Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.