Technical Program Manager, Security

Oakland, California, United States, AMER·Posted yesterday
pythonkubernetesdockerawsgcpterraform
<div class="content-intro"><p>From Fivetran’s founding until now, our mission has remained the same: to make access to data as simple and reliable as electricity. With Fivetran, customer data arrives in their warehouses, canonical and ready to query, with no engineering or maintenance required. We’re proud that more organizations continue to leverage our technology every day to become truly data-driven.</p></div><p><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><strong>About Us</strong></span></p> <p><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Fivetran and dbt Labs are bringing together two industry-leading companies with a shared mission: helping organizations unlock the full value of their data.</span><br><br><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Together, we’re delivering the data infrastructure layer that helps organizations move, transform, and trust their data — from the moment data moves, through every transformation, to the context teams and AI systems rely on.</span><br><br><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Fivetran helps organizations automate data movement across the systems, clouds, engines, and tools they rely on. dbt Labs pioneered analytics engineering, helping teams transform data into reliable, governed insights. Together, we support thousands of organizations as they build a trusted foundation for analytics, AI, and better business decisions.</span><br><br><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">As we bring our teams and technology together, we’re building on the strengths of both companies while continuing to deliver the products and experiences our customers know and trust. It’s an exciting time to join us: we’re creating a company with the scale, talent, and technology to help more organizations put their data to work with greater speed, confidence, and impact.</span><br><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">​</span><br><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">During this transition period, you may see references to both Fivetran and dbt Labs throughout our recruiting process as we integrate our teams, systems, and career sites.</span></p> <p><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><strong>About the Role</strong></span></p> <p><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Fivetran is building data pipelines to power the modern data stack for thousands of companies.</span></p> <p><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">We’re looking for a high-performance, experienced hands-on technical program manager(TPM) in the security domain to be part of an Engineering team. In this role, you will be responsible for leading and managing security-related initiatives across the organization. It involves collaborating with cross-functional teams to ensure the successful planning, execution, and delivery of security programs. The TPM will act as a bridge between technical teams and business stakeholders, ensuring alignment with organizational goals while mitigating security risks.</span></p> <p><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">The work is very diverse. Fivetran is a multi-cloud environment operating on AWS, GCP, and Azure. You will help select security tools, implement improvements within our environments, and assist in developing new processes to increase our security posture.</span></p> <p><br><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">This is a full-time position based out of our Oakland, CA office. Our hybrid work model offers a blend of remote flexibility and in-person collaboration, including two days in the office each week to connect and build as a team.</span></p> <p><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><strong>Technologies You’ll Use</strong></span></p> <p><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Bash, Python, JS, BigQuery, Looker, Sigma, Azure, AWS, GCP, Terraform, Docker, Kubernetes, Github, Buildkite, SonarQube, Grafana, Prisma, Synk, Signal Sciences, AI Tools</span></p> <p><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><strong>What You’ll Do</strong></span></p> <ul> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">This is the primary person in engineering responsible for executing the security vulnerability management program for engineering, including infrastructure, code, and dependency vulnerabilities.</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Collaborate with Security and Engineering teams to ensure vulnerabilities are identified, prioritized, and patched. Provide technical oversight and accountability to ensure the effective delivery of security fixes.</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Enhance processes by evaluating tools, recommending improvements, and driving automation for faster resolution.</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Usage of AI in defining the roadmap for a proactive security approach based on risk assessment/rating</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Running the Dependency management and image hardening programs</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Using AI to contribute to the remediation of code and infrastructure vulnerabilities</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Establish and lead a code scanning program in collaboration with infrastructure, engineering, and security teams to ensure seamless integration and sustainable security practices.</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Dedicate up to 20% of the time to assessing business systems to identify vulnerabilities and compliance gaps proactively. Develop a scanning and detection plan and establish policies and standards for internal data access tools to improve overall system security.</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Advocate for tools and solutions that support shift-left strategies, driving early integration of security and testing in the development lifecycle.</span></li> </ul> <p><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><strong>Skills We’re Looking For</strong></span></p> <ul> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Over 5 years of experience in technical program management with a strong focus on security engineering, vulnerability management, cloud security, and application security.</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Proficient in applying program management methodologies, tools, and best practices to deliver complex security initiatives.</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Exceptional skills in prioritization, organization, and multitasking to manage multiple programs effectively.</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Proven ability to work collaboratively with cross-functional teams, including product teams, SRE/QE engineers, and developers, to embed a security-first mindset into workflows and practices.</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Deep understanding of key security domains, including application/infrastructure security, data privacy, threat modeling, vulnerability management, and secure software development lifecycle (SDLC).</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Strong grasp of security concepts and principles, including network security, encryption, authentication, and authorization.</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Hands-on experience with SAST/DAST tools, agent-based firewalls, IDS/IPS technologies, and automation tools for security orchestration. Experience with scripting languages for automating security processes.</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Proficient in researching and validating vulnerabilities while proposing effective remediation or mitigation strategies.</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Strong familiarity with OWASP principles and best practices for securing web applications, including the OWASP Top 10 vulnerabilities and Application Security Verification Standard (ASVS)</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Up-to-date knowledge of market trends, emerging technologies, and best practices in cloud security</span></li> <li style="font-family: helvetica, arial, sans-serif; font-size: 10pt;"><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">Strong analytical, problem-solving, and communication skills to address security challenges, coupled with the ability to influence and collaborate effectively with engineering teams in enhancing security measures and mitigating vulnerabilities in a dynamic, fast-paced environment.</span></li> </ul> <p>&nbsp;</p> <p><span style="font-family: helvetica, arial, sans-serif; font-size: 10pt;">#LI-HYBRID #LI-EM1</span></p><div class="content-pay-transparency"><div class="pay-input"><div class="description"><p>The compensation range displayed on this job posting reflects the minimum and maximum target for new hire compensation for the target position and level, and may include sales incentives or target bonuses depending on the role. &nbsp;Our compensation ranges are determined by role, level, and location. Our job titles may span more than one career level. Within the range, individual compensation is determined by additional factors, including job-related skills, experience, relevant education or training, business need, market demands. The compensation range is subject to change and may be modified in the future. Your recruiter can share more about the specific compensation range for your location during the hiring process.</p></div><div class="title">Oakland Pay Range</div><div class="pay-range"><span>$158,284</span><span class="divider">&mdash;</span><span>$197,855 USD</span></div></div></div><div class="content-conclusion"><p>&nbsp;</p> <p class="p-rich_text_section" style="line-height: 1.3;"><strong data-stringify-type="bold">Perks and Benefits</strong></p> <ul> <li>100% employer-paid medical insurance<strong>*</strong></li> <li>Generous paid time-off policy (PTO), plus paid sick time, inclusive parental leave policy, holidays (including a year end Global Week of Rest), and volunteer days off</li> <li>RSU stock grants*</li> <li>Professional development and training opportunities</li> <li>Company virtual happy hours, free food, and fun team-building activities</li> <li>Monthly cell phone stipend</li> <li>Access to an innovative mental health support platform that offers personalized care and resources in areas such as: therapy, coaching, and self-guided mindfulness exercises for all covered employees and their covered dependents.</li> </ul> <p style="line-height: 1.3;"><em><strong>*</strong>May vary by country and worker type - please reach out to your recruiter for more information</em></p> <p style="line-height: 1.3;"><em>Click <a href="https://drive.google.com/drive/folders/1CdawUwjo1Q1B7ghZJ_owdmmHB8VtqhBu?usp=sharing" target="_blank">here</a> to learn more about Fivetran's Benefits by Region.</em></p> <hr> <p style="line-height: 1.3;">We’re honored to be <a class="c-link" href="https://fivetran.com/blog/hvr-acquisition-series-d" target="_blank" data-stringify-link="https://fivetran.com/blog/hvr-acquisition-series-d" data-sk="tooltip_parent">valued at over $5.6 billion</a>, but more importantly, we’re proud of our&nbsp;<a class="c-link" href="https://fivetran.com/culture" target="_blank" data-stringify-link="https://fivetran.com/culture" data-sk="tooltip_parent">core values of Get Stuck In, Do the Right Thing, and One Team, One Dream</a>. Read about us in&nbsp;<a class="c-link" href="https://fivetran-com.s3.amazonaws.com/news/forbes-aug-sept-2022-digital-reprint-10-21-22.pdf" target="_blank" data-stringify-link="https://fivetran-com.s3.amazonaws.com/news/forbes-aug-sept-2022-digital-reprint-10-21-22.pdf" data-sk="tooltip_parent">Forbes</a>.&nbsp; &nbsp; &nbsp;</p> <p style="line-height: 1.3;">Fivetran brings together high-quality talent across the globe to make data access as easy and reliable as electricity for our customers. We value and recognize that our customers benefit from having innovative teams made of people from many backgrounds, experiences, and identities. Fivetran promotes diversity, equity, inclusion &amp; belonging through attracting, recruiting, developing, and retaining a diverse workforce, not only because it is the right thing to do, but because it helps us build a world-class company to better serve our customers, our people and our communities.</p> <p style="line-height: 1.3;">To learn more about Fivetran’s culture and what it’s like to be part of the team, <a href="https://www.youtube.com/watch?v=xlhtp4dGh8o" target="_blank">click here</a> and enjoy our video.</p> <p style="line-height: 1.3;">To learn more about our candidate privacy policy, you can <a href="https://fivetran.com/candidate-privacy" target="_blank">read our statement here</a>.</p> <hr> <p style="line-height: 1.3;"><em>We are committed to ensuring that all candidates have an equal opportunity to participate in our interview process. If you require accommodations at any stage of the process due to a disability, medical condition, or any other circumstance, please don't hesitate to submit your request by filling out this <a href="https://forms.gle/V7k3t4u9j523XkEt6">form</a>. We will work with you to provide reasonable accommodations to facilitate your participation and ensure a fair and accessible interview experience. Your request and any information provided will be kept confidential and will not impact your candidacy. We look forward to hearing from you and accommodating your needs to the best of our ability.</em></p></div>