Unknown Company

Technical Program Manager

san francisco, ca • Posted 3 days ago
Hybrid Full Time General

Technical Program ManagerSan Francisco, California, United StatesAbout TaskrabbitTaskrabbit is a marketplace platform that conveniently connects people with Taskers to handle everyday home to-do's, such as furniture assembly, handyman work, moving help, and much more.At Taskrabbit, we want to transform lives one task at a time. As a company we celebrate innovation, inclusion and hard work. Our culture is collaborative, pragmatic, and fast-paced. We're looking for talented, entrepreneurially minded and data-driven people who also have a passion for helping people do what they love.

Together with IKEA, we're creating more opportunities for people to earn a consistent, meaningful income on their own terms by building lasting relationships with clients in communities around the world.Taskrabbit is a hybrid company with employees distributed across the US and EU and a Built In — Best Places to Work (2022, 2023, 2024, 2025) continually ranked across multiple national and regional categories. Join us at Taskrabbit, where your work will be meaningful, your ideas valued, and your potential unleashed!About the RoleTaskrabbit is maturing its engineering organization toward a scalable, secure, and compliant environment, anchored on three programs: Oncall Modernization, Cloud Infrastructure Modernization, and CIS IG1 compliance. Today, the operational "process tail" of these programs—audit evidence gathering, cross-departmental coordination, policy rollout, vulnerability SLA enforcement, and periodic reviews, is absorbed by our most senior technical talent. This is our first dedicated Infrastructure & Security TPM.This role owns the program layer so our ICs and Engineering Managers can refocus on implementation, advisory, review, and architecture.

You will drive CIS IG1 to sustained compliance, lead its expansion from engineering to the entire company, and build the foundation for IG2 and IG3. You will be the "air traffic controller" for security and infrastructure requests.This is a high-visibility, foundational role with a direct mandate to build durable processes from the ground up. You will report to the Director of TPM and partner daily with our infrastructure and security leadership.What You'll DoCompliance & Security Program OwnershipOwn the end-to-end CIS IG1 program: intake, evidence collection, SLA enforcement, and periodic review cycles across all 18 control familiesExpand CIS controls from local engineering teams to the entire company, and build the roadmap for IG2 and IG3Maintain the CIS Crosswalk Tracker as a living record of audit readiness and control statusTranslate technical controls into actionable Jira workflows and enforceable remediation SLAsManage the annual external Penetration Test program and track remediation of findings to closureGovernance & IntakeDesign and operate a centralized intake process for security and infrastructure requests, ensuring engineers work only on vetted, prioritized workStandardize access-granting workflows for new hires, role changes, and tool requests—with full audit trailsEstablish and enforce SLAs for vulnerability remediation, PR reviews, and ticket response; report compliance to leadershipStakeholder & Cross-Functional OrchestrationServe as the primary interface between Engineering, Security, Legal, Finance, IT, and Procurement for security-related programs, vendor reviews, and auditsNegotiate infrastructure and security work into team sprints; manage GIVE/GET dependency tracking with Engineering DirectorsDrive policy approvals and company-wide rollouts (e.g., Data Management, Secure Configuration, Access Control) from draft to operationalized and signed-offOperational Excellence (Run the Business)Operationalize recurring compliance work: quarterly access reviews, monthly vulnerability triage, bi-annual asset inventory updates, annual vendor reassessments, and tabletop BCP exercisesBuild and maintain dashboards and automated evidence pipelines to reduce manual compliance choresReport security posture, key metrics, and a "Security Score" to senior leadership in clear, business-readable termsLead the BCP program: standardize templates, schedule tabletop exercises, document results, and drive remediation into engineering sprintsIncident & Vulnerability Program ManagementScale vulnerability management from local triage to a company-wide SLA-driven program using Wiz, HackerOne, and JiraOwn the SLA—chasing teams to close critical findings within 7 days and reporting Days-to-Patch to leadershipManage the phishing response playbook and incident post-mortem process; ensure P0/P1 action items land in sprintWho You'll Work WithEngineering Director, Infrastructure & SecuritySenior Manager, Cloud InfrastructureSecurity ManagerInfosec/Security team ICsOther TPM'sEngineering Managers and ICs across Cloud Infrastructure and SRELegal (data retention, SOC2/vendor reviews), Finance (security budget), IT (endpoint and asset coverage, Okta), Procurement, and the Data Lead (PII inventory and retention)Senior Engineering and Product leadership (risk and metrics reporting)What We're Looking ForRequired Experience3+ years of technical program management in an infrastructure, security, SRE, or compliance environmentDemonstrated ability to translate security controls (e.g., CIS, SOC2) into actionable Jira workflows, SLAs, and repeatable operational processesProven track record driving company-wide, cross-departmental initiatives through to completion—including securing stakeholder sign-offs and managing organizational resistanceExperience operationalizing run-the-business processes: access reviews, vulnerability remediation tracking, audit evidence collection, and periodic compliance reviewsSufficient technical depth in cloud infrastructure, SRE, and infosec to coordinate credibly with engineers and translate findings for non-technical leadersStrong executive communication skills—able to synthesize technical risk into a business-readable security score and status reportEnd-to-end program ownership: from intake governance and dependency tracking through leadership reportingNice to HavesFamiliarity with CIS Controls v8.1 and the IG1/IG2/IG3 frameworkHands-on exposure to tools in our stack: Wiz, HackerOne, CrowdStrike, Datadog, Okta, JAMF, or KnowBe4Experience supporting SOC2 or PCI auditsJira workflow and dashboard configuration experienceBackground in GRC (Governance, Risk, and Compliance) or security program managementExperience working in an organization operating under a parent- or partner-company compliance contextWhat Success Looks LikeICs and Engineering Managers have measurably less coordination toil—30-40% of their program overhead returned to implementation and advisory workCIS IG1 sustained at or near 100% with automated evidence pipelines, expanded beyond engineering to all departmentsCentralized intake and governance live; SLAs for vulnerability remediation and request response published and enforcedAt least one full periodic review cycle (quarterly access review or monthly vulnerability triage) fully operationalized with documented evidence within 90 daysBCP program established and validated via tabletop exercise within the first yearLeadership receives a clear, consistent security score and metrics report; technical risk is legible to the SLTA credible roadmap for CIS IG2/IG3 underway within one yearCompensation & BenefitsAt Taskrabbit, our approach to compensation is designed to be competitive, transparent and equitable. Total compensation consists of base pay + annual bonus + benefits + perks.

The base pay range for this position is $87,000 - $120,000. This range is representative of base pay only, and does not include any other total cash compensation amounts, such as company bonus or benefits. Final offer amounts may vary from the amounts listed above, and will be determined by factors including, but not

Back to Job Search