{"schemaVersion":"jobsearcher.job.v1","id":"aaefc9695dd349fedbe42c0a","url":"https://jobsearcher.com/jobs/aaefc9695dd349fedbe42c0a","canonicalUrl":"https://jobsearcher.com/jobs/aaefc9695dd349fedbe42c0a","title":"Principal Technical Program Manager, Security","description":"POS- 29555\nAbout You:\nYou're a highly technical, execution-driven program leader who thrives working alongside security engineers and product leaders to ship meaningful security improvements at scale. You bring structure to complex, fast-moving initiatives without slowing them down, and you earn trust with engineers and senior leaders alike by understanding the work deeply enough to drive it forward. You shape platform direction, influence executive decisions, and connect security program outcomes to long-term business impact. You're comfortable operating autonomously in ambiguous environments, know how to navigate organizational complexity, and use AI as a genuine force multiplier in your daily work.\nAbout Us:\nThe HubSpot Security team is dedicated to helping businesses grow better by safeguarding the systems and data that power our global CRM platform. With more than 125,000 customers in over 100 countries, HubSpot's security posture is essential to our mission and a competitive differentiator.\nAs part of the Security Governance and Risk team, you'll:\nPartner closely with security engineering teams to drive the Security Product Line's highest-priority initiatives from planning through delivery.\nOperate at the intersection of security, engineering, and governance, keeping complex multi-team programs moving and unblocking what needs to get done.\nShape how the Security Governance group operates at scale, building the operating rhythms, frameworks, and tooling that let security teams do their best work.\nJoin a culture that values transparency, learning, and authenticity.\nIn this role you will…\nSecurity Engineering Partnership (Core Focus)\nServe as an embedded TPM for security engineering teams, owning program execution for the Security Product Line's most complex and strategically important initiatives.\nDrive end-to-end delivery of large-scale security programs spanning detection and response, identity and access, infrastructure security, application security, and more.\nPartner with security engineering leads and product managers to define roadmaps, sequence work, manage dependencies to keep initiatives on track.\nNavigate ambiguity and organizational complexity independently, escalating the right things to the right people and clearing blockers before they become delays.Champion scalable processes and durable systems within the security organization, raising the operational bar across the product line.\nOwn portfolio-level KPIs, building reporting that connects program delivery to customer, reliability, and business outcomes.\nServe as a thought leader within the TPM function, sharing strategies,approaches, and AI enabled workflows that elevate how the whole team works.\nSOX Compliance for UBB (Near-Term Priority)\nIn the near term, this role will focus on supporting SOX compliance for HubSpot's Usage-Based Billing features. The goal is to build a streamlined, repeatable process for bringing UBB features into SOX compliance, at which point this role hands off to a more sustainable operating model and shifts fully into security engineering TPM support.\nPartner with FinTech and FinOps program management to coordinate SOX compliance work across Engineering, Finance, and Security, keeping the program moving and stakeholders aligned.\nDrive implementation of SOX-compliant technical controls, partnering closely with engineering teams to sequence the work, remove blockers, and get features across the line.\nEnsure UBB features are integrated into the right SOX control frameworks and that engineering teams understand compliance requirements well enough to build compliantly from the start.\nBuild a repeatable, scalable playbook so new UBB features can be evaluated, instrumented, and brought into SOX compliance without starting from scratch each time.\nAI-Powered Execution\nActively use AI tools (e.g., Claude, ChatGPT, or similar) to accelerate program planning, documentation, risk analysis, and stakeholder communications.\nModel AI-fluent working habits for the team, sharing workflows and prompting strategies that multiply output quality and speed.\nIdentify where AI materially changes how security engineering programs are planned, executed, or measured, and translate those opportunities into program strategy and investment priorities.\n\nWe are looking for people who have…\n12+ years of technical program management experience, with a significant portion embedded with security or software engineering teams in a SaaS or cloud environment.\nDeep enough technical fluency to earn credibility with security engineers, understand the work, and ask the right questions without needing to be a practitioner.\nExperience partnering with senior security engineering leaders to shape platform direction, technical standards, and execution guardrails, and the ability to connect security program outcomes to long-term business leverage and security risk.\nHands-on experience leading security programs across domains such as detection and response, identity and access management, infrastructure security, application security, and more.\nThe ability to build durable operating systems: program structures, escalation paths, reporting cadences, and tooling that outlast individual initiatives.\nFamiliarity with compliance security frameworks and standards such as SOX, ISO 27001, NIST, SOC 2, or MITRE ATT&CK sufficient to navigate security conversations and program requirements.\nDemonstrated AI fluency, with a habit of using AI tools to improve the quality, speed, and consistency of program management work. You don't just know these tools exist; you use them daily and have strong opinions on how they fit into a TPM's workflow.\nExperience as a force multiplier for a TPM team, including developing methodologies, mentoring peers, and raising the bar on program quality.\nExcellent written and verbal communication skills, with the ability to translate complex technical and operational topics for diverse audiences.\n\nNice to have:\nHands-on experience working with security engineering teams on major platform or infrastructure security initiatives.\nFamiliarity with SaaS architecture and cloud infrastructure (AWS/GCP) at a depth that helps you understand security engineering trade-offs.\nCertification(s) such as PMP, CISM, CISSP, or CISA.\nPrior experience with Usage-Based Billing or revenue recognition controls in a SaaS context.\nHands-on experience with Asana, GitHub, or similar tools to manage large-scale security programs.\nExperience integrating AI tools into security or engineering workflows, such as using LLMs for documentation, risk summarization, or program reporting.\nWe know the confidence gap and impostor syndrome can get in the way of meeting spectacular candidates, so please don't hesitate to apply — we'd love to hear from you.\nIf you need accommodations or assistance due to a disability, please reach out to us using this form.\nAt HubSpot, we value both flexibility and connection. Whether you're a Remote employee or work from the Office, we want you to start your journey here by building strong connections with your team and peers. If you are joining our Engineering team, you will be required to attend a regional HubSpot office for in-person onboarding. If you join our broader Product team, you'll also attend other in-person events, such as your Product Group Summit and other gatherings, to continue building on those connections.\nIf you require an accommodation due to travel limitations or other reasons, please inform your recruiter during the hiring process. We are committed to supporting candidates who may need alternative arrangements\nMassachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.\nGermany Applicants: (m/f/d) - link to HubSpot's Career Diversity page here.\nIndia Applicants: link to HubSpot India's equal opportunity policy here.\nAbout HubSpot\nHubSpot (NYSE: HUBS) is an AI-powered customer platform with all the software, integrations, and resources customers need to connect marketing, sales, and service. HubSpot's connected platform enables businesses to grow faster by focusing on what matters most: customers.\nAt HubSpot, bold is our baseline. Our employees around the globe move fast, stay customer-obsessed, and win together. Our culture is grounded in four commitments: Solve for the Customer, Be Bold, Learn Fast, Align, Adapt & Go!, and Deliver with HEART. These commitments shape how we work, lead, and grow.\nWe're building a company where people can do their best work. We focus on brilliant work, not badge swipes. By combining clarity, ownership, and trust, we create space for big thinking and meaningful progress. And we know that when our employees grow, our customers do too.\nRecognized globally for our award-winning culture by Comparably, Glassdoor, Fortune, and more, HubSpot is headquartered in Cambridge, MA, with employees and offices around the world.\nExplore more:\nHubSpot Careers\nLife at HubSpot on Instagram\nHubSpot may use AI to help screen or assess candidates, but all hiring decisions are always human. More information can be found here. By submitting your application, you agree that HubSpot may collect your personal data for recruiting, global organization planning, and related purposes. We may use CLEAR ID Verification during the hiring process to confirm your identity and help maintain a safe, secure, and trusted experience for all candidates. Refer to HubSpot's Recruiting Privacy Notice for details on data processing and your rights.","company":"Hubspot","rawCompany":"hubspot","city":"Somerville","state":"MA","isRemote":false,"isActive":false,"createdAt":"2026-08-12T13:27:57.172Z","occupations":[{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"11-3013.01","title":"Security Managers","slug":"security-managers"}],"industries":[{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Principal Technical Program Manager, Security","description":"POS- 29555\nAbout You:\nYou're a highly technical, execution-driven program leader who thrives working alongside security engineers and product leaders to ship meaningful security improvements at scale. You bring structure to complex, fast-moving initiatives without slowing them down, and you earn trust with engineers and senior leaders alike by understanding the work deeply enough to drive it forward. You shape platform direction, influence executive decisions, and connect security program outcomes to long-term business impact. You're comfortable operating autonomously in ambiguous environments, know how to navigate organizational complexity, and use AI as a genuine force multiplier in your daily work.\nAbout Us:\nThe HubSpot Security team is dedicated to helping businesses grow better by safeguarding the systems and data that power our global CRM platform. With more than 125,000 customers in over 100 countries, HubSpot's security posture is essential to our mission and a competitive differentiator.\nAs part of the Security Governance and Risk team, you'll:\nPartner closely with security engineering teams to drive the Security Product Line's highest-priority initiatives from planning through delivery.\nOperate at the intersection of security, engineering, and governance, keeping complex multi-team programs moving and unblocking what needs to get done.\nShape how the Security Governance group operates at scale, building the operating rhythms, frameworks, and tooling that let security teams do their best work.\nJoin a culture that values transparency, learning, and authenticity.\nIn this role you will…\nSecurity Engineering Partnership (Core Focus)\nServe as an embedded TPM for security engineering teams, owning program execution for the Security Product Line's most complex and strategically important initiatives.\nDrive end-to-end delivery of large-scale security programs spanning detection and response, identity and access, infrastructure security, application security, and more.\nPartner with security engineering leads and product managers to define roadmaps, sequence work, manage dependencies to keep initiatives on track.\nNavigate ambiguity and organizational complexity independently, escalating the right things to the right people and clearing blockers before they become delays.Champion scalable processes and durable systems within the security organization, raising the operational bar across the product line.\nOwn portfolio-level KPIs, building reporting that connects program delivery to customer, reliability, and business outcomes.\nServe as a thought leader within the TPM function, sharing strategies,approaches, and AI enabled workflows that elevate how the whole team works.\nSOX Compliance for UBB (Near-Term Priority)\nIn the near term, this role will focus on supporting SOX compliance for HubSpot's Usage-Based Billing features. The goal is to build a streamlined, repeatable process for bringing UBB features into SOX compliance, at which point this role hands off to a more sustainable operating model and shifts fully into security engineering TPM support.\nPartner with FinTech and FinOps program management to coordinate SOX compliance work across Engineering, Finance, and Security, keeping the program moving and stakeholders aligned.\nDrive implementation of SOX-compliant technical controls, partnering closely with engineering teams to sequence the work, remove blockers, and get features across the line.\nEnsure UBB features are integrated into the right SOX control frameworks and that engineering teams understand compliance requirements well enough to build compliantly from the start.\nBuild a repeatable, scalable playbook so new UBB features can be evaluated, instrumented, and brought into SOX compliance without starting from scratch each time.\nAI-Powered Execution\nActively use AI tools (e.g., Claude, ChatGPT, or similar) to accelerate program planning, documentation, risk analysis, and stakeholder communications.\nModel AI-fluent working habits for the team, sharing workflows and prompting strategies that multiply output quality and speed.\nIdentify where AI materially changes how security engineering programs are planned, executed, or measured, and translate those opportunities into program strategy and investment priorities.\n\nWe are looking for people who have…\n12+ years of technical program management experience, with a significant portion embedded with security or software engineering teams in a SaaS or cloud environment.\nDeep enough technical fluency to earn credibility with security engineers, understand the work, and ask the right questions without needing to be a practitioner.\nExperience partnering with senior security engineering leaders to shape platform direction, technical standards, and execution guardrails, and the ability to connect security program outcomes to long-term business leverage and security risk.\nHands-on experience leading security programs across domains such as detection and response, identity and access management, infrastructure security, application security, and more.\nThe ability to build durable operating systems: program structures, escalation paths, reporting cadences, and tooling that outlast individual initiatives.\nFamiliarity with compliance security frameworks and standards such as SOX, ISO 27001, NIST, SOC 2, or MITRE ATT&CK sufficient to navigate security conversations and program requirements.\nDemonstrated AI fluency, with a habit of using AI tools to improve the quality, speed, and consistency of program management work. You don't just know these tools exist; you use them daily and have strong opinions on how they fit into a TPM's workflow.\nExperience as a force multiplier for a TPM team, including developing methodologies, mentoring peers, and raising the bar on program quality.\nExcellent written and verbal communication skills, with the ability to translate complex technical and operational topics for diverse audiences.\n\nNice to have:\nHands-on experience working with security engineering teams on major platform or infrastructure security initiatives.\nFamiliarity with SaaS architecture and cloud infrastructure (AWS/GCP) at a depth that helps you understand security engineering trade-offs.\nCertification(s) such as PMP, CISM, CISSP, or CISA.\nPrior experience with Usage-Based Billing or revenue recognition controls in a SaaS context.\nHands-on experience with Asana, GitHub, or similar tools to manage large-scale security programs.\nExperience integrating AI tools into security or engineering workflows, such as using LLMs for documentation, risk summarization, or program reporting.\nWe know the confidence gap and impostor syndrome can get in the way of meeting spectacular candidates, so please don't hesitate to apply — we'd love to hear from you.\nIf you need accommodations or assistance due to a disability, please reach out to us using this form.\nAt HubSpot, we value both flexibility and connection. Whether you're a Remote employee or work from the Office, we want you to start your journey here by building strong connections with your team and peers. If you are joining our Engineering team, you will be required to attend a regional HubSpot office for in-person onboarding. If you join our broader Product team, you'll also attend other in-person events, such as your Product Group Summit and other gatherings, to continue building on those connections.\nIf you require an accommodation due to travel limitations or other reasons, please inform your recruiter during the hiring process. We are committed to supporting candidates who may need alternative arrangements\nMassachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.\nGermany Applicants: (m/f/d) - link to HubSpot's Career Diversity page here.\nIndia Applicants: link to HubSpot India's equal opportunity policy here.\nAbout HubSpot\nHubSpot (NYSE: HUBS) is an AI-powered customer platform with all the software, integrations, and resources customers need to connect marketing, sales, and service. HubSpot's connected platform enables businesses to grow faster by focusing on what matters most: customers.\nAt HubSpot, bold is our baseline. Our employees around the globe move fast, stay customer-obsessed, and win together. Our culture is grounded in four commitments: Solve for the Customer, Be Bold, Learn Fast, Align, Adapt & Go!, and Deliver with HEART. These commitments shape how we work, lead, and grow.\nWe're building a company where people can do their best work. We focus on brilliant work, not badge swipes. By combining clarity, ownership, and trust, we create space for big thinking and meaningful progress. And we know that when our employees grow, our customers do too.\nRecognized globally for our award-winning culture by Comparably, Glassdoor, Fortune, and more, HubSpot is headquartered in Cambridge, MA, with employees and offices around the world.\nExplore more:\nHubSpot Careers\nLife at HubSpot on Instagram\nHubSpot may use AI to help screen or assess candidates, but all hiring decisions are always human. More information can be found here. By submitting your application, you agree that HubSpot may collect your personal data for recruiting, global organization planning, and related purposes. We may use CLEAR ID Verification during the hiring process to confirm your identity and help maintain a safe, secure, and trusted experience for all candidates. Refer to HubSpot's Recruiting Privacy Notice for details on data processing and your rights.","datePosted":"2026-08-12T13:27:57.172Z","dateModified":"2026-08-12T13:27:57.172Z","hiringOrganization":{"@type":"Organization","name":"Hubspot","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Somerville","addressRegion":"MA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"aaefc9695dd349fedbe42c0a"},"url":"https://jobsearcher.com/jobs/aaefc9695dd349fedbe42c0a"}}