Information Security - Sr Security Program Manager

ACV AuctionsBuffalo, NY
74d$155,000 - $195,000

About The Position

We're hiring a senior Sr Security Program Manager to contribute to and mature an integrated security program that spans Product Security (AppSec / SSDLC), Security Operations (SecOps/IR/cloud security), Technical GRC, and Enterprise Applications and Identity. This is a high-visibility, cross-functional, strategic role. You will own program outcomes, influence product and engineering roadmaps, and be the 'translator' between security, risk, leadership, and the business teams who rely on ACV's marketplace every day. ACV's scale and data scope (including sensitive vehicle, dealer data, identity, and payment information) mean your work will meaningfully reduce enterprise risk and enable secure growth. You will be a trusted member and critical voice of the security leadership team, reporting directly to the CISO.

Requirements

  • 8+ years experience building and operating security programs in SaaS / marketplace / fintech / large data platforms.
  • Demonstrable ownership across AppSec, SecOps, and Corporate Security domains.
  • Experience optimizing and helping vulnerability management and incident response programs mature with measurable SLAs (MTTR, remediation windows).
  • Track record of influencing engineering/product leadership and delivering security as a business enabler (not a blocker).
  • Strong program management skills: roadmap creation, cross-functional timelines, budget stewardship, vendor selection and contract negotiation.
  • Excellent written + verbal communication; experience preparing executive risk briefings and board-level security summaries.
  • Bachelor's degree in CS, Engineering, Information Security, or commensurate experience (5+ years) working in a similar role.

Nice To Haves

  • Prior experience at marketplaces or in automotive/transportation/finance verticals.
  • Familiarity with data products, vehicle inspection pipelines, or payment flows is a plus.
  • Experience with SOC 2 readiness, ISO 27001, PCI scope reduction, or public company compliance programs.
  • Background in privacy program integration, especially where product telemetry/geolocation, vehicle data, and identity data are in scope.

Responsibilities

  • Work with stakeholders to create a unified security program roadmap covering Product Security, SecOps, and Enterprise Security.
  • Translate risk appetite into prioritized initiatives, funding opportunities, and measurable outcomes.
  • Define and publish security KPIs/OKRs as dashboards to various internal audiences.
  • Use data to support visibility and continuous improvement.
  • Work with security teammates to collectively drive programs partnering with Product, Engineering, and DevOps to embed AppSec into the SSDLC.
  • Partner with Operational leads to drive maturity through the creation of requirement frameworks including documented procedures, incident response playbooks, and runbooks.
  • Collaborate with Legal, Privacy, and GRC teams to ensure enterprise controls align with SOC 2 and other industry standard framework requirements.
  • Partner directly with the CISO to ensure top initiatives are well-planned, resourced, and delivered.
  • Anticipate needs, remove roadblocks, and help drive critical decision-making.
  • Identify gaps, improve processes, and support the development of scalable frameworks.
  • Drive cybersecurity initiatives from planning through delivery-ensuring on-time execution, resource alignment, stakeholder engagement, and clear reporting.
  • Help run team meetings, leadership offsites, and special projects that support team health, accountability, and long-term success.

Benefits

  • Compensation: $155,000.00 - $195,000.00 annually.
  • Final compensation will be determined based upon the applicant's relevant experience, skillset, location, business needs, market demands, and other factors as permitted by law.

Stand Out From the Crowd

Upload your resume and get instant feedback on how well it matches this job.

Upload and Match Resume

What This Job Offers

Job Type

Full-time

Career Level

Senior

Industry

Broadcasting and Content Providers

Education Level

Bachelor's degree

Number of Employees

1,001-5,000 employees

© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service