Skip to main content

Technical Program Manager, Security

Fivetran
Hybrid - Oakland, CA, 2 days/weekUpdated 8d ago
Compensation
$158k–$198k
Published range
Location
Hybrid - Oakland, CA, 2 days/week
Remote eligibility
Employment
Full-time
Senior
Role family
Security
B2B SaaS
Role skills
Apply on fivetran.com
Job actionsApply now
Job actionsApply now

About the job

About the Role

Fivetran + dbt is building data pipelines to power the modern data stack for thousands of companies. We’re looking for a high-performance, experienced hands-on technical program manager (TPM) in the security domain to be part of an Engineering team. In this role, you will be responsible for leading and managing security-related initiatives across the organization. It involves collaborating with cross-functional teams to ensure the successful planning, execution, and delivery of security programs. The TPM will act as a bridge between technical teams and business stakeholders, ensuring alignment with organizational goals while mitigating security risks. The work is very diverse. Fivetran is a multi-cloud environment operating on AWS, GCP, and Azure. You will help select security tools, implement improvements within our environments, and assist in developing new processes to increase our security posture.

What You’ll Do

  • This is the primary person in engineering responsible for executing the security vulnerability management program for engineering, including infrastructure, code, and dependency vulnerabilities.
  • Collaborate with Security and Engineering teams to ensure vulnerabilities are identified, prioritized, and patched.
  • Provide technical oversight and accountability to ensure the effective delivery of security fixes.
  • Enhance processes by evaluating tools, recommending improvements, and driving automation for faster resolution.
  • Usage of AI in defining the roadmap for a proactive security approach based on risk assessment/rating.
  • Running the Dependency management and image hardening programs.
  • Using AI to contribute to the remediation of code and infrastructure vulnerabilities.
  • Establish and lead a code scanning program in collaboration with infrastructure, engineering, and security teams to ensure seamless integration and sustainable security practices.
  • Dedicate up to 20% of the time to assessing business systems to identify vulnerabilities and compliance gaps proactively.
  • Develop a scanning and detection plan and establish policies and standards for internal data access tools to improve overall system security.
  • Advocate for tools and solutions that support shift-left strategies, driving early integration of security and testing in the development lifecycle.

Skills We’re Looking For

  • Over 5 years of experience in technical program management with a strong focus on security engineering, vulnerability management, cloud security, and application security.
  • Proficient in applying program management methodologies, tools, and best practices to deliver complex security initiatives.
  • Exceptional skills in prioritization, organization, and multitasking to manage multiple programs effectively.
  • Proven ability to work collaboratively with cross-functional teams, including product teams, SRE/QE engineers, and developers, to embed a security-first mindset into workflows and practices.
  • Deep understanding of key security domains, including application/infrastructure security, data privacy, threat modeling, vulnerability management, and secure software development lifecycle (SDLC).
  • Strong grasp of security concepts and principles, including network security, encryption, authentication, and authorization.
  • Hands-on experience with SAST/DAST tools, agent-based firewalls, IDS/IPS technologies, and automation tools for security orchestration.
  • Experience with scripting languages for automating security processes.
  • Proficient in researching and validating vulnerabilities while proposing effective remediation or mitigation strategies.
  • Strong familiarity with OWASP principles and best practices for securing web applications, including the OWASP Top 10 vulnerabilities and Application Security Verification Standard (ASVS).
  • Up-to-date knowledge of market trends, emerging technologies, and best practices in cloud security.
  • Strong analytical, problem-solving, and communication skills to address security challenges, coupled with the ability to influence and collaborate effectively with engineering teams in enhancing security measures and mitigating vulnerabilities in a dynamic, fast-paced environment.

Technologies You’ll Use

Bash, Python, JS, BigQuery, Looker, Sigma, Azure, AWS, GCP, Terraform, Docker, Kubernetes, Github, Buildkite, SonarQube, Grafana, Prisma, Synk, Signal Sciences, AI Tools

Compensation & Benefits

Oakland Pay Range: $158,284—$197,855 USD. Perks and Benefits: 100% employer-paid medical insurance*, generous paid time away from work, including paid vacation or flexible/unlimited vacation depending on role and country, plus paid sick time, inclusive parental leave, paid holidays, including a year-end Global Week of Rest, and volunteer days off. RSU stock grants*, professional development and training opportunities, company virtual happy hours, free food, and fun team-building activities, monthly cell phone stipend, access to an innovative mental health support platform that offers personalized care and resources in areas such as: therapy, coaching, and self-guided mindfulness exercises for all covered employees and their covered dependents. *May vary by country and worker type - please reach out to your recruiter for more information.

Application Instructions

Apply through the Fivetran careers page for this role.

Skills & tags

What you can verify before applying

Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.