SailPoint Technologies

Senior Technical Program Manager, Security

SailPoint Technologies$97K — $165K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of technical program management experience, especially in security
  • Experience managing 10+ concurrent initiatives with cross-functional dependencies
  • Familiarity with security program domains like application security and DevSecOps
  • Proficiency in using Jira, Confluence, and other program management tools
  • Strong written communication and executive reporting skills

Responsibilities

  • Own end-to-end execution of over 12 concurrent product security initiatives
  • Maintain an up-to-date initiative roadmap and track weekly progress
  • Map and manage cross-team dependencies across various engineering sectors
  • Build relationships with engineering leaders for seamless coordination
  • Manage the vendor procurement pipeline with clear statuses and timelines
  • Drive vendor engagements through evaluations and decision-making processes
  • Track BAU activities against capacity to inform resource allocation

Benefits

  • Opportunity to build an industry-leading security program from the ground up
  • Responsibilities that involve real program complexity across numerous initiatives
  • Engagement with a dedicated team of security professionals
  • Collaboration with an experienced Director who prioritizes effective program management
  • A focus on identity security as a critical aspect of the business
Full Job Description
This is a remote role within the United States. Due to FedRAMP requirements, this role requires US citizenship.

About the Role

SailPoint is looking for a Technical Program Manager to serve as the operational backbone of a product security program running 12+ concurrent initiatives, a growing portfolio of BAU security operations, and coordination across every engineering organization in the company. You will drive execution across security architecture reviews, tooling evaluations, vendor procurements, pipeline buildout, and cross-functional programs spanning Product, Engineering, DevOps, Platform Engineering, and the CISO organization-work that goes well beyond routine status reporting.

The program spans near-term initiatives (production access controls, red team vendor engagement, SCM migration, CI/CD security gates, cloud asset tagging, MCP gateway, API gateway reviews), mid-term initiatives (customer code governance, BYOK architecture, reference architecture standup, non-human identity program), and continuous BAU activities (design reviews, security architecture reviews, AI security reviews, security champions, metrics and reporting, red team operations). You will own the operational rhythm that keeps all of this moving forward without anything falling through the cracks.

About the Team

You will join our Engineering Operations team-the group that keeps SailPoint's engineering organization secure, compliant, and audit-ready as we scale. Engineering Operations sits at the intersection of Engineering, Product, and Compliance, removing friction, standardizing process, and ensuring the right evidence and controls are in place without slowing teams down.

In this role, you will work closely with Engineering Managers, security operations, platform teams, and leaders across Engineering and Cybersecurity. Together, we aim for predictable remediation throughput, transparent risk visibility, and a vulnerability management program that keeps pace with our product and cloud footprint.

Responsibilities
  • Own end-to-end execution of 12+ concurrent product security initiatives across near-term, mid-term, and continuous horizons, keeping each with a current status, next milestone, owner, timeline, and documented dependencies.
  • Maintain the initiative roadmap as a living document, run the weekly tracking cadence, flag drifting work, and escalate blockers before they become delays.
  • Map and actively manage cross-team dependencies across DevOps, Platform Engineering, FinOps, Architecture, Product, Engineering Directors, and the CISO organization.
  • Build trusted relationships with engineering leaders whose teams support active initiatives, making cross-team coordination frictionless rather than adding process.
  • Manage the full vendor and procurement pipeline, giving every engagement a clear status, next action, owner, and timeline, and eliminating procurement surprises.
  • Drive vendor engagements through the front door process, coordinating evaluators, scoping POCs, compiling results, and preparing decision packages for leadership.
  • Track recurring BAU work - design and architecture reviews, AI security reviews, red team operations, security champions, and metrics - against capacity so the Director can see where the team has room for additional work.
  • Produce executive-ready status updates, quarterly program reviews, and decision packages that leadership uses to evaluate program health and make investment decisions.
  • Steer the program with data such as aging, throughput, and SLA adherence, sizing risk in concrete terms for both technical and executive audiences.
  • Build and maintain program tracking in Jira and Confluence, establish a consistent intake process for new initiatives, and apply AI-assisted workflows with sound judgment about when automation helps and when human oversight is required.


Roadmap for Success

By 30 days - Discovery & Assessment:
  • Complete a thorough review of the initiative roadmap (12 initiatives across near-term and mid-term horizons), the BAU tracker (10 recurring activities with quarterly load allocations), and the quarter map that sequences all work. Understand the dependencies between initiatives, the staffing model, and where capacity is tight.
  • Map every cross-team dependency. This program touches DevOps, Platform Engineering, FinOps, Architecture, Product, Engineering Directors, the CISO organization, and multiple vendor relationships. Build the dependency map and identify which dependencies are on track, at risk, or blocked.
  • Review every active procurement and POC. Understand where each vendor engagement sits in the front door process, what the evaluation timeline looks like, who the decision makers are, and what approvals are still outstanding.
  • Establish the communication rhythm. Learn how the Director communicates with leadership and calibrate your reporting to support that cadence.


By 60 days - Own the Rhythm:
  • Take full ownership of the weekly initiative tracking cadence. Run the weekly sync, maintain the roadmap tracker, flag initiatives that are drifting, and escalate blockers before they become delays.
  • Drive at least one active procurement to completion or to the next milestone (vendor contract executed, POC scoped, or evaluation results compiled). Demonstrate that you can navigate the procurement process, coordinate evaluators, and deliver a decision package.
  • Build working relationships with every engineering director whose team is a dependency for an active initiative. They should know your name, understand your role, and see you as the person who makes cross-team coordination frictionless rather than adding process.


By 90 days - Program Structure & Execution:
  • Full operational ownership of all 12 initiatives. Every initiative has a current status, a next milestone, an owner, a timeline, and a documented set of dependencies and blockers. Nothing is stale. Nothing is untracked.
  • BAU load tracking operational. The team's recurring work (design reviews, architecture reviews, AI security reviews, red team operations, security champions, metrics) is tracked against capacity so the Director can see where the team is at capacity and where there is room for additional initiative work.
  • Vendor and procurement pipeline fully managed. Every active vendor engagement has a clear status, next action, owner, and timeline. Procurement surprises are eliminated.
  • First quarterly program review prepared and delivered. Compile the quarter's progress into a single executive-ready document: initiatives completed, initiatives in flight, metrics movement, staffing utilization, and the plan for the next quarter.


By 6 months - Program Operating System:
  • The initiative roadmap is a living document that the entire team and stakeholders reference. Initiatives move between phases on a predictable cadence. New initiatives are scoped, staffed, and sequenced using a consistent intake process rather than ad hoc prioritization.
  • Cross-team dependencies are managed proactively. Engineering directors, DevOps, Platform Engineering, and the CISO organization experience the security program as organized and predictable rather than reactive. Commitments are tracked and met.
  • Metrics and reporting are automated or semi-automated. The Director's executive updates, the team's KPI dashboard, and the initiative health tracker are maintained continuously, not assembled in a rush before each reporting cycle.
  • At least two initiatives have been driven to completion under your program management, with documented outcomes, lessons learned, and the transition to BAU or closure clearly executed.


By 1 year - Strategic Program Partner:
  • The product security program operates with the organizational discipline of a program three times its size. Initiatives are planned quarterly, tracked weekly, and reported on a cadence that leadership trusts. The Director spends time on strategy and stakeholder relationships, not on initiative tracking and cross-team coordination, because you own that entirely.
  • You are recognized by engineering leadership as the person who makes the security program operationally credible. When someone asks 'where does the security program stand on X,' they come to you, and you have the answer.
  • Program planning for the next fiscal year is driven by you. You compile the initiative proposals, the staffing model, the capacity analysis, and the quarter map for the Director's review and approval. The Director defines strategy; you translate strategy into an executable plan.
  • Backlog and emerging items are actively managed. The pipeline of future work is scoped, sized, and sequenced so that when an emerging item becomes urgent, the intake process is ready.


To Be Successful in This Role You Must:
  • Stay highly organized-you will coordinate work across multiple Engineering and Security teams at the same time.
  • Bring deep program management experience in a fast-moving technology organization, with credibility in security or infrastructure contexts.
  • Apply strong technical judgment on vulnerability severity, remediation trade-offs, and cloud-native security risk.
  • Build trusted relationships across Engineering and Security; this is a people-facing role that drives outcomes through influence.
  • Communicate clearly to both technical and executive audiences, including sizing risk in concrete terms.
  • Stay data-driven-use metrics such as aging, throughput, and service-level agreement (SLA) adherence to steer the program, not anecdotes.
  • Have deep experience with Jira and Confluence as the backbone of program planning and reporting.


Requirements
  • 7+ years of technical program management experience, with at least 3 years managing security, infrastructure, or platform engineering programs.
  • Demonstrated experience managing 10+ concurrent initiatives with cross-functional dependencies across engineering organizations.
  • Experience managing vendor procurement processes for security or engineering tooling, including evaluations, POCs, and contract execution.
  • Familiarity with security program domains: application security, cloud security, DevSecOps, vulnerability management, and identity/access management. You do not need to be a practitioner, but you need to understand the landscape.
  • Proficiency with program management tooling (Jira, Confluence, spreadsheet-based trackers) and the ability to build and maintain program tracking without dedicated PMO infrastructure.
  • Strong written communication. You will produce the executive status updates, quarterly reviews, and decision packages that leadership uses to evaluate program health and make investment decisions.
  • Bachelor's degree in a relevant field or equivalent experience.


Desired Qualifications
  • Experience building or maturing a security, infrastructure, or platform program operating model - intake, quarterly planning, weekly execution rhythm, BAU transition, and portfolio capacity planning across concurrent initiatives.
  • Prior ownership of DevSecOps, CI/CD security, or SCM/toolchain programs (e.g., pipeline security gates, developer tooling migration, cloud asset governance).
  • Identity and access security program coordination, including production access controls, non-human identity, or similar IAM-adjacent initiatives.
  • Experience coordinating security review and operations programs - design/architecture reviews, AI security reviews, red team vendor engagement, and security champions.
  • Track record delivering executive quarterly program reviews, procurement decision packages, and semi-automated metrics reporting (aging, throughput, SLA adherence) for security or engineering programs.
  • SaaS or enterprise product security experience in audit- or compliance-sensitive environments, with demonstrated ability to influence engineering leadership and resolve cross-org dependencies without direct authority.
  • Hands-on experience using AI-assisted and agent-orchestrated workflows to accelerate planning, tracking, and communication across complex, multi-team programs, with sound judgment about when automation helps and when human oversight is required.
  • Proven ability to design and maintain program tracking in Jira and Confluence that drives accountability and executive-ready visibility.


Why Join Us
  • Build the operating system for an industry-leading security program. This is a greenfield security program with executive sponsorship, a funded roadmap, and a Director who needs a program partner, not a project coordinator. You will build the operational muscle of the program, not inherit someone else's process.
  • Real program complexity, not project management dressed up. The roadmap spans 12 initiatives, 10 BAU activities, and 5+ vendor engagements across a two-year horizon. You will run a portfolio-not manage one project at a time.
  • Identity is the attack surface that matters most. SailPoint's platform governs access for thousands of enterprises and millions of identities. The program you manage protects the trust those customers place in the platform.
  • A team that takes security seriously. You will work alongside security architects, a red team, security engineers, and a security champions program. The team is technically deep and operationally committed-and needs someone who can match their intensity on the program side.
  • Work with a leader who gets it. You'll partner with a Director who has built security programs at scale and understands that program management is a force multiplier, not overhead. Your role will be valued, resourced, and defended.


Benefits and Compensation listed vary based on the location of your empl

About SailPoint Technologies

SailPoint Technologies Holdings, Inc. is an American software company that provides identity management solutions for enterprises. SailPoint's open identity platform gives organizations the power to enter new markets, scale their workforces, embrace new technologies, innovate faster and compete on a global basis. As both an industry pioneer and market leader in identity governance, SailPoint delivers security, operational efficiency and compliance to enterprises with complex IT environments. SailPoint's customers are among the world's largest companies in a wide range of industries, including: 7 of the top 15 banks, 4 of the top 6 healthcare insurance and managed care providers, 9 of the top 15 property and casualty insurance providers, 5 of the top 15 pharmaceutical companies, and 11 of the largest 15 federal agencies.
Learn more about SailPoint Technologies
Size
1,676 employees
Market Cap
$6 billion
Industry
Net Income
-$10.7 million
Founded
2005
5 Year Trend
+27.1%
Revenue
$365.2 million
NASDAQ

Similar Jobs

More Jobs at SailPoint Technologies

More Information Technology Jobs

Find similar Senior Technical Program Manager, Security jobs: