Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Chan Zuckerberg Initiative

Senior Technical Program Manager, Product Security

Chan Zuckerberg Initiative

Technical Program Manager optimizing application security for CZI, driving innovations in scientific and educational technologies. Collaborating with engineers to safeguard technological advancements.

Posted 7/21/2026full-timeRedwood City • California • 🇺🇸 United StatesSenior💰 $190,000 - $261,800 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in security tooling, automation, and architecture, with a strong focus on integrating security throughout the software development lifecycle. Proven ability to lead security projects, collaborate with cross-functional teams, and ensure compliance with security standards in complex environments.

Highest-signal resume keywords
Technical Program ManagementSecure SDLC ProcessesDevSecOps PrinciplesSecurity Architecture DesignVulnerability Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security Controls ManagementThreat ModelingStatic Application Security TestingDynamic Application Security TestingSoftware Composition AnalysisSecurity AutomationInfrastructure-as-Code SecurityContainer SecurityMicroservices ArchitectureCloud Platform Security
Soft Skills
CollaborationCommunicationProblem-SolvingLeadership
Tools & Technologies
CI/CD PipelinesDockerKubernetesAWSAzureGCP
Industry Keywords
Zero TrustDefense-in-DepthCompliance RequirementsRegulated Industries

Tech Stack

Tools & technologies
AWSAzureCloudDockerGoogle Cloud PlatformKubernetesMicroservicesSDLC

About the role

Key responsibilities & impact
  • Conceive, design, develop, and improve industry-leading security tooling, automation, architecture, and/or frameworks that enable enterprise teams at scale to deliver applications and services with appropriate security controls to meet evolving requirements for security and privacy.
  • Identify and eliminate classes of security problems by shifting detection and prevention left into the development workflow.
  • Provide just-in-time, actionable, technical security guidance to enterprise application and service teams.
  • Ensure prioritization, resourcing, and timely delivery of work within a changing business environment.
  • Collaborate with cross-functional teams to ensure security work is being prioritized and addressed.
  • Drive end-to-end execution of technical security projects, including requirements gathering, scoping, status updates, and delivery milestones.
  • Establish and report metrics to track compliance, program health, and ongoing risk posture.
  • Coordinate with third-party vendors and auditors to augment internal security capabilities.
  • Serve as a subject matter expert on infrastructure, architecture, and application security, offering guidance to technical and non-technical stakeholders.
  • Support security reviews, threat modeling, and incident response efforts for applications and production infrastructure.

Requirements

What you’ll need
  • 5+ years of technical program management or equivalent experience, with a specific focus on security or application security.
  • Demonstrated proficiency with secure SDLC processes and best practices for integrating security throughout the software development lifecycle.
  • Hands-on experience designing and managing security controls within CI/CD pipelines, using automation frameworks to enable secure code delivery and rapid remediation.
  • Familiarity with threat modeling, static and dynamic application security testing (SAST/DAST), and software composition analysis (SCA) tools.
  • Deep understanding of DevSecOps principles, security automation, and infrastructure-as-code security.
  • Experience driving the adoption of vulnerability management, architectural best practices, and incident response for cloud-native and distributed applications.
  • Knowledge of container security (Docker, Kubernetes), microservices architectures, and cloud platform security (AWS, Azure, GCP).
  • Experience leading end-to-end security architecture design and governance across complex, cloud-native, and hybrid enterprise environments, aligning security capabilities to business and risk objectives.
  • Proven ability to define and maintain reference architectures, security patterns, and control standards spanning network, identity, data protection, and application security domains.
  • Skilled in conducting architecture risk assessments and design reviews, ensuring new and existing solutions meet zero trust, defense-in-depth, and compliance requirements in regulated industries.

Benefits

Comp & perks
  • Provides a generous employer match on employee 401(k) contributions to support planning for the future.
  • Paid time off to volunteer at an organization of your choice.
  • Funding for select family-forming benefits.
  • Relocation support for employees who need assistance moving