This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We’re looking for a Security Technical Program Manager (TPM) to lead Webflow’s Security program and drive collaboration across different teams in Webflow and Security. This role blends technical understanding with program leadership — ensuring key projects across information security, across the spectrum of security operations, application security, compliance and specifically vulnerability management.
Job Responsibility:
Coordinate security-wide planning across teams — tracking dependencies, aligning on priorities, and maintaining roadmap visibility
Lead the end-to-end Vulnerability Management lifecycle, from discovery to remediation
Manage stakeholder communication, and cross-functional alignment
Partner with Engineering to ensure vulnerability ownership, ticket quality, and remediation clarity
Experience with AI tooling and workflow automation to better drive efficiency
Maintain and improve Jira workflows for vulnerability and security ticketing
Develop and publish vulnerability metrics and dashboards for visibility and accountability
Identify and resolve process bottlenecks
drive continuous improvement in the vulnerability lifecycle
Collaborate with SMEs in AppSec and SecDevOps to maintain full scanning and tooling coverage (e.g., Socket, container scanning, SCA)
Maintain VM documentation, operating procedures, and readiness for audits (SOC 2, ISO 27001, ISO 42001)
Identify opportunities for automation or reporting enhancements that scale VM effectiveness
Requirements:
3-4 years of program or project management experience in technical domains such as security, infrastructure, or DevOps
Experience coordinating cross-functional delivery between engineering, security, and operations teams
Comfortable working with vulnerability management tools and workflows (e.g., Socket, container scanning, SCA, Jira)
Strong organizational skills
Communicate clearly and with empathy
Understand the importance of balancing speed with security
Have experience improving or building processes that make vulnerability management more scalable and predictable
Take ownership of your work
Thrive in ambiguity
Are curious about how security and engineering systems fit together
Nice to have:
Exposure to security compliance frameworks such as SOC 2, ISO 27001, or similar audit processes
Familiarity with security scanning and reporting tools (Socket, Qualys, or equivalent)
Experience supporting or coordinating incident response or vulnerability triage workflows
Background in SaaS or cloud environments with an understanding of common infrastructure patterns
Experience developing dashboards or metrics for vulnerability tracking and remediation progress
Prior experience in a fast-paced, remote-first organization or working across distributed teams
What we offer:
Ownership in what you help build. Every permanent Webflower receives equity (RSUs) in our growing, privately held company
Health coverage that actually covers you. Comprehensive medical, dental, and vision plans for full-time employees and their dependents, with Webflow covering most premiums
Support for every stage of family life. 12 weeks of paid parental leave for all parents and 6+ weeks of additional paid leave for birthing parents. Plus inclusive care for family planning, menopause, and midlife transitions
Time off that’s actually off. Flexible vacation, paid holidays, and a sabbatical program to help you recharge and come back inspired
Wellness for the whole you. Access to mental health resources, therapy and coaching
Invest in your future. A 401(k) with 100% employer match (up to $6,000/year) in the U.S., and support for retirement savings globally
Monthly stipends that flex with your life. Localized support for work and wellness expenses — from Wi-Fi to workouts
Bonus for building together. All full-time, permanent, non-commission employees are eligible for our annual WIN bonus program