Security Technical Program Manager
Job description
About the role
You will drive end-to-end security and infrastructure programs that define the foundation for Sierra's AI customer platform. You will own the planning, sequencing, and execution of complex security initiatives spanning cloud infrastructure, identity and access management, detection and response, vulnerability management, and secure software delivery. You will translate ambiguous risk and compliance challenges into structured, measurable programs that balance growth, trust, and long-term scalability. You will partner closely with security, engineering, product, and executive leadership to shape Sierra's security strategy and ensure initiatives are aligned with customer trust and platform reliability. You will act as the central hub for communication, surfacing issues early, managing dependencies, and keeping critical security programs on track for decisive outcomes. You will operate with high ownership and agency in an environment where security foundations are still being defined, helping decide what needs to be built first and how it should scale.
Key facts
What you'll do
Drive high-impact security and infrastructure initiatives end-to-end while coordinating cross-functional dependencies and maintaining rigorous program health.
Own execution, planning, and program health by defining milestones, managing risks, and ensuring delivery of Sierra's most critical security programs with clear outcomes.
Help shape Sierra's security strategy in partnership with security and engineering leadership to prioritize investments that reduce risk while enabling platform growth and scalability.
Build and strengthen security foundations by driving programs around identity boundaries, access controls, logging and detection baselines, incident readiness, and secure defaults for future teams.
Translate ambiguous security, risk, and compliance challenges in emerging AI domains into structured workstreams, prioritized deliverables, and measurable outcomes.
Lead communication and alignment by providing clear, concise updates to leadership on program health, risks, dependencies, and tradeoffs while surfacing issues early.
Collaborate with engineering teams such as Infrastructure, Data Platform, and Agent SDK to define technical requirements, manage dependencies, and deliver resilient systems.
Partner with Security and GRC on threat models, control strategy, audits, and risk management to ensure alignment in a rapidly evolving AI landscape.
Work with Product and GTM to operationalize security commitments and respond to sophisticated customer and regulator expectations without compromising velocity.
Coordinate with Legal on security terms, third-party risk, and contractual obligations to ensure programs remain compliant and enforceable.
Provide clear prioritization and decision support to executive leadership, building confidence in Sierra's security strategy and execution capabilities.
Support the scaling of security programs globally by contributing to processes suitable for AI-first or data-intensive SaaS environments and multi-cloud setups.
Requirements
Demonstrate experience running security-focused technical programs in fast-growing SaaS or platform environments with a track record of delivery.
Show strong technical fluency across cloud infrastructure, identity and access management, infrastructure as code, observability, secure CI/CD, and incident response.
Prove ability to execute through ambiguity, prioritize effectively under constraints, and keep multiple teams moving toward shared outcomes.
Comfort operating in environments where things are not fully built yet and helping define what needs to be built first in a regulated context.
Communicate clearly and concisely with senior technical and business leaders, translating complex security concepts into actionable plans.
Collaborate in a pragmatic, collaborative style while maintaining high ownership, high agency, and accountability for program outcomes.
Have experience scaling security programs globally, ideally in AI-first or data-intensive SaaS environments where risk and compliance are continuously evolving.
Understand emerging AI risk, data governance, and agent and model-related security considerations relevant to platform and customer trust.
Nice to have
Experience supporting security initiatives in public-sector, regulated and/or multi-cloud environments (AWS, GCP, Azure).
Relevant security, cloud, AI or technical program management certifications.
Familiarity with regulatory and compliance frameworks such as ISO 27001, PCI DSS, FedRAMP, and HIPAA.
Practical notes
This role is based in San Francisco, California, and requires in-person presence during standard business hours.
Travel may be required for security engagements, customer meetings, and cross-office collaboration.
Candidates must be authorized to work in the United States without sponsorship for this position.