This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Senior Technical Program Manager, Security & GRC will work directly with our Infosec and Risk (GRC) teams to ensure that our improvements in security don’t slow us down in our mission to solve America’s retirement savings crisis. This role sits at the intersection of software engineering, corporate risk, and business operations. This TPM role will ensure that our security and risk teams are organized, coordinated and have well planned backlogs, but it is not managing a checklist. This role will help build and enable a technical ecosystem where security and compliance are automated, invisible, and inseparable from the software development lifecycle.
Job Responsibility:
Technical security orchestration: Partner with Security Engineering, Risk, Product, and Infrastructure teams to bake security and compliance 'into the kiln'
Help design risk solutions: Dive deep into the security stack to not only identify execution blockers but actively architect the technical solutions to implement them
Help architect our security mission: Define the technical milestones for high-stakes initiatives like Zero Trust and IAM overhauls, translating a broad vision into a precise execution roadmap
Drive high-velocity operations: Lead agile security sprints that harmonize vulnerability remediation and threat detection with feature development
Optimize the 'rhythm of the business' by automating manual GRC workflows, eliminating manual friction and moving us toward Compliance as Code
Translate telemetry into narrative: Distill complex security data and telemetry into compelling risk narratives for leadership while maintaining high-fidelity technical depth for engineers
Optimize the defensive roadmap: Command long-term strategic planning by aligning cloud infrastructure costs and security tooling with the company’s overarching defensive goals
Cultivate organizational excellence: Uphold a relentless culture of focus and accountability, identifying systemic inefficiencies and driving impact through superior tooling and process engineering
Requirements:
Bachelor's degree in CS, Engineering, or a related field
Started career as a Security Engineer, Systems Administrator, or Analyst
TPM professional for 5+ years, specifically managing high-stakes security, privacy, or infrastructure initiatives
Deep understanding of the Security SDLC and experience navigating cloud-native service architectures (AWS/GCP) with a focus on security guardrails
Experience translating regulatory frameworks (e.g., SOC2, ISO 27001, FedRAMP, or GDPR) into concrete technical requirements
Proven ability to 'go deep' and comfortable looking at architectural diagrams, API docs, or cloud configurations to find root causes
Exceptional communication skills with a knack for explaining the 'why' behind a security control to a developer and the 'how' of a technical fix to an auditor
Strong ability to leverage data—from vulnerability scanners to Jira velocity—to tell a story and drive cross-functional decision-making
What we offer:
A great 401(k) plan: Our own! Our 401(k) includes a dollar-for-dollar employer match up to 4% of compensation (immediately vested) and $0 plan fees
Top-of-the-line health plans, as well as dental and vision insurance
Competitive time off and parental leave
Addition Wealth: Unlimited access to digital tools, financial professionals, and a knowledge center to help you understand your equity and support your financial wellness
Lyra: Enhanced Mental Health Support for Employees and dependents
Carrot: Fertility healthcare and family forming benefits
Candidly: Student loan resource to help you and your family plan, borrow, and repay student debt
Monthly work-from-home stipend
quarterly lifestyle stipend
Engaging team-building experiences, ranging from virtual social events to team offsites, promoting collaboration and camaraderie