Gusto

Security Technical Program Manager

Gusto$138K — $156K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-8 years of experience in cross-functional TPM or delivery roles, specifically in security or platform engineering.
  • Solid understanding of vulnerability management, security operations, and their impact on AI acceleration.
  • Familiarity with AI-driven tools and methodologies for program delivery.
  • Strong communication skills to align various technical teams and stakeholders.
  • Experience in regulated environments, demonstrating the ability to navigate ambiguity and drive projects to completion.

Responsibilities

  • Set strategy and roadmap for vulnerability management and security operations.
  • Lead delivery of a centralized vulnerability management program across various domains.
  • Expand security operations monitoring and alerting across systems and vendors.
  • Develop daily metrics dashboards to manage security health and vulnerabilities.
  • Build AI-driven workflows for automated security coverage checks.
  • Manage stakeholder expectations and program budgets effectively.
  • Ensure timely updates and alignment among fast-moving teams.

Benefits

  • Work-life balance with designated in-office days for collaboration.
  • Opportunity to drive AI initiatives in a complex, regulated environment.
  • Work in a strategically significant program that shapes Gusto's security posture.
  • Access to advanced AI tools that streamline program execution.
  • Engagement with cross-functional teams to enhance collaborative solutions.
Full Job Description
About the Role:

Gusto is becoming an AI-native company, and that only works if our security posture keeps pace. As the Security TPM, you'll own the definition and delivery of Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk. You'll drive the centralized vulnerability scorecard, expand detection and monitoring coverage, harden the SDLC, and stand up the security metrics leadership runs the business on. You'll drive the timelines, manage the dependencies, head off the risk, and use AI plugins to do the work itself, so security becomes something that helps Gusto move faster instead of slowing it down.

About the Team:

The TPM organization is part of our AIT, Risk, and Security team. We deliver the cross-functional work that lets Gusto securely accelerate its AI and platform modernization. The vulnerability management and security operations programs sit right at the intersection of security engineering, infrastructure, and GRC, and they're foundational to how Gusto scales its AI ambitions safely. This is one of the most strategic programs on the team, and you'll lead it across a complex, fast-moving group of stakeholders.

Here's what you'll do day-to-day:

Set the strategy and the roadmap

Work with leaders across Security, AIT, R&D, Infrastructure, GRC, and Risk to shape where vulnerability management and security operations go as Gusto becomes an AI-native company.Define what good vulnerability management and security operations look like for an AI-first business, and set the multi-quarter vision that gets us there.Run intake and prioritization with senior stakeholders, and make the call on what gets built first.Decide where security should clear the way for AI speed and where it needs to hold the line, and bring leaders along on the why.Put AI plugins to work to pull together stakeholder input, map dependencies, and keep the roadmap grounded in what's really happening.

Run the programs and the change
  • Lead delivery of the centralized vulnerability management program: coverage across code, cloud, data, and edge; CSPM/DSPM, container scanning, dependency and secrets detection, and owner-based remediation routing to closure.
  • Lead security operations delivery: expand high-risk detection and alerting across systems and vendors, impersonation and privileged-access logging, SIEM integration, insider-risk telemetry, and logging of agentic activity.
  • Stand up the daily security-health and vulnerability-management metrics dashboards leadership uses to run the business, and drive monthly vulnerability reporting.
  • Build security workflows that run on AI plugins by default, so coverage checks and evidence collection happen automatically instead of by hand.
  • Build the plans, manage scope and risk, track milestones, and deliver against every audit and regulatory commitment.
  • Roll out new controls, like risk-scored PR review, JIT privileged access, and secrets management, and help teams adopt them with training, comms, and runbooks that plugins keep up to date for you.
  • Keep a busy, fast-moving group of stakeholders aligned with clear, steady updates on where things stand.

Manage stakeholders and vendors
  • Hold vendors and partners to their commitments and push them toward AI-forward ways of working.
  • Stay on top of how every workstream is tracking, raise flags early, and get teams unstuck when they stall.
  • Watch the program budget, tooling spend, and implementation costs.

Here's what we're looking for:

You'll need
  • A history of taking programs from ambiguous to shipped in regulated environments.
  • 5 to 8+ years leading cross-functional TPM or delivery work, with real time spent on security, infrastructure, or platform engineering.
  • A solid handle on vulnerability management and security operations, from scanning coverage and remediation SLAs to detection engineering, SIEM/monitoring, and identity and privileged access, and a sense for how they help Gusto move faster on AI.
  • A way of working where AI plugins drive your everyday delivery, and you help the people around you work the same way.
  • The ability to speak the language of security engineering, infrastructure, GRC, and R&D, and keep everyone rowing together.

Nice to have
  • Familiarity with the modern security stack, including vulnerability and asset scanners (e.g., Wiz, Axonius), code security (dependency and secret scanning), SIEM/detection (e.g., Panther), and identity/JIT access (e.g., Opal).
  • Hands-on experience using AI clients and plugins (MCPs) to generate program artifacts and take the busywork off your plate.
  • A working knowledge of control frameworks like SOC 1/2 and ISO 27001, plus secure SDLC practices.
  • A PM certification (PMP, CAPM, Scrum, or Prosci) and time spent in high-growth fintech or another regulated, fast-paced industry.

Our cash compensation amount for this role is targeted at $138,000-156,000 in Denver, and $168,000-189,000 in the San Francisco Bay Area. Stock equity is additional. Final offer amounts are determined by multiple factors including candidate experience and expertise and may vary from the amounts listed above.

Gusto has physical office spaces in Denver, San Francisco, and New York City. Employees who are based in those locations will be expected to work from the office on designated days approximately 2-3 days per week (or more depending on role). The same office expectations apply to all Symmetry roles, Gusto's subsidiary, whose physical office is in Scottsdale.

Note: The San Francisco office expectations encompass both the San Francisco and San Jose metro areas.

When approved to work from a location other than a Gusto office, a secure, reliable, and consistent internet connection is required. This includes non-office days for hybrid employees.

About Gusto

Gusto is a cloud-based human resources software platform that provides payroll, benefits, and HR management services to small businesses. The company was founded in 2011 and is headquartered in San Francisco, California. Gusto's platform automates many of the administrative tasks associated with HR, such as payroll processing, tax filings, and benefits administration. The company also offers a range of HR services, including compliance support, employee onboarding, and time tracking. Gusto is committed to helping small businesses succeed by providing them with the tools and resources they need to manage their HR operations more efficiently.
Learn more about Gusto
Size
1,000 employees
Industry
Founded
2012

Similar Jobs

More Jobs at Gusto

More Information Technology Jobs

Find similar Security Technical Program Manager jobs: