FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Vulnerability Management Technical Lead
GustoVulnerability Management Technical Lead securing Gusto’s payroll, benefits, and HR platform for small businesses. Leading vulnerability management, security operations, AI-enabled workflows, and compliance delivery.
Posted 9/2/2026full-timeSan Francisco • California • 🇺🇸 United StatesSenior💰 $168,000 - $189,000 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in vulnerability management and security operations, with a strong focus on strategy development, cross-functional leadership, and regulatory compliance. Proficient in implementing security controls, managing risk, and utilizing AI-driven tools for enhanced security workflows.
Highest-signal resume keywords
Vulnerability ManagementSecurity OperationsCross-Functional LeadershipSIEM IntegrationPM Certification
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Vulnerability ManagementSecurity OperationsDetection EngineeringRemediation SLAsScanning CoverageSecure SDLC PracticesDependency ScanningSecrets ManagementPrivileged Access ManagementRisk Management
Soft Skills
Stakeholder AlignmentCommunicationTrainingVendor ManagementCross-Functional Collaboration
Tools & Technologies
CSPMDSPMSIEM ToolsWizAxoniusPantherOpalAI ClientsMCPsDashboards
Certifications & Qualifications
PMPCAPMScrumProsci
Industry Keywords
Regulated EnvironmentsFintechSOC 1/2ISO 27001Risk Scoring
Tech Stack
Tools & technologiesCloudPMPSDLC
About the role
Key responsibilities & impact- Own the definition and delivery of Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk
- Set the strategy, roadmap, multi-quarter vision, intake, and prioritization for vulnerability management and security operations
- Lead delivery of centralized vulnerability management across code, cloud, data, and edge
- Deliver CSPM/DSPM, container scanning, dependency and secrets detection, and owner-based remediation routing through closure
- Expand high-risk security detection and alerting across systems and vendors
- Implement impersonation and privileged-access logging, SIEM integration, insider-risk telemetry, and agentic-activity logging
- Establish daily security-health and vulnerability-management dashboards and drive monthly reporting
- Build AI-plugin-driven security workflows for automated coverage checks and evidence collection
- Build plans, manage scope and risk, track milestones, and deliver audit and regulatory commitments
- Roll out controls including risk-scored PR review, JIT privileged access, and secrets management
- Support adoption through training, communications, and runbooks
- Align stakeholders through clear updates, manage vendors and partners, monitor workstreams, budgets, tooling spend, and implementation costs
Requirements
What you’ll need- History of taking programs from ambiguous to shipped in regulated environments
- 5 to 8+ years leading cross-functional TPM or delivery work
- Real time spent on security, infrastructure, or platform engineering
- Solid understanding of vulnerability management and security operations, including scanning coverage, remediation SLAs, detection engineering, SIEM/monitoring, identity, and privileged access
- AI plugins drive everyday delivery, with ability to help others work the same way
- Ability to speak the language of security engineering, infrastructure, GRC, and R&D
- Familiarity with vulnerability and asset scanners such as Wiz and Axonius
- Experience with dependency and secret scanning
- Familiarity with SIEM/detection tools such as Panther
- Familiarity with identity/JIT access tools such as Opal
- Hands-on experience using AI clients and plugins (MCPs)
- Working knowledge of SOC 1/2 and ISO 27001 control frameworks
- Secure SDLC practices
- PM certification (PMP, CAPM, Scrum, or Prosci) and experience in high-growth fintech or another regulated, fast-paced industry are nice to have
Benefits
Comp & perks- Competitive base pay
- Health insurance
- 401(k)
- Equity (RSUs)
- Secure, reliable, and consistent internet connection required when working outside a Gusto office
- Reasonable accommodations for qualified individuals with disabilities and disabled veterans