Fivetran 5 days ago

Technical Program Manager, Security

Salary not specified
MARKET
15,167median for this role
Cloud Engineer · 21 jobs with disclosed pay
5,233half of the offers: 6,800–15,16761,617
The employer didn't disclose pay — compare with the market yourself.
Oakland

Responsibilities

  • 01Execute the security vulnerability management program for engineering, including infrastructure, code, and dependency vulnerabilities
  • 02Collaborate with Security and Engineering teams to ensure vulnerabilities are identified, prioritized, and patched
  • 03Provide technical oversight and accountability to ensure the effective delivery of security fixes
  • 04Enhance processes by evaluating tools, recommending improvements, and driving automation for faster resolution
  • 05Usage of AI in defining the roadmap for a proactive security approach based on risk assessment/rating
  • 06Running the Dependency management and image hardening programs
  • 07Using AI to contribute to the remediation of code and infrastructure vulnerabilities
  • 08Establish and lead a code scanning program in collaboration with infrastructure, engineering, and security teams
  • 09Dedicate up to 20% of the time to assessing business systems to identify vulnerabilities and compliance gaps proactively
  • 10Develop a scanning and detection plan and establish policies and standards for internal data access tools
  • 11Advocate for tools and solutions that support shift-left strategies, driving early integration of security and testing in the development lifecycle

Requirements

  • 01Over 5 years of experience in technical program management with a strong focus on security engineering, vulnerability management, cloud security, and application security
  • 02Proficient in applying program management methodologies, tools, and best practices to deliver complex security initiatives
  • 03Exceptional skills in prioritization, organization, and multitasking to manage multiple programs effectively
  • 04Proven ability to work collaboratively with cross-functional teams, including product teams, SRE/QE engineers, and developers, to embed a security-first mindset into workflows and practices
  • 05Deep understanding of key security domains, including application/infrastructure security, data privacy, threat modeling, vulnerability management, and secure software development lifecycle (SDLC)
  • 06Strong grasp of security concepts and principles, including network security, encryption, authentication, and authorization
  • 07Hands-on experience with SAST/DAST tools, agent-based firewalls, IDS/IPS technologies, and automation tools for security orchestration
  • 08Experience with scripting languages for automating security processes
  • 09Proficient in researching and validating vulnerabilities while proposing effective remediation or mitigation strategies
  • 10Strong familiarity with OWASP principles and best practices for securing web applications, including the OWASP Top 10 vulnerabilities and Application Security Verification Standard (ASVS)
  • 11Up-to-date knowledge of market trends, emerging technologies, and best practices in cloud security
  • 12Strong analytical, problem-solving, and communication skills

What we offer

  • 01Full-time position based out of our Oakland, CA office
  • 02Hybrid work model offers a blend of remote flexibility and in-person collaboration
  • 03Two days in the office each week to connect and build as a team