We're hiring a Senior Security Program Manager to run security and compliance as a program at TinyFish. You'll own the operational backbone — Vanta, audits, vulnerability SLAs, policy lifecycle, vendor risk, customer security reviews — so our Security Lead can stay focused on architecture and threat work, and security requirements run smoothly across our enterprise deals. This is an IC role reporting to the Staff Program Manager, working closely with our Security Lead. You'll be the first hire whose full-time job is running the program rather than building the controls. About TinyFish TinyFish builds browser-based AI agents that do real work on the open web for enterprise customers. We're a small, technical team shipping fast against serious enterprise buyers who ask serious security questions. We're mid-flight on ISO 27001 certification renewal (Schellman external, Alameda internal) and our security posture is moving from "small startup" to "we can answer a 400-line questionnaire without flinching." Why this role, why now Today our Security Lead is doing two jobs — designing the controls and running the program that proves they work. That worked at our previous scale but doesn't scale to the next one, and it leaves architecture and threat work under-invested. You'll take the program side so he can take the design side. You'll also be the representative of TinyFish when an enterprise customer has questions about our security program.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior
Education Level
No Education Listed