Technical Program Manager, Security
Fullscript
What you'll do
- Own the security program portfolio
- Own the end-to-end security program roadmap, balancing short-term risk reduction with long-term security maturity.
- Translate security strategy, risk posture, and compliance requirements into clear, prioritized, and executable programs.
- Establish durable planning rhythms, milestones, and success metrics for security initiatives.
- Lead Security Engineering Programs
- Own the Vulnerability Management program, including prioritization frameworks, remediation tracking, and executive-level reporting.
- Coordinate internal and external Penetration Tests, from scoping and scheduling through remediation and closure.
- Partner with engineering and infrastructure teams to ensure security findings are addressed efficiently and sustainably.
- Drive Compliance & Audit Readiness
- Serve as the primary program-level owner for SOC 2 execution and readiness, coordinating timelines, evidence collection, and cross-team accountability.
- Partner with Compliance and Security to reduce audit friction through better processes, documentation, and tooling.
- Identify systemic audit gaps and lead programs to close them long-term, not just for the next audit cycle.
- Establish Scalable Operating Models
- Design and evolve the operating model for security programs, ensuring work scales as Fullscript grows.
- Identify recurring pain points and implement structural improvements to reduce manual coordination and rework.
- Ensure security programs are predictable, measurable, and transparent.
- Communicate with Clarity and Trust
- Communicate program status, risks, and tradeoffs clearly to senior leaders and stakeholders.
- Create and maintain high-quality program documentation, including plans, timelines, and decision records.
- Build trust through proactive communication, follow-through, and shared accountability.
What you bring to the table
- Deep experience leading complex, cross-functional technical programs in security, infrastructure, or highly regulated domains.
- Proven ability to operate at both strategic and execution levels, without losing sight of delivery.
- Strong technical fluency that enables effective partnership with security and engineering teams.
- Comfort navigating ambiguity and making sound judgment calls in risk-based environments.
- Exceptional communication skills and the ability to influence without direct authority.
- A mindset rooted in ownership, transparency, and continuous improvement.
Bonus points if you have
- Direct experience supporting SOC 2, or similar security compliance frameworks.
- Familiarity with vulnerability management tools, penetration testing workflows, or security incident processes.
- Experience working in cloud-based environments and modern CI/CD pipelines.
- Background in health-tech, fintech, or other highly regulated industries.
- Experience scaling security programs in a growing organization.
