Security Technical Program Manager

Sierra Sierra · AI Frontier · San Francisco, CA · Engineering

This role is for a Security Technical Program Manager at Sierra, a company building an AI platform for customer experiences. The TPM will drive security and infrastructure initiatives, own program execution, shape security strategy, build security foundations, and translate ambiguity into clear execution, particularly in emerging AI domains. They will collaborate with engineering, security, GRC, product, GTM, legal, and executive leadership. Required technical fluency includes cloud infrastructure, IAM, observability, and secure CI/CD. Experience scaling security programs in AI-first or data-intensive SaaS environments, and exposure to AI risk and model security are preferred.

What you'd actually do

  1. Drive high-impact security and infrastructure initiatives end-to-end. **Lead complex, cross-functional programs spanning cloud infrastructure, platform security, identity and access management, detection and response, vulnerability management, and secure software delivery from problem definition through execution and sustained outcomes.
  2. Own execution, planning, and program health. Be accountable for sequencing work, managing dependencies, tracking risk, and ensuring delivery of Sierra’s most critical security programs, with clear milestones and outcomes.
  3. Help shape Sierra’s security strategy. Partner with security and engineering leadership to define priorities, investment areas, and execution plans that align risk reduction with platform growth, customer trust, and long-term scalability.
  4. Build and strengthen security foundations. Drive programs that establish durable security primitives such as identity boundaries, access controls, logging and detection baselines, incident readiness, and secure defaults that future teams and features can confidently build on.
  5. Translate ambiguity into clear execution. Decompose loosely defined security, risk, and compliance challenges particularly in emerging AI domains into structured programs, prioritized workstreams, and measurable outcomes.

Skills

Required

  • Experience running security-focused technical programs in fast-growing SaaS or platform environments.
  • Strong technical fluency across cloud infrastructure, IAM, infrastructure as code, observability, secure CI/CD, and incident response.
  • Ability to execute through ambiguity, prioritize effectively, and keep teams moving.
  • Comfort operating in environments where things aren’t fully built yet and helping decide what needs to be built first.
  • Clear, concise communication with senior technical and business leaders.
  • A collaborative, pragmatic style with high ownership and high agency.

Nice to have

  • Experience scaling security programs globally in AI-first or data-intensive SaaS environments.
  • Exposure to emerging AI risk, data governance, or agent and model-related security considerations.
  • Experience supporting security initiatives in public-sector, regulated and/or multi-cloud environments (AWS, GCP, Azure).
  • Relevant security, cloud, AI or technical program management certifications.
  • Familiarity with regulatory and compliance frameworks (ISO 27001, PCI DSS, FedRAMP, HIPAA).

What the JD emphasized

  • emerging AI domains
  • AI landscape
  • agent and model-related security considerations
  • security-focused technical programs
  • technical fluency across cloud infrastructure, IAM, infrastructure as code, observability, secure CI/CD, and incident response
  • scaling security programs globally in AI-first or data-intensive SaaS environments
  • emerging AI risk, data governance, or agent and model-related security considerations
  • public-sector, regulated and/or multi-cloud environments (AWS, GCP, Azure)
  • regulatory and compliance frameworks (ISO 27001, PCI DSS, FedRAMP, HIPAA)