SailPoint logo
SailPoint

At SailPoint, we believe enterprise security must start with identity at the foundation. Today’s enterprise runs on a diverse workforce of not just human but also digital identities—and securing them all is critical. Through the lens of identity, SailPoint empowers organizations to seamlessly manage and secure access to applications and data at speed and scale. Our unified, intelligent, and extensible platform delivers identity-first security, helping enterprises defend against dynamic threats while driving productivity and transformation. Trusted by many of the world’s most complex organizations, SailPoint secures the modern enterprise.

Senior Technical Program Manager, Security

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 1,001-5,000Since 2005H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

3 days ago

Salary

$97.9K - $165.1K / year

Seniority

Senior

English

Job Description

Senior Technical Program Manager, Security

SailPoint

This is a remote role within the United States. Due to FedRAMP requirements, this role requires US citizenship. About SailPointSailPoint leads in identity security for the cloud enterprise. Built on AI and machine learning, our Identity Security Cloud Platform delivers the right level of access to the right identities and resources at the right time—matching the scale, velocity, and evolving needs of today's modern enterprise. About the RoleSailPoint is looking for a Technical Program Manager to serve as the operational backbone of a product security program running 12+ concurrent initiatives, a growing portfolio of BAU security operations, and coordination across every engineering organization in the company. You will drive execution across security architecture reviews, tooling evaluations, vendor procurements, pipeline buildout, and cross-functional programs spanning Product, Engineering, DevOps, Platform Engineering, and the CISO organization—work that goes well beyond routine status reporting. The program spans near-term initiatives (production access controls, red team vendor engagement, SCM migration, CI/CD security gates, cloud asset tagging, MCP gateway, API gateway reviews), mid-term initiatives (customer code governance, BYOK architecture, reference architecture standup, non-human identity program), and continuous BAU activities (design reviews, security architecture reviews, AI security reviews, security champions, metrics and reporting, red team operations). You will own the operational rhythm that keeps all of this moving forward without anything falling through the cracks. About the TeamYou will join our Engineering Operations team—the group that keeps SailPoint's engineering organization secure, compliant, and audit-ready as we scale. Engineering Operations sits at the intersection of Engineering, Product, and Compliance, removing friction, standardizing process, and ensuring the right evidence and controls are in place without slowing teams down. In this role, you will work closely with Engineering Managers, security operations, platform teams, and leaders across Engineering and Cybersecurity. Together, we aim for predictable remediation throughput, transparent risk visibility, and a vulnerability management program that keeps pace with our product and cloud footprint. Responsibilities - Own end-to-end execution of 12+ concurrent product security initiatives across near-term, mid-term, and continuous horizons, keeping each with a current status, next milestone, owner, timeline, and documented dependencies. - Maintain the initiative roadmap as a living document, run the weekly tracking cadence, flag drifting work, and escalate blockers before they become delays. - Map and actively manage cross-team dependencies across DevOps, Platform Engineering, FinOps, Architecture, Product, Engineering Directors, and the CISO organization. - Build trusted relationships with engineering leaders whose teams support active initiatives, making cross-team coordination frictionless rather than adding process. - Manage the full vendor and procurement pipeline, giving every engagement a clear status, next action, owner, and timeline, and eliminating procurement surprises. - Drive vendor engagements through the front door process, coordinating evaluators, scoping POCs, compiling results, and preparing decision packages for leadership. - Track recurring BAU work — design and architecture reviews, AI security reviews, red team operations, security champions, and metrics — against capacity so the Director can see where the team has room for additional work. - Produce executive-ready status updates, quarterly program reviews, and decision packages that leadership uses to evaluate program health and make investment decisions. - Steer the program with data such as aging, throughput, and SLA adherence, sizing risk in concrete terms for both technical and executive audiences. - Build and maintain program tracking in Jira and Confluence, establish a consistent intake process for new initiatives, and apply AI-assisted workflows with sound judgment about when automation helps and when human oversight is required. Roadmap for SuccessBy 30 days — Discovery & Assessment: - Complete a thorough review of the initiative roadmap (12 initiatives across near-term and mid-term horizons), the BAU tracker (10 recurring activities with quarterly load allocations), and the quarter map that sequences all work. Understand the dependencies between initiatives, the staffing model, and where capacity is tight. - Map every cross-team dependency. This program touches DevOps, Platform Engineering, FinOps, Architecture, Product, Engineering Directors, the CISO organization, and multiple vendor relationships. Build the dependency map and identify which dependencies are on track, at risk, or blocked. - Review every active procurement and POC. Understand where each vendor engagement sits in the front door process, what the evaluation timeline looks like, who the decision makers are, and what approvals are still outstanding. - Establish the communication rhythm. Learn how the Director communicates with leadership and calibrate your reporting to support that cadence. By 60 days — Own the Rhythm: - Take full ownership of the weekly initiative tracking cadence. Run the weekly sync, maintain the roadmap tracker, flag initiatives that are drifting, and escalate blockers before they become delays. - Drive at least one active procurement to completion or to the next milestone (vendor contract executed, POC scoped, or evaluation results compiled). Demonstrate that you can navigate the procurement process, coordinate evaluators, and deliver a decision package. - Build working relationships with every engineering director whose team is a dependency for an active initiative. They should know your name, understand your role, and see you as the person who makes cross-team coordination frictionless rather than adding process. By 90 days — Program Structure & Execution: - Full operational ownership of all 12 initiatives. Every initiative has a current status, a next milestone, an owner, a timeline, and a documented set of dependencies and blockers. Nothing is stale. Nothing is untracked. - BAU load tracking operational. The team's recurring work (design reviews, architecture reviews, AI security reviews, red team operations, security champions, metrics) is tracked against capacity so the Director can see where the team is at capacity and where there is room for additional initiative work. - Vendor and procurement pipeline fully managed. Every active vendor engagement has a clear status, next action, owner, and timeline. Procurement surprises are eliminated. - First quarterly program review prepared and delivered. Compile the quarter's progress into a single executive-ready document: initiatives completed, initiatives in flight, metrics movement, staffing utilization, and the plan for the next quarter. By 6 months — Program Operating System: - The initiative roadmap is a living document that the entire team and stakeholders reference. Initiatives move between phases on a predictable cadence. New initiatives are scoped, staffed, and sequenced using a consistent intake process rather than ad hoc prioritization. - Cross-team dependencies are managed proactively. Engineering directors, DevOps, Platform Engineering, and the CISO organization experience the security program as organized and predictable rather than reactive. Commitments are tracked and met. - Metrics and reporting are automated or semi-automated. The Director's executive updates, the team's KPI dashboard, and the initiative health tracker are maintained continuously, not assembled in a rush before each reporting cycle. - At least two initiatives have been driven to completion under your program management, with documented outcomes, lessons learned, and the transition to BAU or closure clearly executed. By 1 year — Strategic Program Partner: - The product security program operates with the organizational discipline of a program three times its size. Initiatives are planned quarterly, tracked weekly, and reported on a cadence that leadership trusts. The Director spends time on strategy and stakeholder relationships, not on initiative tracking and cross-team coordination, because you own that entirely. - You are recognized by engineering leadership as the person who makes the security program operationally credible. When someone asks 'where does the security program stand on X,' they come to you, and you have the answer. - Program planning for the next fiscal year is driven by you. You compile the initiative proposals, the staffing model, the capacity analysis, and the quarter map for the Director's review and approval. The Director defines strategy; you translate strategy into an executable plan. - Backlog and emerging items are actively managed. The pipeline of future work is scoped, sized, and sequenced so that when an emerging item becomes urgent, the intake process is ready. To Be Successful in This Role You Must: - Stay highly organized—you will coordinate work across multiple Engineering and Security teams at the same time. - Bring deep program management experience in a fast-moving technology organization, with credibility in security or infrastructure contexts. - Apply strong technical judgment on vulnerability severity, remediation trade-offs, and cloud-native security risk. - Build trusted relationships across Engineering and Security; this is a people-facing role that drives outcomes through influence. - Communicate clearly to both technical and executive audiences, including sizing risk in concrete terms. - Stay data-driven—use metrics such as aging, throughput, and service-level agreement (SLA) adherence to steer the program, not anecdotes. - Have deep experience with Jira and Confluence as the backbone of program planning and reporting. Requirements - 7+ years of technical program management experience, with at least 3 years managing security, infrastructure, or platform engineering programs. - Demonstrated experience managing 10+ concurrent initiatives with cross-functional dependencies across engineering organizations. - Experience managing vendor procurement processes for security or engineering tooling, including evaluations, POCs, and contract execution. - Familiarity with security program domains: application security, cloud security, DevSecOps, vulnerability management, and identity/access management. You do not need to be a practitioner, but you need to understand the landscape. - Proficiency with program management tooling (Jira, Confluence, spreadsheet-based trackers) and the ability to build and maintain program tracking without dedicated PMO infrastructure. - Strong written communication. You will produce the executive status updates, quarterly reviews, and decision packages that leadership uses to evaluate program health and make investment decisions. - Bachelor's degree in a relevant field or equivalent experience. Desired Qualifications - Experience building or maturing a security, infrastructure, or platform program operating model — intake, quarterly planning, weekly execution rhythm, BAU transition, and portfolio capacity planning across concurrent initiatives. - Prior ownership of DevSecOps, CI/CD security, or SCM/toolchain programs (e.g., pipeline security gates, developer tooling migration, cloud asset governance). - Identity and access security program coordination, including production access controls, non-human identity, or similar IAM-adjacent initiatives. - Experience coordinating security review and operations programs — design/architecture reviews, AI security reviews, red team vendor engagement, and security champions. - Track record delivering executive quarterly program reviews, procurement decision packages, and semi-automated metrics reporting (aging, throughput, SLA adherence) for security or engineering programs. - SaaS or enterprise product security experience in audit- or compliance-sensitive environments, with demonstrated ability to influence engineering leadership and resolve cross-org dependencies without direct authority. - Hands-on experience using AI-assisted and agent-orchestrated workflows to accelerate planning, tracking, and communication across complex, multi-team programs, with sound judgment about when automation helps and when human oversight is required. - Proven ability to design and maintain program tracking in Jira and Confluence that drives accountability and executive-ready visibility. Why Join Us - Build the operating system for an industry-leading security program. This is a greenfield security program with executive sponsorship, a funded roadmap, and a Director who needs a program partner, not a project coordinator. You will build the operational muscle of the program, not inherit someone else's process. - Real program complexity, not project management dressed up. The roadmap spans 12 initiatives, 10 BAU activities, and 5+ vendor engagements across a two-year horizon. You will run a portfolio—not manage one project at a time. - Identity is the attack surface that matters most. SailPoint's platform governs access for thousands of enterprises and millions of identities. The program you manage protects the trust those customers place in the platform. - A team that takes security seriously. You will work alongside security architects, a red team, security engineers, and a security champions program. The team is technically deep and operationally committed—and needs someone who can match their intensity on the program side. - Work with a leader who gets it. You'll partner with a Director who has built security programs at scale and understands that program management is a force multiplier, not overhead. Your role will be valued, resourced, and defended. Benefits and Compensation listed vary based on the location of your employment and the nature of your employment with SailPoint. As a part of the total compensation package, this role may be eligible for the SailPoint Corporate Bonus Plan or a role-specific commission, along with potential eligibility for equity participation. SailPoint maintains broad salary ranges for its roles to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect SailPoint’s differing products, industries, and lines of business. Candidates are typically placed into the range based on the preceding factors as well as internal peer equity. We estimate the base salary, for US-based employees, will be in this range from (min-max, USD): $97,900 - $165,082.00Base salaries for employees based in other locations are competitive for the employee’s home location. Benefits Overview 1. Health and wellness coverage: Medical, dental, and vision insurance 2. Disability coverage: Short-term and long-term disability 3. Life protection: Life insurance and Accidental Death & Dismemberment (AD&D) 4. Additional life coverage options: Supplemental life insurance for employees, spouses, and children 5. Flexible spending accounts for health care, and dependent care; limited purpose flexible spending account 6. Financial security: 401(k) Savings and Investment Plan with company matching 7. Time off benefits: Flexible vacation policy 8. Holidays: 8 paid holidays annually 9. Sick leave 10. Parental support: Paid parental leave 11. Employee Assistance Program (EAP) and Care Counselors 12. Voluntary benefits: Legal Assistance, Critical Illness, Accident, Hospital Indemnity and Pet Insurance options 13. Health Savings Account (HSA) with employer contribution SailPoint is an equal opportunity employer and we welcome all qualified candidates to apply to join our team. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other category protected by applicable law. Alternative methods of applying for employment are available to individuals unable to submit an application through this site because of a disability. Contact applicationassistance@sailpoint.com or mail to 11120 Four Points Dr, Suite 100, Austin, TX 78726, to discuss reasonable accommodations. NOTE: Any unsolicited resumes sent by candidates or agencies to this email will not be considered for current openings at SailPoint.

Related Categories

Related Job Pages

More Security Engineer Jobs

Deutsche Telekom IT Solutions logo

Java Developer with Identity & Security Focus

Deutsche Telekom IT Solutions

As Hungary’s most attractive employer in 2025 (according to Randstad’s representative survey), Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees. We have hundreds of large customers, corporations in Germany and in other European countries. DT-ITS received the Best in Educational Cooperation award from HIPA in 2019, acknowledged as the Most Ethical Multinational Company in 2019. The company continuously develops its four sites in Budapest, Debrecen, Pécs and Szeged and is looking for skilled IT professionals to join its team.

Full TimeRemoteTeam 5,001-10,000

Role Description We are looking for a highly skilled Java Developer with a strong security mindset to join a team building Germany’s next-generation Identity Provider platform for the national healthcare Telematics Infrastructure (TI). This platform enables millions of healthcare users to securely access digital health services and operates in one of the most security-sensitive and compliance-driven environments in Europe. As a Senior Java Developer, you will be responsible for: - Designing and building highly secure backend services, authentication and authorization components, and security-critical platform capabilities. - Ensuring that security is embedded into every stage of the software development lifecycle, from architecture and implementation to deployment and operations. This role is ideal for an experienced Java engineer who enjoys solving complex security challenges and building resilient, enterprise-grade software. Qualifications - Java SW Engineering Background - 5+ years of proven software development experience. - Strong expertise in Java and Spring Boot ecosystem. - Extensive experience designing and developing enterprise-grade backend applications. - Deep understanding of distributed systems, REST APIs, microservices, and event-driven architectures. - Strong database experience, preferably PostgreSQL. - Security Expertise - Strong security-first mindset and passion for secure software development. - Solid understanding of application security principles including: - OWASP Top 10 - Secure Coding Practices - Authentication & Authorization - Threat Modeling - Secrets Management - Data Protection - Security Testing - Hands-on experience with: - Spring Security - OAuth 2.0 - OpenID Connect - JWT - mTLS - Experience implementing secure authentication and authorization mechanisms. - Good understanding of cryptography fundamentals, certificate management, PKI, and key lifecycle management. - Engineering Practices - Experience with: - Git - CI/CD pipelines - Automated testing - DevSecOps practices - Strong understanding of cloud-native application development. Requirements - Please be informed that our remote working possibility is only available within Hungary due to European taxation regulation. Company Description As Hungary’s most attractive employer in 2025 (according to Randstad’s representative survey), Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees. We have hundreds of large customers, corporations in Germany and in other European countries. DT-ITS received the Best in Educational Cooperation award from HIPA in 2019, acknowledged as the the Most Ethical Multinational Company in 2019. The company continuously develops its four sites in Budapest, Debrecen, Pécs and Szeged and is looking for skilled IT professionals to join its team.

Hungary
Full TimeRemoteTeam 10,001+H1B Sponsor

• Lead cybersecurity risk assessments and security maturity evaluations using industry frameworks, including NIST CSF, identifying control gaps, emerging risks, and opportunities to strengthen Ferguson's security posture. • Develop risk mitigation strategies, remediation plans, and governance recommendations, partnering with business and technology teams to drive sustainable risk reduction. • Support the development and continuous improvement of cybersecurity governance processes, security roadmaps, risk registers, and program performance metrics. • Coordinate and support internal and external audits, independent security assessments, regulatory reviews, and risk management initiatives. • Lead Ferguson's enterprise simulated phishing exercises and cybersecurity education program, developing risk-based campaigns and targeted training initiatives that improve employee awareness and cyber resilience. • Analyze phishing simulation results, reporting trends, and awareness metrics to identify risks, measure efficiency, and drive ongoing improvement of security culture. • Partner with business leaders, Human Resources, Corporate Communications, and Information Security teams to reduce phishing susceptibility and increase employee engagement in security procedures. • Conduct security assessments of vendors, suppliers, and technology partners as part of Ferguson's third-party risk management program. • Review security questionnaires, SOC reports, penetration test results, compliance certifications, and other security documentation to evaluate vendor risk. • Identify, assess, and communicate third-party security risks, providing recommendations to support informed business decisions and remediation efforts. • Collaborate with Procurement, Legal, and business customers to help ensure appropriate security requirements are incorporated into third-party engagements. • Develop and maintain cybersecurity dashboards, scorecards, important metrics, KRIs, and executive reporting that provide access to risk, compliance, and program performance. • Apply reporting and automation tools to improve the efficiency, effectiveness, and scalability of Governance, Risk, and Compliance (GRC) activities. • Translate technical risks into business-focused insights, helping leaders understand risk exposure, prioritize remediation efforts, and make informed decisions. • Serve as a trusted advisor on cybersecurity governance, risk management, and compliance matters, building strong partnerships across business and technology teams. • Communicate security risks, recommendations, and program outcomes effectively to both technical and non-technical audiences, including senior leadership.

United States
$8.5K - $14.8K / month
SkyePoint Decisions logo

Cybersecurity Technical Writer

SkyePoint Decisions

SkyePoint Decisions is an established ISO 9001:2015 and ISO/IEC 27001:2013 certified small business and appraised at CMMI Level 3 for Services and Development. We possess a common vision of excellence and foster a collaborative team culture built upon individual performance and accountability. We invest in our people and systems to create value for our clients. It is the SkyePoint Way. We are grateful for the opportunity to work with exceptional people and give back to the communities we serve. Our employees value the flexibility at SkyePoint that allows them to balance quality work and their personal lives. SkyePoint Decisions is a participating E-Verify Employer. U.S. Citizenship is required for most positions. Equal Opportunity Employer/Veterans/Disabled.

Full TimeRemoteTeam 51-200

Role Description This is a contingent position based on contract win. SkyePoint Decisions is seeking a Cybersecurity Technical Writer to support a cybersecurity program by developing, editing, reviewing, and maintaining technical, operational, compliance, and program management documentation. The position works closely with: - Cybersecurity engineers - RMF analysts - ISSO - Project managers - Government stakeholders The Cybersecurity Technical Writer will perform independent quality assurance reviews of RMF, cybersecurity, governance, risk, compliance, and executive reporting artifacts to ensure: - Completeness - Consistency - Traceability - Section 508 compliance - Readiness for Government submission This position is fully remote. Responsibilities: - Develop, edit, and maintain cybersecurity documentation supporting programs and systems. - Create and update technical documents, reports, procedures, and operational guides. - Translate complex cybersecurity concepts into clear, understandable language for technical and non-technical audiences. - Ensure consistency, quality, accuracy, and formatting across all program deliverables. - Maintain document repositories and version control processes. - Support development and maintenance of authorization package documentation, including: - System Security Plans (SSPs) - Security Assessment Plans (SAPs) - Security Assessment Reports (SARs) - Plans of Action and Milestones (POA&Ms) - Security Categorization documentation - Contingency Plans - Incident Response Plans - Standard Operating Procedures (SOPs) - Policies and Standards - Review cybersecurity artifacts for completeness, quality, and compliance. - Coordinate document updates resulting from assessments, audits, and authorization activities. - Develop executive briefings, status reports, dashboards, and presentation materials. - Assist with monthly, quarterly, and annual reporting requirements. - Perform technical editing, proofreading, and formatting of cybersecurity deliverables. - Ensure documents adhere to organizational documentation standards. - Ensure documents, reports, presentations, and deliverables meet Section 508 accessibility requirements. - Review and remediate documents for accessibility compliance. Qualifications - Bachelor's degree in Technical Writing, English, Communications, Information Technology, Cybersecurity, or a related field. - Minimum 3-5 years of experience in technical writing supporting cybersecurity, IT, or Federal programs. - Experience developing technical documentation in support of cybersecurity or information technology initiatives. - Strong technical writing, editing, proofreading, and document management skills. - Experience creating executive reports, technical documentation, and standard operating procedures. - Familiarity with: - NIST Risk Management Framework (RMF) - NIST SP 800-53 - FISMA - Federal cybersecurity documentation requirements - Proficiency with Microsoft Office Suite, including Word, Excel, PowerPoint, and Visio. - Strong organizational and communication skills. - U.S. Citizenship required. - Ability to obtain and maintain a Public Trust. Preferred Qualifications - One or more of the following certifications: - Certified Professional Technical Communicator (CPTC) - Security+ - CGRC (Certified in Governance, Risk and Compliance) - CAP (Certified Authorization Professional) - CISSP - Microsoft Office Specialist (MOS) - Experience supporting Federal civilian agencies. - Experience supporting RMF authorization efforts and cybersecurity compliance programs. - Knowledge of cybersecurity governance, risk, and compliance processes. - Experience creating documentation for cloud, cybersecurity, and IT operations programs. - Familiarity with ServiceNow, SharePoint, Confluence, Jira, eMASS, or similar documentation platforms. - Experience supporting proposal development and technical volume preparation. Compensation - Salary Range: $110K - $130K - The SkyePoint Decisions salary range for this position is a general guideline only. It represents an estimated range for this position and is just one piece of our total compensation package. - Salary at SkyePoint is determined by various factors, including but not limited to location, work schedule, the candidate’s combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability, market data and business considerations. Benefits - Competitive salary - Certification incentive program - PTO - Floating federal holiday options - Several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs] - Flex Spending Accounts [FSAs] - Full Dental Plans - Vision - ST/LT Disability - Life Insurance - 401k matched

United States
$110K - $130K / year
Rimini Street logo

AI Security Engineer

Rimini Street

Extraordinary technology solutions powered by extraordinary people

Full TimeRemoteTeam 1,001-5,000Since 2005H1B Sponsor

• Develop and maintain AI security standards, governance requirements, and control frameworks. • Review and assess AI tools, agents, platforms, and use cases for security, privacy, compliance, and operational risk. • Partner with Security Operations, IT, and business teams to implement appropriate controls for AI-enabled solutions. • Monitor emerging AI threats, attack techniques, and industry best practices and translate them into actionable security controls. • Coordinate AI risk assessments, exception reviews, and governance activities.

United States
$102K - $153K / year