Gusto is on a mission to grow the small business economy, handling payroll, health insurance, 401(k)s, and HR for more than 500,000 small businesses nationwide.
Teams in Denver, San Francisco, and New York.
About the role
As the Vulnerability Management Technical Lead, you'll own the definition and delivery of Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk.
You'll drive the centralized vulnerability scorecard, expand detection and monitoring coverage, harden the SDLC, and stand up the security metrics leadership runs the business on.
Responsibilities
Set the strategy and roadmap for vulnerability management and security operations as Gusto becomes an AI-native company.
Lead delivery of the centralized vulnerability management program: coverage across code, cloud, data, and edge; CSPM/DSPM, container scanning, dependency and secrets detection, and owner-based remediation routing to closure.
Lead security operations delivery: expand high-risk detection and alerting, impersonation and privileged-access logging, SIEM integration, insider-risk telemetry, and logging of agentic activity.
Stand up daily security-health and vulnerability-management metrics dashboards and drive monthly vulnerability reporting.
Build security workflows that run on AI plugins by default.
Roll out new controls like risk-scored PR review, JIT privileged access, and secrets management.
Manage stakeholders and vendors, watch program budget, tooling spend, and implementation costs.
Requirements
5 to 8+ years leading cross-functional TPM or delivery work, with real time spent on security, infrastructure, or platform engineering.
Solid handle on vulnerability management and security operations, from scanning coverage and remediation SLAs to detection engineering, SIEM/monitoring, and identity and privileged access.
Ability to speak the language of security engineering, infrastructure, GRC, and R&D.
Nice to have: familiarity with Wiz, Axonius, Panther, Opal; AI clients and plugins (MCPs); SOC 1/2 and ISO 27001; PM certification (PMP, CAPM, Scrum, or Prosci).
Conditions
Hybrid role based in San Francisco, CA.
Competitive base pay, benefits, and equity (RSUs).