Назад
Company hidden
3 часа назад

Senior Technical Program Manager, Product Security

190 000 - 261 800$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Technical Program Manager, Product Security (Application Security/DevSecOps): Building scalable security tooling, automation, architectures, and frameworks that prevent application and infrastructure vulnerabilities across CZI’s enterprise with an accent on secure SDLC, cloud-native security, and security controls. Focus on shifting detection and prevention left, designing reference architectures and control standards, and driving end-to-end security programs across distributed applications.

Location: Redwood City, California, United States (hybrid); onsite at least 60% of the working month, approximately three days per week.

Base salary: $190,000–$261,800 per year, plus potential discretionary annual performance bonus.

Company

A mission-driven nonprofit initiative using technology, AI, and scientific and educational infrastructure to support Biohub and Learning Commons.

What you will do

  • Design, develop, and improve security tooling, automation, architectures, and frameworks for enterprise application and service teams.
  • Shift vulnerability detection and prevention into development workflows and provide actionable technical security guidance.
  • Drive end-to-end execution of technical security projects, including requirements, scoping, prioritization, milestones, and delivery.
  • Establish metrics for compliance, program health, and risk posture while coordinating with vendors and auditors.
  • Act as a subject matter expert on application, infrastructure, architecture, and cloud security.
  • Support security reviews, threat modeling, architecture assessments, and incident response.

Requirements

  • 5+ years of technical program management or equivalent experience focused on security or application security.
  • Strong knowledge of secure SDLC, DevSecOps, security automation, infrastructure-as-code security, and secure CI/CD controls.
  • Experience with threat modeling, SAST, DAST, SCA, vulnerability management, and incident response.
  • Knowledge of Docker, Kubernetes, microservices, and AWS, Azure, or GCP security.
  • Experience designing security architectures, reference architectures, security patterns, and control standards across complex cloud-native and hybrid environments.
  • Ability to conduct architecture risk assessments and design reviews aligned with zero trust, defense-in-depth, and compliance requirements.

Culture & Benefits

  • Collaborative, mission-driven, team-oriented environment with a strong focus on in-person connection.
  • Employer match on 401(k) contributions.
  • Paid time off for volunteering.
  • Funding for select family-forming benefits.
  • Relocation support is available for employees who need assistance moving.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →