Skip to main content

Security Technical Program Manager

Gusto
Hybrid - San Francisco, CA, 2-3 days/weekUpdated 2d ago
Base salary
$168k–$189k
Published base salary range
Location
Hybrid - San Francisco, CA, 2-3 days/week
Remote eligibility
Employment
Full-time
Mid-level
Role family
Security
Fintech
Apply on job-boards.greenhouse.io
Job actionsApply now
Job actionsApply now

About the job

3 min read9 sections
About Gusto

Gusto is on a mission to grow the small business economy, handling payroll, health insurance, 401(k)s, and HR for over 500,000 small businesses nationwide. With teams in Denver, San Francisco, and New York, Gusto is building a workplace that reflects the people it serves. All full-time employees receive competitive base pay, benefits, and equity (RSUs).

About the Role

As the Vulnerability Management Technical Lead, you will own the definition and delivery of Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk. You will drive the centralized vulnerability scorecard, expand detection and monitoring coverage, harden the SDLC, and stand up security metrics dashboards. You will drive timelines, manage dependencies, and use AI plugins to automate work, making security an enabler for Gusto's AI-native transformation.

About the Team

The TPM organization is part of the AIT, Risk, and Security team, delivering cross-functional work that lets Gusto securely accelerate its AI and platform modernization. The vulnerability management and security operations programs sit at the intersection of security engineering, infrastructure, and GRC.

What You'll Do Day-to-Day

  • Set the strategy and roadmap for vulnerability management and security operations as Gusto becomes AI-native.
  • Run intake and prioritization with senior stakeholders, deciding what gets built first.
  • Lead delivery of the centralized vulnerability management program: coverage across code, cloud, data, and edge; CSPM/DSPM, container scanning, dependency and secrets detection, and owner-based remediation routing.
  • Lead security operations delivery: expand high-risk detection and alerting, impersonation and privileged-access logging, SIEM integration, insider-risk telemetry, and logging of agentic activity.
  • Stand up daily security-health and vulnerability-management metrics dashboards and drive monthly vulnerability reporting.
  • Build security workflows that run on AI plugins by default, automating coverage checks and evidence collection.
  • Manage scope, risk, milestones, and deliver against audit and regulatory commitments.
  • Roll out new controls like risk-scored PR review, JIT privileged access, and secrets management, with training and runbooks.
  • Manage stakeholders and vendors, track program budget and tooling spend.

What We're Looking For

  • 5 to 8+ years leading cross-functional TPM or delivery work, with time spent on security, infrastructure, or platform engineering.
  • Solid handle on vulnerability management and security operations, from scanning coverage and remediation SLAs to detection engineering, SIEM/monitoring, and identity and privileged access.
  • AI plugins drive your everyday delivery, and you help others work the same way.
  • Ability to speak the language of security engineering, infrastructure, GRC, and R&D.

Nice to Have

  • Familiarity with modern security stack: Wiz, Axonius, Panther, Opal.
  • Hands-on experience using AI clients and plugins (MCPs) to generate program artifacts.
  • Working knowledge of control frameworks like SOC 1/2 and ISO 27001, plus secure SDLC practices.
  • PM certification (PMP, CAPM, Scrum, or Prosci) and time in high-growth fintech or regulated industry.

Compensation & Benefits

Cash compensation is targeted at $138,000-156,000 in Denver, and $168,000–189,000 in the San Francisco Bay Area. Stock equity is additional. Final offers vary by candidate experience and location. All full-time employees receive competitive base pay, benefits, and equity (RSUs).

Location & Work Style

This role is based in San Francisco, CA with a hybrid work schedule. Employees based in Denver, San Francisco, or New York City are expected to work from the office on designated days approximately 2-3 days per week (or more depending on role). The San Francisco office expectations encompass both San Francisco and San Jose metro areas. When approved to work remotely, a secure, reliable, and consistent internet connection is required.

Application Instructions

Apply through the Gusto Greenhouse job posting.

Skills & tags

What you can verify before applying

Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.