Gusto

Gusto

Security Technical Program Manager

Denver, CO;San Francisco, CA · Full-time

Sponsorship not specified$138k-$156kDetected 2 days ago
CybersecuritySIEMSOC OperationsDetection EngineeringComplianceAgileRecruitingLeadership

About the role

  • Gusto is becoming an AI-native company, and that only works if our security posture keeps pace.
  • The TPM organization is part of our AIT, Risk, and Security team.
  • The vulnerability management and security operations programs sit right at the intersection of security engineering, infrastructure, and GRC, and they're foundational to how Gusto scales its AI ambitions safely.

Responsibilities

  • As the Security TPM, you'll own the definition and delivery of Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk.
  • You'll drive the timelines, manage the dependencies, head off the risk, and use AI plugins to do the work itself, so security becomes something that helps Gusto move faster instead of slowing it down.
  • Build the plans, manage scope and risk, track milestones, and deliver against every audit and regulatory commitment.
  • Manage stakeholders and vendors
  • With teams in Denver, San Francisco, and New York, we support more than 500,000 small businesses nationwide and are building a workplace that reflects the people we serve.

Requirements

  • 5 to 8+ years leading cross-functional TPM or delivery work, with real time spent on security, infrastructure, or platform engineering.
  • The ability to speak the language of security engineering, infrastructure, GRC, and R&D, and keep everyone rowing together.

Nice to have

  • Hands-on experience using AI clients and plugins (MCPs) to generate program artifacts and take the busywork off your plate.
  • A working knowledge of control frameworks like SOC 1/2 and ISO 27001, plus secure SDLC practices.
  • A PM certification (PMP, CAPM, Scrum, or Prosci) and time spent in high-growth fintech or another regulated, fast-paced industry.
  • Our cash compensation amount for this role is targeted at $138,000-156,000 in Denver, and $168,000-189,000 in the San Francisco Bay Area.
  • Final offer amounts are determined by multiple factors including candidate experience and expertise and may vary from the amounts listed above.
  • Gusto has physical office spaces in Denver, San Francisco, and New York City.
  • The same office expectations apply to all Symmetry roles, Gusto's subsidiary, whose physical office is in Scottsdale.
  • Note: The San Francisco office expectations encompass both the San Francisco and San Jose metro areas.

Compensation

  • All full-time employees receive competitive base pay, benefits, and equity (RSUs) — because everyone who helps build Gusto should share in its success.

Benefits

  • We handle the hard stuff - payroll, health insurance, 401(k)s, and HR - so owners can focus on their craft and their customers.
  • All full-time employees receive competitive base pay, benefits, and equity (RSUs) - because everyone who helps build Gusto should share in its success.
  • Learn more about our Total Rewards philosophy.
  • Stand up the daily security-health and vulnerability-management metrics dashboards leadership uses to run the business, and drive monthly vulnerability reporting.
  • Build security workflows that run on AI plugins by default, so coverage checks and evidence collection happen automatically instead of by hand.
  • Define what good vulnerability management and security operations look like for an AI-first business, and set the multi-quarter vision that gets us there.
  • You'll drive the centralized vulnerability scorecard, expand detection and monitoring coverage, harden the SDLC, and stand up the security metrics leadership runs the business on.

Company info

  • We deliver the cross-functional work that lets Gusto securely accelerate its AI and platform modernization.
  • This is one of the most strategic programs on the team, and you'll lead it across a complex, fast-moving group of stakeholders.
  • Here's what you'll do day-to-day:
  • Set the strategy and the roadmap
  • Work with leaders across Security, AIT, R&D, Infrastructure, GRC, and Risk to shape where vulnerability management and security operations go as Gusto becomes an AI-native company.
  • Run intake and prioritization with senior stakeholders, and make the call on what gets built first.
  • Decide where security should clear the way for AI speed and where it needs to hold the line, and bring leaders along on the why.
  • Put AI plugins to work to pull together stakeholder input, map dependencies, and keep the roadmap grounded in what's really happening.
  • Run the programs and the change
  • Lead delivery of the centralized vulnerability management program: coverage across code, cloud, data, and edge; CSPM/DSPM, container scanning, dependency and secrets detection, and owner-based remediation routing to closure.
  • Lead security operations delivery: expand high-risk detection and alerting across systems and vendors, impersonation and privileged-access logging, SIEM integration, insider-risk telemetry, and logging of agentic activity.

This listing is sourced directly from Gusto's careers page and normalized into a canonical job model.