This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We’re hiring a senior Sr Security Program Manager to contribute to and mature an integrated security program that spans Product Security (AppSec / SSDLC), Security Operations (SecOps/IR/cloud security), Technical GRC, and Enterprise Applications and Identity. This is a high-visibility, cross-functional, strategic role. You will own program outcomes, influence product and engineering roadmaps, and be the “translator” between security, risk, leadership, and the business teams who rely on ACV’s marketplace every day. ACV’s scale and data scope (including sensitive vehicle, dealer data, identity, and payment information) mean your work will meaningfully reduce enterprise risk and enable secure growth. You will be a trusted member and critical voice of the security leadership team, reporting directly to the CISO.
Job Responsibility:
Work with stakeholders to create a unified security program roadmap covering Product Security, SecOps, and Enterprise Security
Translate risk appetite into prioritized initiatives, funding opportunities, and measurable outcomes
Define and publish security KPIs/OKRs as dashboards to various internal audiences
Use data to support visibility and continuous improvement
Work with security teammates to collectively drive programs partnering with Product, Engineering, and DevOps to embed AppSec into the SSDLC
Partner with Operational leads to drive maturity through the creation of requirement frameworks including documented procedures, incident response playbooks, and runbooks
Collaborate with Legal, Privacy, and GRC teams to ensure enterprise controls align with SOC 2 and other industry standard framework requirements
Partner directly with the CISO to ensure top initiatives are well-planned, resourced, and delivered
Identify gaps, improve processes, and support the development of scalable frameworks
Drive cybersecurity initiatives from planning through delivery
Help run team meetings, leadership offsites, and special projects that support team health, accountability, and long-term success
Requirements:
8+ years experience building and operating security programs in SaaS / marketplace / fintech / large data platforms
Demonstrable ownership across AppSec, SecOps, and Corporate Security domains
Experience optimizing and helping vulnerability management and incident response programs mature with measurable SLAs (MTTR, remediation windows)
Track record of influencing engineering/product leadership and delivering security as a business enabler (not a blocker)
Strong program management skills: roadmap creation, cross-functional timelines, budget stewardship, vendor selection and contract negotiation
Excellent written + verbal communication
experience preparing executive risk briefings and board-level security summaries
Bachelor’s degree in CS, Engineering, Information Security, or commensurate experience (5+ years) working in a similar role
Nice to have:
Prior experience at marketplaces or in automotive/transportation/finance verticals
Familiarity with data products, vehicle inspection pipelines, or payment flows
Experience with SOC 2 readiness, ISO 27001, PCI scope reduction, or public company compliance programs
Background in privacy program integration, especially where product telemetry/geolocation, vehicle data, and identity data are in scope
What we offer:
Multiple medical plans including a high deductible, low cost health plan
Company-sponsored (paid) Short-Term Disability, Long-Term Disability, and Life Insurance
Comprehensive optional benefits such as Dental, Vision, Supplemental Life/AD&D, Legal/ID Protection, and Accident and Critical Illness Insurance
Generous paid time off options, including uncapped vacation days, the greater of 3 paid sick days or in accordance with the applicable state or local paid sick leave law, 6 paid company holidays, 2 floating holidays, parental leave, bereavement leave, jury duty leave, voting leave, and other forms of paid leave as required by applicable law or regulation
Employee Stock Purchase Program with additional opportunities to earn stock in the Company