Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Staff Technical Program Manager, Security Assurance image - Rise Careers
Job details

Senior Staff Technical Program Manager, Security Assurance

About Us:

SentinelOne is defining the future of cybersecurity through our XDR platform that automatically prevents, detects, and responds to threats in real-time. Singularity XDR ingests data and leverages our patented AI models to deliver autonomous protection. With SentinelOne, organizations gain full transparency into everything happening across the network at machine speed – to defeat every attack, at every stage of the threat lifecycle. 

We are a values-driven team where names are known, results are rewarded, and friendships are formed. Trust, accountability, relentlessness, ingenuity, and OneSentinel define the pillars of our collaborative and unified global culture. We're looking for people that will drive team success and collaboration across SentinelOne. If you’re enthusiastic about innovative approaches to problem-solving, we would love to speak with you about joining our team!

What are we looking for?

The goal of Technical Program Manager - Security Assurance is to ensure that the SentinelOne system meets its security requirements and is resilient against security vulnerabilities through the implementation and management of security hardening, testing, and vulnerability management. These activities include defining security goals/metrics, driving the vulnerability management program, rebuilding processes to scale with the business, assisting in analyzing threats, supporting penetration testing and security audits, and providing recommendations and mitigation plans.

What will you do? 

  • Vulnerability Management
    • Lead the design, development, and execution of the Vulnerability Management Program, ensuring alignment with organizational security goals and compliance requirements.
    • Oversee the identification, assessment, and prioritization of all vulnerabilities across all environments, including cloud, on-premises, and hybrid infrastructures.
    • Develop and maintain processes for timely and effective vulnerability remediation, working closely with engineering and operations teams.
    • Monitor and report on vulnerability management metrics, providing deep security insights and recommendations to senior leadership.
    • Identify and assess risks associated with vulnerabilities, providing detailed analysis, correlation, categorization, and recommendations for risk mitigation.
    • Serve as a key point of contact for vulnerability management, working closely with stakeholders across the organization to communicate risks, progress, and remediation efforts.
  • Secure Software Development Life Cycle
    • Collaborate with development teams to help define and build a robust secure software development life cycle by incorporating security testing, code scanning, and vulnerability assessment results to ensure security is embedded in all parts of the development life cycle.
  • Continuous Improvement
    • Identify and drive continuous improvement initiatives, to include Red Team and external penetration testing, to enhance the effectiveness and efficiency of the workflows and processes and scale with the business.
    • Collaborate with product teams to build Bug Bounty campaigns and hack-a-thons to help identify gaps regarding the effectiveness of our internal security and engineering practices.
  • Security Compliance
    • Oversee that SentinelOne security hardening standards are met, monitored, and maintained.
    • Ensure compliance with relevant regulatory requirements and industry standards (e.g., NIST, ISO 27001, PCI-DSS) through effective security assurance practices.
    • Help build and define training and awareness programs and guidance to promote a security-first mindset among development, operations, and business teams.
    • Stay current with emerging threats, vulnerabilities, and industry trends, incorporating new tools and techniques into the security workflows and processes.
  • Reporting
    • Prepare and present actionable reports on the status and trends of the security posture of the system to internal and external stakeholders.
    • Facilitate effective communication across teams and stakeholders regarding security updates and initiatives.
    • Handle business escalations with a data-driven approach to build trust with security, IT and engineering teams.
    • Create and manage project timelines, establish key milestones and major deliverables, ensure resource alignment, and drive teams forward.

What skills and knowledge should you bring?

  • Bachelor’s degree in cybersecurity, information technology, computer science, or a related field; advanced degree preferred.
  • 7+ years of progressive experience in cybersecurity, with at least 5+ years dedicated to building or supporting Vulnerability Management Programs.
  • 2-3 years experience supporting DevSecOps, including integrating security practices into CI/CD pipelines and development processes.
  • Strong knowledge of vulnerability assessment tools (e.g., Nessus, Qualys, Tenable, Metasploit).
  • Familiarity with cloud security practices and platforms (e.g., AWS, Azure, Google Cloud).
  • Background and experience working with security frameworks and standards (e.g., NIST, ISO 27001, OWASP, CIS Controls).
  • Excellent project management skills with the ability to manage multiple projects and initiatives simultaneously.
  • Strong analytical, problem-solving, and communication skills, with the ability to present complex information to technical and non-technical audiences.
  • Hold relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or Certified Information Security Manager (CISM).

Why us?

You will be joining a cutting-edge company where you will tackle extraordinary challenges and work with the very best in the industry.

  • Medical, Vision, Dental, 401(k), Commuter, Health and Dependent FSA
  • Unlimited PTO
  • Industry-leading gender-neutral parental leave
  • Paid Company Holidays
  • Paid Sick Time
  • Employee stock purchase program
  • Disability and life insurance
  • Employee assistance program
  • Gym membership reimbursement
  • Cell phone reimbursement
  • Numerous company-sponsored events, including travel for conferences and team-building events
This U.S. role has a base pay range that will vary based on the location of the candidate.  For some

locations, a different pay range may apply.  If so, this range will be provided to you during the recruiting

process.  You can also reach out to the recruiter with any questions.

Base Salary Range
$176,000$242,000 USD

SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

SentinelOne participates in the E-Verify Program for all U.S. based roles. 

SentinelOne Glassdoor Company Review
4.6 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
SentinelOne DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of SentinelOne
SentinelOne CEO photo
Tomer Weingarten
Approve of CEO

Average salary estimate

$209000 / YEARLY (est.)
min
max
$176000K
$242000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Staff Technical Program Manager, Security Assurance, SentinelOne

At SentinelOne, we are redefining the future of cybersecurity, and we're on the lookout for a Senior Staff Technical Program Manager, Security Assurance to join our energetic remote team! In this role, you will be at the forefront of ensuring our groundbreaking XDR platform meets its security requirements and remains resilient against vulnerabilities. You’ll lead initiatives to drive our Vulnerability Management Program, helping us stay a step ahead of potential threats across cloud, on-premises, and hybrid infrastructures. Your analytical skills will shine as you assess and prioritize risks, develop remediation processes, and provide crucial insights that inform our senior leadership. Collaborating with development teams, you'll embed security into our Software Development Life Cycle, paving the way for continuous improvement initiatives, including innovative Bug Bounty campaigns that keep our systems secure. You’ll be tasked with ensuring compliance with industry standards and creating training programs that foster a security-first mindset throughout the organization. With the opportunity to directly influence SentinelOne’s security posture, your leadership will enhance both our workflows and the capabilities of our teams. If you're passionate about cybersecurity and eager to tackle extraordinary challenges in an environment that values trust and collaboration, we want to discuss how you can help further our mission!

Frequently Asked Questions (FAQs) for Senior Staff Technical Program Manager, Security Assurance Role at SentinelOne
What are the core responsibilities of a Senior Staff Technical Program Manager, Security Assurance at SentinelOne?

As a Senior Staff Technical Program Manager, Security Assurance at SentinelOne, your primary responsibilities include leading the design and execution of the Vulnerability Management Program, ensuring alignment with security goals, and managing vulnerability remediation processes. You'll assess risks, collaborate with engineering teams to integrate security in the development cycle, and oversee compliance with regulatory requirements. Your role will also involve monitoring metrics and communicating progress on security initiatives to stakeholders.

Join Rise to see the full answer
What qualifications are required for the Senior Staff Technical Program Manager, Security Assurance position at SentinelOne?

To be considered for the Senior Staff Technical Program Manager, Security Assurance role at SentinelOne, candidates should possess a bachelor’s degree in cybersecurity or a related field, with an advanced degree preferred. You should also have over 7 years of progressive experience in the cybersecurity field, including a minimum of 5 years focused on Vulnerability Management. Proficiency with vulnerability assessment tools and familiarity with cloud security practices are also necessary. Relevant certifications such as CISSP, CEH, or CISM are highly regarded.

Join Rise to see the full answer
How does the Senior Staff Technical Program Manager, Security Assurance contribute to SentinelOne's mission?

The Senior Staff Technical Program Manager, Security Assurance plays a crucial role in advancing SentinelOne's mission by ensuring our XDR platform remains secure against emerging threats. By managing the Vulnerability Management Program and fostering a culture of security compliance, you ensure that SentinelOne's systems are not only resilient but also continuously improved to meet the dynamic needs of cybersecurity. Your efforts directly contribute to maintaining trust with our customers and stakeholders.

Join Rise to see the full answer
What security frameworks is the Senior Staff Technical Program Manager, Security Assurance at SentinelOne expected to be familiar with?

In the Senior Staff Technical Program Manager, Security Assurance role at SentinelOne, familiarity with security frameworks and standards such as NIST, ISO 27001, OWASP, and CIS Controls is essential. Understanding these frameworks helps guide the implementation of robust vulnerability management practices and compliance assurance, ensuring our organization meets both industry standards and regulatory requirements.

Join Rise to see the full answer
What career growth opportunities exist for the Senior Staff Technical Program Manager, Security Assurance at SentinelOne?

At SentinelOne, the Senior Staff Technical Program Manager, Security Assurance position is well-suited for career advancement within a rapidly evolving field. Opportunities for growth include taking the lead on larger security initiatives, mentoring junior team members, and potentially moving into executive leadership roles as SentinelOne expands its market impact. With ongoing professional development and a commitment to innovation, your career can flourish alongside the company.

Join Rise to see the full answer
Common Interview Questions for Senior Staff Technical Program Manager, Security Assurance
Can you explain your approach to vulnerability management in a software development lifecycle?

When addressing vulnerability management in a software development lifecycle, I focus on integrating security at each phase of development. This means collaborating with development teams early to define secure coding practices, utilizing automated tools for code scanning, and ensuring comprehensive testing is conducted at various stages to identify vulnerabilities proactively. Communicating findings clearly with development teams is crucial for fostering a collaborative security mindset.

Join Rise to see the full answer
What tools do you prefer for vulnerability assessment and why?

I have a strong preference for tools like Nessus and Qualys due to their comprehensive capabilities in vulnerability scanning and reporting. They offer in-depth assessments across various environments and are user-friendly for teams to adopt. Additionally, integrating these tools into CI/CD pipelines helps automate the scanning process, ensuring vulnerabilities are identified and addressed promptly.

Join Rise to see the full answer
How do you prioritize vulnerabilities in your management program?

Prioritizing vulnerabilities involves assessing their potential impact and exploitability within our environment. I utilize risk-based methodologies, collaborating with stakeholders to understand business context and priorities. By categorizing vulnerabilities into critical, high, medium, and low risk, I can direct resources effectively and ensure timely remediation of the most significant threats.

Join Rise to see the full answer
Describe a situation where you had to advocate for security practices to non-technical stakeholders.

One instance involved presenting security risks to our executive team regarding a major software release. I focused on aligning potential security implications with business impact, using visual metrics and relatable examples to illustrate risks. This approach helped build understanding and buy-in, leading to increased support for implementing security measures that ultimately enhanced our product's integrity.

Join Rise to see the full answer
What continuous improvement initiatives have you advocated in your previous roles?

In my previous roles, I’ve led initiatives involving Red Team assessments and penetration testing to identify gaps in security practices. I also championed the establishment of Bug Bounty programs, engaging external cybersecurity researchers to discover vulnerabilities. Both initiatives resulted in enhanced security postures and enriched collaboration among teams, fostering a more proactive security culture.

Join Rise to see the full answer
How do you stay updated on the latest security threats?

I stay updated on security threats by following reputable sources such as security blogs, industry webinars, and forums. Additionally, I participate in professional organizations and attend conferences to network with peers and share insights. This continuous learning approach allows me to incorporate new tools and techniques into our vulnerability management practices effectively.

Join Rise to see the full answer
What role does communication play in your approach to vulnerability management?

Communication is pivotal in vulnerability management; it ensures that all stakeholders are aligned and aware of the current security posture. I prioritize clear and consistent communication, whether sharing vulnerability metrics with leadership or collaborating with engineering teams on remediation efforts. An open dialogue fosters accountability and encourages a security-first mindset across the organization.

Join Rise to see the full answer
How do you ensure compliance with security regulations and standards?

I ensure compliance by regularly conducting audits against established standards such as NIST and ISO 27001. This involves implementing robust policies, conducting training for team members, and utilizing assessment tools to ascertain adherence. Distributing findings and corrective action plans transparently helps maintain accountability and fosters a culture of compliance.

Join Rise to see the full answer
Can you detail your experience with integrating security into CI/CD pipelines?

My experience with CI/CD security integration includes working closely with development teams to incorporate automated security testing tools at various stages of the pipeline. This involves setting up pre-commit hooks to trigger scans, ensuring issues are identified before code progression. I’ve also led training sessions to equip teams with the knowledge to recognize and address security considerations, leading to more secure deployment practices.

Join Rise to see the full answer
What advice would you give to someone new to vulnerability management?

For anyone new to vulnerability management, I recommend starting with a solid understanding of the security landscape and the tools available. Engage in regular collaborations with both technical and non-technical teams to grasp the business implications of security issues. Lastly, don’t hesitate to advocate for a culture of continuous improvement and awareness—security is a shared responsibility, and involving everyone is key.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
SentinelOne Remote United States - Remote
Posted 9 days ago
Photo of the Rise User
SentinelOne Remote United States - Remote
Posted 9 days ago
Photo of the Rise User
Posted 11 days ago
Photo of the Rise User
Posted 5 days ago
Photo of the Rise User
Peraton Hybrid Herndon, AR
Posted 4 days ago
Photo of the Rise User
Posted 6 days ago
Photo of the Rise User
Posted 6 days ago
Photo of the Rise User
Posted 7 days ago

Defeating every attack, every second of every day.

85 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
December 3, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!