Human Interest is a high-growth fintech company on a mission to provide accessible retirement benefits to all lines of work. The Senior Technical Program Manager will collaborate with Infosec and Risk teams to integrate security into the software development lifecycle, ensuring that security measures enhance rather than hinder the company's objectives.
Responsibilities:
- Technical security orchestration: Partner with Security Engineering, Risk, Product, and Infrastructure teams to bake security and compliance "into the kiln" rather than painting it on at the end
- Help design risk solutions: Dive deep into the security stack to not only identify execution blockers but actively architect the technical solutions to implement them
- Help architect our security mission: Define the technical milestones for high-stakes initiatives like Zero Trust and IAM overhauls, translating a broad vision into a precise execution roadmap
- Drive high-velocity operations: Lead agile security sprints that harmonize vulnerability remediation and threat detection with feature development, ensuring security moves at the speed of innovation
- Optimize the "rhythm of the business" by automating manual GRC workflows, eliminating manual friction and moving us toward Compliance as Code
- Translate telemetry into narrative: Distill complex security data and telemetry into compelling risk narratives for leadership while maintaining high-fidelity technical depth for engineers
- Optimize the defensive roadmap: Command long-term strategic planning by aligning cloud infrastructure costs and security tooling with the company’s overarching defensive goals
- Cultivate organizational excellence: Uphold a relentless culture of focus and accountability, identifying systemic inefficiencies and driving impact through superior tooling and process engineering
Requirements:
- Bachelor's degree in CS, Engineering, or a related field
- TPM professional for 5+ years, specifically managing high-stakes security, privacy, or infrastructure initiatives
- Deep understanding of the Security SDLC and experience navigating cloud-native service architectures (AWS/GCP) with a focus on security guardrails
- Experience translating regulatory frameworks (e.g., SOC2, ISO 27001, FedRAMP, or GDPR) into concrete technical requirements that engineers can actually execute
- Proven ability to 'go deep.' Comfortable looking at architectural diagrams, API docs, or cloud configurations to find the root cause of a program delay
- Exceptional communication skills with a knack for explaining the 'why' behind a security control to a developer and the 'how' of a technical fix to an auditor
- Strong ability to leverage data—from vulnerability scanners to Jira velocity—to tell a story and drive cross-functional decision-making