Security Technical Program Manager

Gusto Gusto · Fintech · Denver, CO +1 · Engineering

Security Technical Program Manager at Gusto, a fintech company aiming to be AI-native. This role focuses on defining and delivering vulnerability management and security operations programs to support AI initiatives. Responsibilities include strategy setting, program delivery, stakeholder management, and leveraging AI plugins to enhance security processes and accelerate development in a regulated environment.

What you'd actually do

  1. Set the strategy and the roadmap
  2. Lead delivery of the centralized vulnerability management program: coverage across code, cloud, data, and edge; CSPM/DSPM, container scanning, dependency and secrets detection, and owner-based remediation routing to closure.
  3. Lead security operations delivery: expand high-risk detection and alerting across systems and vendors, impersonation and privileged-access logging, SIEM integration, insider-risk telemetry, and logging of agentic activity.
  4. Stand up the daily security-health and vulnerability-management metrics dashboards leadership uses to run the business, and drive monthly vulnerability reporting.
  5. Build security workflows that run on AI plugins by default, so coverage checks and evidence collection happen automatically instead of by hand.

Skills

Required

  • History of taking programs from ambiguous to shipped in regulated environments
  • 5 to 8+ years leading cross-functional TPM or delivery work, with real time spent on security, infrastructure, or platform engineering
  • Solid handle on vulnerability management and security operations, from scanning coverage and remediation SLAs to detection engineering, SIEM/monitoring, and identity and privileged access, and a sense for how they help Gusto move faster on AI
  • Way of working where AI plugins drive your everyday delivery, and you help the people around you work the same way
  • Ability to speak the language of security engineering, infrastructure, GRC, and R&D, and keep everyone rowing together

Nice to have

  • Familiarity with the modern security stack, including vulnerability and asset scanners (e.g., Wiz, Axonius), code security (dependency and secret scanning), SIEM/detection (e.g., Panther), and identity/JIT access (e.g., Opal)
  • Hands-on experience using AI clients and plugins (MCPs) to generate program artifacts and take the busywork off your plate
  • Working knowledge of control frameworks like SOC 1/2 and ISO 27001, plus secure SDLC practices
  • PM certification (PMP, CAPM, Scrum, or Prosci) and time spent in high-growth fintech or another regulated, fast-paced industry

What the JD emphasized

  • regulated environments
  • security, infrastructure, or platform engineering
  • vulnerability management and security operations
  • AI plugins drive your everyday delivery
  • SOC 1/2 and ISO 27001