368,530open jobs
9,432companies
50,439added this week
Browse all
Salary
$138k – $156k per year
Location
In office (Denver)
Employment
Internship
Overview
Company
Impact
Profile match
Gusto is a SaaS company that builds software to help businesses run core people operations, particularly payroll, benefits, and HR administration. Its products are designed to reduce the time and risk involved in paying employees, managing tax filings and compliance tasks, and handling the ongoing paperwork that comes with hiring and supporting a team. For job seekers, the focus is on practical, high‑stakes workflows where accuracy, security, and reliability matter, because customers depend on the platform to pay people correctly and on time.

About Gusto

At Gusto, we're on a mission to grow the small business economy. We handle the hard stuff - payroll, health insurance, 401(k)s, and HR - so owners can focus on their craft and their customers. With teams in Denver, San Francisco, and New York, we support more than 500,000 small businesses nationwide and are building a workplace that reflects the people we serve.

All full-time employees receive competitive base pay, benefits, and equity (RSUs) - because everyone who helps build Gusto should share in its success. Offer amounts are determined by role, level, and location. Learn more about ourTotal Rewards philosophy.

AI is a fundamental part of how work gets done at Gusto. We expect all team members to actively engage with AI tools relevant to their role and grow their fluency as the technology evolves. AI experience requirements vary by role and will be assessed during the interview process.

About the Role:

Gusto is becoming an AI-native company, and that only works if our security posture keeps pace. As the Security TPM, you'll own the definition and delivery of Gusto's vulnerability management and security operations programs across Security, AIT, R&D, Infrastructure, GRC, and Risk. You'll drive the centralized vulnerability scorecard, expand detection and monitoring coverage, harden the SDLC, and stand up the security metrics leadership runs the business on. You'll drive the timelines, manage the dependencies, head off the risk, and use AI plugins to do the work itself, so security becomes something that helps Gusto move faster instead of slowing it down.

About the Team:

The TPM organization is part of our AIT, Risk, and Security team. We deliver the cross-functional work that lets Gusto securely accelerate its AI and platform modernization. The vulnerability management and security operations programs sit right at the intersection of security engineering, infrastructure, and GRC, and they're foundational to how Gusto scales its AI ambitions safely. This is one of the most strategic programs on the team, and you'll lead it across a complex, fast-moving group of stakeholders.

Here’s what you’ll do day-to-day:

Set the strategy and the roadmap

Work with leaders across Security, AIT, R&D, Infrastructure, GRC, and Risk to shape where vulnerability management and security operations go as Gusto becomes an AI-native company.Define what good vulnerability management and security operations look like for an AI-first business, and set the multi-quarter vision that gets us there.Run intake and prioritization with senior stakeholders, and make the call on what gets built first.Decide where security should clear the way for AI speed and where it needs to hold the line, and bring leaders along on the why.Put AI plugins to work to pull together stakeholder input, map dependencies, and keep the roadmap grounded in what's really happening.

Run the programs and the change

  • Lead delivery of the centralized vulnerability management program: coverage across code, cloud, data, and edge; CSPM/DSPM, container scanning, dependency and secrets detection, and owner-based remediation routing to closure.
  • Lead security operations delivery: expand high-risk detection and alerting across systems and vendors, impersonation and privileged-access logging, SIEM integration, insider-risk telemetry, and logging of agentic activity.
  • Stand up the daily security-health and vulnerability-management metrics dashboards leadership uses to run the business, and drive monthly vulnerability reporting.
  • Build security workflows that run on AI plugins by default, so coverage checks and evidence collection happen automatically instead of by hand.
  • Build the plans, manage scope and risk, track milestones, and deliver against every audit and regulatory commitment.
  • Roll out new controls, like risk-scored PR review, JIT privileged access, and secrets management, and help teams adopt them with training, comms, and runbooks that plugins keep up to date for you.
  • Keep a busy, fast-moving group of stakeholders aligned with clear, steady updates on where things stand.

Manage stakeholders and vendors

  • Hold vendors and partners to their commitments and push them toward AI-forward ways of working.
  • Stay on top of how every workstream is tracking, raise flags early, and get teams unstuck when they stall.
  • Watch the program budget, tooling spend, and implementation costs.

Here's what we're looking for:

You'll need

  • A history of taking programs from ambiguous to shipped in regulated environments.
  • 5 to 8+ years leading cross-functional TPM or delivery work, with real time spent on security, infrastructure, or platform engineering.
  • A solid handle on vulnerability management and security operations, from scanning coverage and remediation SLAs to detection engineering, SIEM/monitoring, and identity and privileged access, and a sense for how they help Gusto move faster on AI.
  • A way of working where AI plugins drive your everyday delivery, and you help the people around you work the same way.
  • The ability to speak the language of security engineering, infrastructure, GRC, and R&D, and keep everyone rowing together.

Nice to have

  • Familiarity with the modern security stack, including vulnerability and asset scanners (e.g., Wiz, Axonius), code security (dependency and secret scanning), SIEM/detection (e.g., Panther), and identity/JIT access (e.g., Opal).
  • Hands-on experience using AI clients and plugins (MCPs) to generate program artifacts and take the busywork off your plate.
  • A working knowledge of control frameworks like SOC 1/2 and ISO 27001, plus secure SDLC practices.
  • A PM certification (PMP, CAPM, Scrum, or Prosci) and time spent in high-growth fintech or another regulated, fast-paced industry.

Our cash compensation amount for this role is targeted at $138,000-156,000 in Denver, and $168,000-189,000 in the San Francisco Bay Area. Stock equity is additional. Final offer amounts are determined by multiple factors including candidate experience and expertise and may vary from the amounts listed above.

Gusto has physical office spaces in Denver, San Francisco, and New York City. Employees who are based in those locations will be expected to work from the office on designated days approximately 2-3 days per week (or more depending on role). The same office expectations apply to all Symmetry roles, Gusto's subsidiary, whose physical office is in Scottsdale.

Note: The San Francisco office expectations encompass both the San Francisco and San Jose metro areas. 

When approved to work from a location other than a Gusto office, a secure, reliable, and consistent internet connection is required. This includes non-office days for hybrid employees.

Our customers come from all walks of life and so do we. We hire great people from a wide variety of backgrounds, not just because it's the right thing to do, but because it makes our company stronger. If you share our values and our enthusiasm for small businesses, you will find a home at Gusto. 

Gusto is proud to be an equal opportunity employer. We do not discriminate in hiring or any employment decision based on race, color, religion, national origin, age, sex (including pregnancy, childbirth, or related medical conditions), marital status, ancestry, physical or mental disability, genetic information, veteran status, gender identity or expression, sexual orientation, or other applicable legally protected characteristic. Gusto considers qualified applicants with criminal histories, consistent with applicable federal, state and local law. Gusto is also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. We want to see our candidates perform to the best of their ability. If you require a medical or religious accommodation at any time throughout your candidate journey, please fill out this form and a member of our team will get in touch with you.

Gusto takes security and protection of your personal information very seriously. Please review our Fraudulent Activity Disclaimer.

Personal information collected and processed as part of your Gusto application will be subject to  Gusto's Applicant Privacy Notice.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,530 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Denver
$42k – $104k per year (Estimated) • In office • Internship • 5+ years exp
Bash
PowerShell
Python
DevOps
Amazon EC2
Amazon EKS
Ansible
AWS
AWS Lambda
Azure
CentOS Stream
Chef
CI/CD
CloudFormation
Configuration Management
Datadog
FinOps
GCP
Git
GitHub Actions
GitLab CI
Grafana
Hyper-V
Istio
Jenkins
Kubernetes
KVM
Linkerd
Platform Engineering
Prometheus
Puppet
Service Mesh
Splunk
Terraform
Ubuntu
VMWare
Windows Server
Amazon CloudWatch
Amazon ECS
Amazon S3
API Gateway
AWS Step Functions
GitHub
GitLab
IAM
Cybersecurity
GDPR
ISO 27001
SOC 2
Apply
$122k – $270k per year (Estimated) • Remote • Full-Time • 8+ years exp • Bachelor's Degree • Toronto
AI/ML
Anomaly Detection
DevOps
AIOps
Dynatrace
Incident Management
OpenTelemetry
Platform Engineering
Management
ServiceNow
Apply
$23k – $58k per year (Estimated) • In office • Full-Time • 7+ years exp • Gurgaon
Python
Databases
Apache Kafka
ElasticSearch
Redis
DevOps
Error Budget
Grafana
Incident Management
Kubernetes
OpenShift
Platform Engineering
Prometheus
Self-Healing
Cybersecurity
HashiCorp Vault
Cryptography
Vault
Apply
$23k – $57k per year (Estimated) • Remote • Full-Time • 6+ years exp
Python
Databases
OpenSearch
DevOps
AIOps
ArgoCD
AWS
Azure
CI/CD
Datadog
Docker
Dynatrace
GCP
GitHub Actions
Grafana
Incident Management
Jaeger
Jenkins
Kubernetes
New Relic
OpenTelemetry
Platform Engineering
Prometheus
SLI/SLO/SLA
Splunk
Terraform
GitHub
Apply
$105k – $252k per year • Remote • Full-Time • 18+ years exp • Bachelor's Degree
Python
Java
Java
Gradle
DevOps
Ansible
AWS
CI/CD
CloudFormation
Configuration Management
Docker
GitHub Actions
GitLab CI
Helm
Jenkins
Kubernetes
Platform Engineering
Terraform
GitHub
GitLab
Cybersecurity
Sonatype Nexus IQ
Management
Confluence
Jira
Apply
$183k – $200k per year • Equity • Remote/Hybrid • Internship • 8+ years exp • Bachelor's Degree • New York
Mobile
Modularization
Apply
$163k – $204k per year • Equity • Remote/Hybrid • Internship • 6+ years exp • Denver
Apex
Ruby
Ruby
Ruby on Rails
AI/ML
Claude
Claude Code
Marketing
Salesforce
Apply
$163k – $204k per year • Equity • Remote/Hybrid • Internship • 8+ years exp • San Francisco
Ruby
Ruby
Ruby on Rails
AI/ML
LLM
Apply
$163k – $204k per year • Equity • In office • Internship • 8+ years exp • New York
JavaScript
Ruby
Ruby
Ruby on Rails
Frontend
React.js
DevOps
Platform Engineering
Apply
$163k – $204k per year • Equity • In office • Internship • 8+ years exp
Ruby
JavaScript
Ruby
Ruby on Rails
Sidekiq
Frontend
GraphQL
React.js
Apply
$159k – $282k per year • In office • Full-Time • Bachelor's Degree • Minneapolis • Chicago • Phoenix • Raleigh • Dallas
Apply
$366k per year • Remote/Hybrid • Internship • 15+ years exp • Bachelor's Degree • Denver
AI/ML
AI Agents
Computer Vision
DevOps
AWS
Platform Engineering
Cybersecurity
GDPR
Apply
$148k – $284k per year (Estimated) • Equity • In office • 8+ years exp • Denver
AI/ML
AI Agents
Anthropic
DevOps
Incident Management
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
$94k – $294k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Portland • Milwaukee • Dallas • Columbus
Apply
See all jobs
This is one of many
368,530 more open roles from verified company boards, updated every day.