Senior Technical Program Manager, Security
Austin, TX - USA
Job Summary
SailPoint leads in identity security for the cloud enterprise. Built on AI and machine learning our Identity Security Cloud Platform delivers the right level of access to the right identities and resources at the right timematching the scale velocity and evolving needs of todays modern enterprise.
SailPoint is looking for a Technical Program Manager to serve as the operational backbone of a product security program running 12 concurrent initiatives a growing portfolio of BAU security operations and coordination across every engineering organization in the company. You will drive execution across security architecture reviews tooling evaluations vendor procurements pipeline buildout and cross-functional programs spanning Product Engineering DevOps Platform Engineering and the CISO organizationwork that goes well beyond routine status reporting.
The program spans near-term initiatives (production access controls red team vendor engagement SCM migration CI/CD security gates cloud asset tagging MCP gateway API gateway reviews) mid-term initiatives (customer code governance BYOK architecture reference architecture standup non-human identity program) and continuous BAU activities (design reviews security architecture reviews AI security reviews security champions metrics and reporting red team operations). You will own the operational rhythm that keeps all of this moving forward without anything falling through the cracks.
You will join our Engineering Operations teamthe group that keeps SailPoints engineering organization secure compliant and audit-ready as we scale. Engineering Operations sits at the intersection of Engineering Product and Compliance removing friction standardizing process and ensuring the right evidence and controls are in place without slowing teams down.
In this role you will work closely with Engineering Managers security operations platform teams and leaders across Engineering and Cybersecurity. Together we aim for predictable remediation throughput transparent risk visibility and a vulnerability management program that keeps pace with our product and cloud footprint.
- Own end-to-end execution of 12 concurrent product security initiatives across near-term mid-term and continuous horizons keeping each with a current status next milestone owner timeline and documented dependencies.
- Maintain the initiative roadmap as a living document run the weekly tracking cadence flag drifting work and escalate blockers before they become delays.
- Map and actively manage cross-team dependencies across DevOps Platform Engineering FinOps Architecture Product Engineering Directors and the CISO organization.
- Build trusted relationships with engineering leaders whose teams support active initiatives making cross-team coordination frictionless rather than adding process.
- Manage the full vendor and procurement pipeline giving every engagement a clear status next action owner and timeline and eliminating procurement surprises.
- Drive vendor engagements through the front door process coordinating evaluators scoping POCs compiling results and preparing decision packages for leadership.
- Track recurring BAU work design and architecture reviews AI security reviews red team operations security champions and metrics against capacity so the Director can see where the team has room for additional work.
- Produce executive-ready status updates quarterly program reviews and decision packages that leadership uses to evaluate program health and make investment decisions.
- Steer the program with data such as aging throughput and SLA adherence sizing risk in concrete terms for both technical and executive audiences.
- Build and maintain program tracking in Jira and Confluence establish a consistent intake process for new initiatives and apply AI-assisted workflows with sound judgment about when automation helps and when human oversight is required.
By 30 days Discovery & Assessment:
- Complete a thorough review of the initiative roadmap (12 initiatives across near-term and mid-term horizons) the BAU tracker (10 recurring activities with quarterly load allocations) and the quarter map that sequences all work. Understand the dependencies between initiatives the staffing model and where capacity is tight.
- Map every cross-team dependency. This program touches DevOps Platform Engineering FinOps Architecture Product Engineering Directors the CISO organization and multiple vendor relationships. Build the dependency map and identify which dependencies are on track at risk or blocked.
- Review every active procurement and POC. Understand where each vendor engagement sits in the front door process what the evaluation timeline looks like who the decision makers are and what approvals are still outstanding.
- Establish the communication rhythm. Learn how the Director communicates with leadership and calibrate your reporting to support that cadence.
By 60 days Own the Rhythm:
- Take full ownership of the weekly initiative tracking cadence. Run the weekly sync maintain the roadmap tracker flag initiatives that are drifting and escalate blockers before they become delays.
- Drive at least one active procurement to completion or to the next milestone (vendor contract executed POC scoped or evaluation results compiled). Demonstrate that you can navigate the procurement process coordinate evaluators and deliver a decision package.
- Build working relationships with every engineering director whose team is a dependency for an active initiative. They should know your name understand your role and see you as the person who makes cross-team coordination frictionless rather than adding process.
By 90 days Program Structure & Execution:
- Full operational ownership of all 12 initiatives. Every initiative has a current status a next milestone an owner a timeline and a documented set of dependencies and blockers. Nothing is stale. Nothing is untracked.
- BAU load tracking operational. The teams recurring work (design reviews architecture reviews AI security reviews red team operations security champions metrics) is tracked against capacity so the Director can see where the team is at capacity and where there is room for additional initiative work.
- Vendor and procurement pipeline fully managed. Every active vendor engagement has a clear status next action owner and timeline. Procurement surprises are eliminated.
- First quarterly program review prepared and delivered. Compile the quarters progress into a single executive-ready document: initiatives completed initiatives in flight metrics movement staffing utilization and the plan for the next quarter.
By 6 months Program Operating System:
- The initiative roadmap is a living document that the entire team and stakeholders reference. Initiatives move between phases on a predictable cadence. New initiatives are scoped staffed and sequenced using a consistent intake process rather than ad hoc prioritization.
- Cross-team dependencies are managed proactively. Engineering directors DevOps Platform Engineering and the CISO organization experience the security program as organized and predictable rather than reactive. Commitments are tracked and met.
- Metrics and reporting are automated or semi-automated. The Directors executive updates the teams KPI dashboard and the initiative health tracker are maintained continuously not assembled in a rush before each reporting cycle.
- At least two initiatives have been driven to completion under your program management with documented outcomes lessons learned and the transition to BAU or closure clearly executed.
By 1 year Strategic Program Partner:
- The product security program operates with the organizational discipline of a program three times its size. Initiatives are planned quarterly tracked weekly and reported on a cadence that leadership trusts. The Director spends time on strategy and stakeholder relationships not on initiative tracking and cross-team coordination because you own that entirely.
- You are recognized by engineering leadership as the person who makes the security program operationally credible. When someone asks where does the security program stand on X they come to you and you have the answer.
- Program planning for the next fiscal year is driven by you. You compile the initiative proposals the staffing model the capacity analysis and the quarter map for the Directors review and approval. The Director defines strategy; you translate strategy into an executable plan.
- Backlog and emerging items are actively managed. The pipeline of future work is scoped sized and sequenced so that when an emerging item becomes urgent the intake process is ready.
- Stay highly organizedyou will coordinate work across multiple Engineering and Security teams at the same time.
- Bring deep program management experience in a fast-moving technology organization with credibility in security or infrastructure contexts.
- Apply strong technical judgment on vulnerability severity remediation trade-offs and cloud-native security risk.
- Build trusted relationships across Engineering and Security; this is a people-facing role that drives outcomes through influence.
- Communicate clearly to both technical and executive audiences including sizing risk in concrete terms.
- Stay data-drivenuse metrics such as aging throughput and service-level agreement (SLA) adherence to steer the program not anecdotes.
- Have deep experience with Jira and Confluence as the backbone of program planning and reporting.
- 7 years of technical program management experience with at least 3 years managing security infrastructure or platform engineering programs.
- Demonstrated experience managing 10 concurrent initiatives with cross-functional dependencies across engineering organizations.
- Experience managing vendor procurement processes for security or engineering tooling including evaluations POCs and contract execution.
- Familiarity with security program domains: application security cloud security DevSecOps vulnerability management and identity/access management. You do not need to be a practitioner but you need to understand the landscape.
- Proficiency with program management tooling (Jira Confluence spreadsheet-based trackers) and the ability to build and maintain program tracking without dedicated PMO infrastructure.
- Strong written communication. You will produce the executive status updates quarterly reviews and decision packages that leadership uses to evaluate program health and make investment decisions.
- Bachelors degree in a relevant field or equivalent experience.
- Experience building or maturing a security infrastructure or platform program operating model intake quarterly planning weekly execution rhythm BAU transition and portfolio capacity planning across concurrent initiatives.
- Prior ownership of DevSecOps CI/CD security or SCM/toolchain programs (e.g. pipeline security gates developer tooling migration cloud asset governance).
- Identity and access security program coordination including production access controls non-human identity or similar IAM-adjacent initiatives.
- Experience coordinating security review and operations programs design/architecture reviews AI security reviews red team vendor engagement and security champions.
- Track record delivering executive quarterly program reviews procurement decision packages and semi-automated metrics reporting (aging throughput SLA adherence) for security or engineering programs.
- SaaS or enterprise product security experience in audit- or compliance-sensitive environments with demonstrated ability to influence engineering leadership and resolve cross-org dependencies without direct authority.
- Hands-on experience using AI-assisted and agent-orchestrated workflows to accelerate planning tracking and communication across complex multi-team programs with sound judgment about when automation helps and when human oversight is required.
- Proven ability to design and maintain program tracking in Jira and Confluence that drives accountability and executive-ready visibility.
- Build the operating system for an industry-leading security program. This is a greenfield security program with executive sponsorship a funded roadmap and a Director who needs a program partner not a project coordinator. You will build the operational muscle of the program not inherit someone elses process.
- Real program complexity not project management dressed up. The roadmap spans 12 initiatives 10 BAU activities and 5 vendor engagements across a two-year horizon. You will run a portfolionot manage one project at a time.
- Identity is the attack surface that matters most. SailPoints platform governs access for thousands of enterprises and millions of identities. The program you manage protects the trust those customers place in the platform.
- A team that takes security seriously. You will work alongside security architects a red team security engineers and a security champions program. The team is technically deep and operationally committedand needs someone who can match their intensity on the program side.
- Work with a leader who gets it. Youll partner with a Director who has built security programs at scale and understands that program management is a force multiplier not overhead. Your role will be valued resourced and defended.
Benefits and Compensation listed vary based on the location of your employment and the nature of your employment with SailPoint.
As a part of the total compensation package this role may be eligible for the SailPoint Corporate Bonus Plan or a role-specific commission along with potential eligibility for equity participation. SailPoint maintains broad salary ranges for its roles to account for variations in knowledge skills experience market conditions and locations as well as reflect SailPoints differing products industries and lines of business. Candidates are typically placed into the range based on the preceding factors as well as internal peer equity. We estimate the base salary for US-based employees will be in this range from (min-max USD):
$97900 - $165082.00Base salaries for employees based in other locations are competitive for the employees home location.
Benefits Overview
1. Health and wellness coverage: Medical dental and vision insurance
2. Disability coverage: Short-term and long-term disability
3. Life protection: Life insurance and Accidental Death & Dismemberment (AD&D)
4. Additional life coverage options: Supplemental life insurance for employees spouses and children
5. Flexible spending accounts for health care and dependent care; limited purpose flexible spending account
6. Financial security: 401(k) Savings and Investment Plan with company matching
7. Time off benefits: Flexible vacation policy
8. Holidays: 8 paid holidays annually
9. Sick leave
10. Parental support: Paid parental leave
11. Employee Assistance Program (EAP) and Care Counselors
12. Voluntary benefits: Legal Assistance Critical Illness Accident Hospital Indemnity and Pet Insurance options
13. Health Savings Account (HSA) with employer contribution
SailPoint is an equal opportunity employer and we welcome all qualified candidates to apply to join our team. All qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity national origin disability protected veteran status or any other category protected by applicable law.
Alternative methods of applying for employment are available to individuals unable to submit an application through this site because of a disability. Contact or mail to 11120 Four Points Dr Suite 100 Austin TX 78726 to discuss reasonable accommodations. NOTE: Any unsolicited resumes sent by candidates or agencies to this email will not be considered for current openings at SailPoint.
Required Experience:
Senior IC
About Company
The core of enterprise security is identity. Take a tour to see how our identity security platform delivers a foundation that securely fuels your business.