Назад
Company hidden
обновлено 8 дней назад

Technical Program Manager (Security)

158 284 - 197 855$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Technical Program Manager (Security) (Cloud and Application Security): Leading vulnerability management, code scanning, dependency management, and image hardening programs across a multi-cloud engineering environment with an accent on security automation, risk assessment, and cross-functional delivery. Focus on building proactive security roadmaps with AI, integrating shift-left security practices, and driving remediation of code and infrastructure vulnerabilities.

Location: Oakland, California, United States. Hybrid schedule with two days in the office each week.

Salary: $158,284–$197,855 USD per year.

Company

hirify.global and dbt Labs build data infrastructure that helps organizations move, transform, govern, and use data for analytics and AI.

What you will do

  • Lead the engineering security vulnerability management program across infrastructure, code, and dependencies.
  • Collaborate with Security and Engineering teams to identify, prioritize, patch, and remediate vulnerabilities.
  • Evaluate security tools, improve processes, and drive automation for faster resolution.
  • Run dependency management and image-hardening programs, using AI to support risk assessment and vulnerability remediation.
  • Establish and lead a code-scanning program with infrastructure, engineering, and security stakeholders.
  • Assess business systems, identify compliance gaps, define scanning and detection plans, and promote shift-left security practices.

Requirements

  • More than 5 years of technical program management experience focused on security engineering, vulnerability management, cloud security, and application security.
  • Experience delivering complex security initiatives using program management methodologies and best practices.
  • Strong understanding of application and infrastructure security, data privacy, threat modeling, vulnerability management, and secure SDLC practices.
  • Knowledge of network security, encryption, authentication, authorization, OWASP principles, OWASP Top 10, and ASVS.
  • Hands-on experience with SAST/DAST tools, firewalls, IDS/IPS technologies, security orchestration, and scripting for security automation.
  • Strong analytical, communication, prioritization, and cross-functional collaboration skills.

Culture & Benefits

  • Hybrid work model combining remote flexibility with in-person collaboration.
  • Employer-paid medical insurance, subject to country and worker type.
  • Paid vacation or flexible/unlimited vacation depending on role and country, paid sick time, parental leave, holidays, and volunteer days.
  • RSU stock grants and professional development opportunities.
  • Cell phone stipend and mental health support for employees and covered dependents.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →