About the Role
We are seeking an experienced Technical Program Manager (TPM) to join our Enterprise Information Security organization and lead complex, cross-functional security and InfoSec programs.
The ideal candidate brings strong experience working within Enterprise Security / Information Security organizations and understands the unique challenges of delivering security programs across a large technology environment. This includes working across Security Engineering, GRC, Infrastructure, Cloud, Application Security, Identity & Access Management, Privacy, Compliance, Engineering, and business teams.
In addition to strong security program management capabilities, the ideal candidate will be AI-literate and enthusiastic about applying AI to the practice of project and program management. As organizations increasingly "AI-fy" project management processes, this person will help identify opportunities to use AI to improve planning, risk management, reporting, dependency management, decision-making, and overall program execution.
This is a highly collaborative role requiring someone who can operate comfortably between security leadership, technical teams, business stakeholders, and executive leadership.
Key Responsibilities
Enterprise Security Program Management
Lead complex, enterprise-wide Information Security and cybersecurity programs from initiation through implementation and operationalization.
Partner with Security leadership to define program objectives, scope, roadmaps, milestones, dependencies, and success criteria.
Drive execution across Security Engineering, GRC, Application Security, Cloud Security, Infrastructure, IAM, Privacy, Compliance, Engineering, and other stakeholder teams.
Establish program governance, operating cadence, status reporting, RAID management, and executive communications.
Manage cross-functional dependencies and proactively identify and resolve delivery risks and blockers.
Ensure security initiatives remain aligned with organizational priorities, regulatory requirements, security strategy, and business objectives.
Security & InfoSec Domain
Demonstrate a strong understanding of enterprise security organizations, processes, and operating models.
Work across programs involving areas such as:
Governance, Risk & Compliance (GRC)
Vulnerability and Risk Management
Application Security / DevSecOps
Cloud Security
Identity & Access Management (IAM)
Security Operations
Security Architecture
Data Security & Privacy
Third-Party / Vendor Risk Management
Security Assessments and Audits
Incident Response and Remediation
Security Policies, Controls, and Compliance
Partner with security teams to translate technical and regulatory requirements into actionable program plans.
Track security risks, remediation activities, control implementation, audit findings, and other security-related commitments.
Coordinate across technical and non-technical stakeholders to drive timely resolution of security issues.
Support preparation of executive-level security program reporting and risk summaries.
AI-Enabled Program Management
Identify opportunities to leverage AI and Generative AI to improve project and program management processes.
Partner with Product, Engineering, Data, and Security teams to evaluate and implement AI-enabled PM capabilities.
Explore opportunities to use AI for:
Program status reporting and summarization
Risk and issue identification
Dependency detection and management
Action-item tracking
Meeting summarization and follow-up
Project documentation
Requirements analysis
Resource and capacity planning
Schedule and milestone management
Predictive insights and program health
Executive reporting
Help define practical use cases where AI can reduce administrative overhead and improve the quality and speed of program decision-making.
Understand the limitations and risks of applying AI within enterprise security environments, including data privacy, access controls, confidentiality, security, accuracy, and responsible AI considerations.
Work with security and technology teams to ensure AI-enabled PM solutions meet enterprise security and governance requirements.
Stakeholder & Executive Management
Serve as a trusted partner to Security leadership and key technology stakeholders.
Facilitate program planning, roadmap reviews, risk reviews, steering committees, and executive meetings.
Communicate complex security initiatives clearly to both technical and non-technical audiences.
Provide concise reporting on program health, milestones, risks, dependencies, decisions, and business impact.
Drive alignment when priorities, resources, or timelines span multiple organizations.
Build strong working relationships across Security, Engineering, Product, IT, Compliance, Legal, and business teams.
Program Planning & Execution
Develop detailed program plans incorporating milestones, dependencies, resources, risks, and critical paths.
Establish appropriate KPIs and measures of program success.
Manage multiple concurrent initiatives while maintaining visibility into overall portfolio health.
Drive Agile and/or hybrid program delivery methodologies as appropriate.
Maintain program documentation, decision logs, RAID logs, roadmaps, and executive dashboards.
Conduct retrospectives and continuously improve program execution processes.
Required Qualifications
8+ years of experience in Technical Program Management, Information Security Program Management, Cybersecurity, IT, Engineering, or a related technology discipline.
Demonstrated experience leading complex enterprise security / InfoSec programs across multiple technical and business organizations.
Strong understanding of how Enterprise Security / InfoSec organizations operate, including security governance, risk management, compliance, engineering, and remediation processes.
Experience working directly with Security leadership, security engineers, architects, infrastructure teams, application teams, and business stakeholders.
Strong program management fundamentals, including planning, dependency management, risk management, executive reporting, and cross-functional execution.
Ability to understand technical security concepts and translate them into actionable program plans and business-level communications.
AI literacy, with a practical understanding of Generative AI, LLMs, AI-enabled workflows, and the opportunities and limitations of applying AI to enterprise processes.
Strong written and verbal communication skills, including the ability to communicate effectively with senior executives.
Demonstrated ability to operate independently in a complex, fast-paced enterprise environment.
Preferred Qualifications
Experience managing programs within a large-scale Enterprise Information Security organization.
Experience with security frameworks and standards such as SOC 2, ISO 27001, NIST, FedRAMP, PCI DSS, or similar.
Experience with security risk, vulnerability, compliance, audit, or remediation programs.
Experience with Application Security, Cloud Security, IAM, GRC, or Security Operations.
Experience working in a SaaS / cloud technology environment.
Experience supporting enterprise security transformation or modernization initiatives.
Experience implementing AI-enabled tools or workflows within Project, Program, Product, IT, or Security organizations.
Familiarity with AI governance, responsible AI, data privacy, and enterprise AI security considerations.
Experience with tools such as Jira, Confluence, ServiceNow, Workiva, Microsoft Project, Smartsheet, or similar program-management platforms.
PMP, PgMP, CISM, CISSP, CRISC, or similar certification is a plus.
Bachelor's or Master's degree in Computer Science, Information Systems, Cybersecurity, Engineering, or a related discipline is a plus.
Key Competencies
Enterprise Security Acumen
Understands the structure, priorities, processes, risks, and operating model of a modern Enterprise Security organization.
Program Leadership
Can lead complex, multi-team security programs from strategy through execution and operationalization.
Technical Fluency
Comfortable engaging with security engineers, architects, developers, infrastructure teams, and technical leadership.
Risk Management
Understands how to identify, prioritize, communicate, and drive remediation of security and program risks.
AI Literacy
Understands practical applications of AI and Generative AI and can identify opportunities to improve program-management effectiveness through AI.
Cross-Functional Leadership
Can influence teams and stakeholders without direct authority and create alignment across organizational boundaries.
Executive Communication
Can turn complex technical and security information into concise, actionable executive-level insights.
Process Optimization
Continuously looks for ways to improve how security programs are planned, governed, measured, and executed.
Execution Orientation
Takes ownership of outcomes and drives programs forward despite ambiguity, competing priorities, and organizational dependencies.
What Success Looks Like
Within the first 90 days, the TPM will:
Develop a strong understanding of the organization's Enterprise Security strategy, portfolio, stakeholders, and operating model.
Establish trusted relationships with Security leadership and key cross-functional partners.
Gain visibility into active security programs, dependencies, risks, and critical milestones.
Establish or improve program governance, reporting, and execution rhythms.
Identify opportunities to improve security program execution through AI-enabled capabilities and automation.
Begin implementing practical improvements that reduce program-management overhead and increase visibility, predictability, and decision-making effectiveness.
The Ideal Candidate
The ideal candidate is someone who can comfortably operate in three dimensions:
Security: Understands Enterprise InfoSec and can speak credibly with security professionals.
Program Management: Can take complex, multi-team security initiatives and drive them to measurable outcomes.
AI: Understands where AI can meaningfully improve how programs are planned and executed—and can help turn those opportunities into practical solutions.
This is not simply a project coordinator role. We are looking for a strategic, technically curious TPM who can become a trusted partner to Security leadership while helping modernize the way enterprise security programs are managed and delivered.
--