Technical Program Manager, Security - Coordinated Vulnerability Disclosure
Related skills
codeql cve oss-fuzz coordinated_vulnerability_disclosure cert_ccπ Description
- Own end-to-end CVD program strategy and execution.
- Lead internal triage and QA of AI findings.
- Design tiered disclosure timelines by severity.
- Build pacing and submission models for findings.
- Lead external coordination with maintainers and vendors.
- Establish program metrics and reporting.
π― Requirements
- 10+ years in cybersecurity or vulnerability management; 4+ years leading disclosure programs.
- Deep understanding of coordinated vulnerability disclosure with CERT/CC or MITRE CVE.
- Familiar with vulnerability discovery tooling, static analysis, fuzzing (OSS-Fuzz, CodeQL), triage workflows.
- Experience engaging with open-source maintainers and governance dynamics.
- Proven TPM or similar role in security with cross-org program leadership.
- Executive communication skills; ability to influence senior leadership and C-suite.
π Benefits
- Competitive compensation and benefits.
- Optional equity donation matching.
- Generous vacation and parental leave.
- Flexible working hours.
- Lovely office space.
π Visa sponsorship
Meet JobCopilot: Your Personal AI Job Hunter
Automatically Apply to Engineering Jobs. Just set your
preferences and Job Copilot will do the rest β finding, filtering, and applying while you focus on what matters.
Help us maintain the quality of jobs posted on Empllo!
Is this position not a remote job?
Let us know!