Senior Technical Program Manager, Security
Foster City, CA • FullTime
Posted 5h ago
Job Location
Foster City, CA
Tech Stack
Remote Work Policy
On-site
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Replit is seeking a Senior Technical Program Manager to own their vulnerability management program end-to-end. This role involves driving vulnerability intake, triage, remediation, and reporting across bug bounty programs, Google Cloud Platform (GCP) infrastructure, GitHub-hosted source code, and third-party SaaS services. You will collaborate closely with platform engineering, product engineering, SRE, security, IT, legal, and vendor management to ensure vulnerabilities are identified, triaged, and resolved within SLAs, while providing leadership with a clear understanding of the organization's risk posture. The ideal candidate will leverage AI and automation to scale their efforts, prioritizing clarity, trade-offs, and execution.
Responsibilities
- Own and improve the vulnerability management program, including intake, severity scoring, SLA definition, and remediation tracking.
- Manage bug bounty operations, including triage, payouts, rewards, and program health reporting.
- Drive GCP infrastructure vulnerability remediation by partnering with security, cloud, and platform engineering teams.
- Coordinate remediation of vulnerabilities in code and supply chain risks identified through SAST/DAST/SCA tooling.
- Build and manage the process for assessing and tracking security posture of third-party SaaS applications.
- Define and enforce escalation paths for overdue or critical findings, including risk acceptance and exception processes.
- Partner with engineering managers and tech leads to integrate remediation work into sprint planning and ensure SLA compliance.
- Establish and maintain a central source of truth for vulnerability status, aging, SLA compliance, and risk trends with dashboards.
- Support audit and compliance efforts by ensuring vulnerability management evidence and metrics are audit-ready.
- Drive process improvements and automation to reduce manual triage effort and improve remediation times.
Requirements
- 4-6+ years of experience in technical program management, security program management, or security operations, with direct ownership of a vulnerability management or application security program.
- Hands-on experience running a bug bounty program (e.g., HackerOne, Bugcrowd, Intigriti), including triage and payout workflows.
- Working knowledge of GCP security fundamentals: IAM, VPC/networking, Security Command Center, Cloud Logging/Monitoring, and common cloud misconfiguration risks.
- Familiarity with GitHub-based development workflows and code security tooling (Wiz Code, Dependabot, SAST/DAST/SCA tools such as Snyk, Semgrep, or CodeQL).
- Strong grasp of vulnerability scoring frameworks (CVSS) and risk-based prioritization.
- Excellent cross-functional communication skills, able to translate technical vulnerability data into business risk for executive audiences.
- Proven ability to build reporting/dashboards (e.g., Linear, Jira, ServiceNow, Tableau, Looker) for real-time program health visibility.
- Experience supporting compliance frameworks such as SOC 2, ISO 27001, PCI-DSS, or FedRAMP.
- Systems Thinking: Ability to understand how vulnerability management decisions impact the entire stack.
- Technical Influence: Ability to drive alignment across engineering and security through expertise and collaboration.
- Autonomy: Comfortable owning a program end-to-end with minimal oversight.
- Bias for Action: Track record of effectively driving vulnerability remediation.
Benefits
- Competitive Salary & Equity
- 401(k) Program with a 4% match (US Only)
- Health, Dental, Vision and Life Insurance
- Short Term and Long Term Disability
- Paid Parental, Medical, Caregiver Leave
- Flexible Time Off (FTO) + Holidays
- Commuter Benefits (In-Office Only)
- Monthly Wellness Stipend
- Autonomous Work Environment
- In Office Set-Up Reimbursement (In-Office Only)
- Quarterly Team Gatherings
- In Office Amenities (In-Office Only)