Senior Technical Program Manager shaping application security at Chan Zuckerberg Initiative. Collaborating with teams to enhance security protocols for scientific and educational innovations and technology solutions.
Responsibilities
Conceive, design, develop, and improve industry-leading security tooling, automation, architecture, and/or frameworks that enable enterprise teams at scale to deliver applications and services with appropriate security controls to meet evolving requirements for security and privacy.
Identify and eliminate classes of security problems by shifting detection and prevention left into the development workflow.
Provide just-in-time, actionable, technical security guidance to enterprise application and service teams.
Ensure prioritization, resourcing, and timely delivery of work within a changing business environment.
Collaborate with cross-functional teams to ensure security work is being prioritized and addressed.
Drive end-to-end execution of technical security projects, including requirements gathering, scoping, status updates, and delivery milestones.
Establish and report metrics to track compliance, program health, and ongoing risk posture.
Coordinate with third-party vendors and auditors to augment internal security capabilities.
Serve as a subject matter expert on infrastructure, architecture, and application security, offering guidance to technical and non-technical stakeholders.
Support security reviews, threat modeling, and incident response efforts for applications and production infrastructure.
Requirements
5+ years of technical program management or equivalent experience, with a specific focus on security or application security.
Demonstrated proficiency with secure SDLC processes and best practices for integrating security throughout the software development lifecycle.
Hands-on experience designing and managing security controls within CI/CD pipelines, using automation frameworks to enable secure code delivery and rapid remediation.
Familiarity with threat modeling, static and dynamic application security testing (SAST/DAST), and software composition analysis (SCA) tools.
Deep understanding of DevSecOps principles, security automation, and infrastructure-as-code security.
Experience driving the adoption of vulnerability management, architectural best practices, and incident response for cloud-native and distributed applications.
Knowledge of container security (Docker, Kubernetes), microservices architectures, and cloud platform security (AWS, Azure, GCP).
Experience leading end-to-end security architecture design and governance across complex, cloud-native, and hybrid enterprise environments, aligning security capabilities to business and risk objectives.
Proven ability to define and maintain reference architectures, security patterns, and control standards spanning network, identity, data protection, and application security domains.
Skilled in conducting architecture risk assessments and design reviews, ensuring new and existing solutions meet zero trust, defense-in-depth, and compliance requirements in regulated industries.
Benefits
Provides a generous employer match on employee 401(k) contributions to support planning for the future.
Paid time off to volunteer at an organization of your choice.
Funding for select family-forming benefits.
Relocation support for employees who need assistance moving
Job title
Senior Technical Program Manager, Product Security
Cibersecurity Technician responsible for detecting and responding to security incidents at Telefónica Tech. Collaborating in a dynamic team while ensuring cybersecurity measures are effective.
Cybersecurity Consultant in Telefónica Tech conducting vulnerability assessments and leading remediation strategies. Collaborating with teams to prioritize security measures and enhance digital transformation.
Security Specialist ensuring compliance with security policies and procedures at AMERICAN SYSTEMS, a federal government contractor. Administering security programs, providing guidance, and managing eligibility programs.
Security Specialist at American Systems administering DoD and other industrial security programs. Providing guidance, support, and oversight for classified information protection and compliance.
IT Security Specialist responsible for day - to - day support of Hudbay’s IT security program and monitoring security risks. Collaborating on various projects to ensure security best practices are followed across the organization.
Cybersecurity Engineer specializing in Risk Management Framework operations and project management for federal clients. Role involves collaboration and leadership across multiple cybersecurity initiatives.
Manager overseeing Command Systems hardware engineering at Northrop Grumman. Driving hardware design, development, and integration for various defense projects.
Técnico em Segurança do Trabalho realizando visitas técnicas e treinamentos para elaboração do PGR e NR's. Atuando na área de segurança do trabalho na empresa Perfil Medicina.
Security Sergeant at Busch Gardens ensuring safety for guests and employees. Leading the security team in a fast - paced amusement park environment with a focus on guest service and safety.
Cybersecurity & Information Technology Faculty position at Austin Community College. Instructing students on cybersecurity principles and practices in a multicultural setting.