The Opportunity
As a Security Technical Program Manager, you will be the connective tissue between our Product and Engineering teams, ensuring security isn't just a checkpoint, but a foundational pillar of our cloud and AI ecosystems.
We are looking for a leader who can translate complex threat landscapes into high-impact, actionable roadmaps, balancing rigorous program management with deep technical empathy. You won't just manage tasks; you will architect the execution of our security vision.
Key Responsibilities
Security Architecture & Design: Lead high-stakes Security Design Reviews, embedding Secure-SDLC principles from the first line of code to global deployment.
Vulnerability Governance: Orchestrate the end-to-end threat lifecycle, partnering with SRE, DevOps, and Engineering to turn risk data into rapid, automated remediation.
Compliance & Trust: Champion our commitment to PCI DSS, SOX, and SOC2, while navigating the complexities of global regulations like GDPR and HIPAA.
Strategic Execution: Define the "Security North Star," establishing clear success metrics (KPIs/KRIs) and reporting progress directly to executive leadership.
Velocity & Security: Partner with development teams to integrate best practices that enhance—rather than hinder—development velocity, proving that "secure" and "fast" can coexist.
Program Operations: Transform abstract security ideas into structured project charters with clear roles, timelines, and a definitive "Definition of Done."
What We’re Looking For
Experience: 6+ years in Technical Program Management, specifically focused on Information Security, Application Security, or Cyber Risk.
Compliance Mastery: A proven track record of managing and delivering audits for PCI, SOC2, and SOX.
Technical Depth: You "speak engineer." You have a deep understanding of the OWASP Top 10, Cloud environments (AWS, GCP, or Azure), and modern vulnerability management tools.
Execution Excellence: The ability to orchestrate multiple high-stakes projects simultaneously across different time zones and functions without losing momentum.
Strategic Communication: Exceptional ability to translate complex technical vulnerabilities or compliance hurdles into concise, actionable plans for non-technical stakeholders.
Crisis Leadership: Resilience in high-pressure scenarios, with the judgment to make informed decisions during security incidents or tight launch windows.
Influence: A natural ability to motivate and influence cross-functional teams and seniority levels without direct authority.
Education: Bachelor's or Master's degree in Cybersecurity, Computer Science, or a related technical field.
Desired Certifications & Proficiencies
Security & Compliance: CISSP, CISM, or CCSK.
Audit Focused: CISA (particularly valuable for our SOX and SOC2 requirements).
Program Management: PMP or Agile/Scrum Master certifications.
Tooling: Familiarity with GRC platforms (e.g., Vanta, Drata), vulnerability scanners (e.g., Nessus, Snyk), and CSPM tools.
Valencia, Spain Hybrid Full-time