HCM - Senior Security Program Manager

TinyFishLos Altos, CA

About The Position

We're hiring a Senior Security Program Manager to run security and compliance as a program at TinyFish. You'll own the operational backbone — Vanta, audits, vulnerability SLAs, policy lifecycle, vendor risk, customer security reviews — so our Security Lead can stay focused on architecture and threat work, and security requirements run smoothly across our enterprise deals. This is an IC role reporting to the Staff Program Manager, working closely with our Security Lead. You'll be the first hire whose full-time job is running the program rather than building the controls. About TinyFish TinyFish builds browser-based AI agents that do real work on the open web for enterprise customers. We're a small, technical team shipping fast against serious enterprise buyers who ask serious security questions. We're mid-flight on ISO 27001 certification renewal (Schellman external, Alameda internal) and our security posture is moving from "small startup" to "we can answer a 400-line questionnaire without flinching." Why this role, why now Today our Security Lead is doing two jobs — designing the controls and running the program that proves they work. That worked at our previous scale but doesn't scale to the next one, and it leaves architecture and threat work under-invested. You'll take the program side so he can take the design side. You'll also be the representative of TinyFish when an enterprise customer has questions about our security program.

Requirements

  • 4-7 years in security or GRC program management, ideally at a B2B SaaS company that grew through early stages.
  • Lived experience running and owning ISO 27001 and SOC 2 audits end-to-end, including auditor management.
  • Deep fluency in Vanta (or Drata/Tugboat with willingness to switch).
  • Comfortable in front of customer security teams to both represent the capabilities of our security program as well as instill confidence in the team.
  • Strong written communication.
  • Good judgment on when a control gap is a real risk vs. a paperwork issue, and the ability to escalate issues quickly to the right audiences.

Nice To Haves

  • AI/ML security experience, especially model providers, prompt injection, data handling in agentic systems.
  • Prior work at a company with a browser-based product (extensions, agents, scraping at scale).
  • Experience standing up an additional framework (HIPAA, FedRAMP, ISO 27017/27018, C5).
  • Background in pen-test coordination or bug bounty program management.

Responsibilities

  • Maintain ISO 27001 certification, prep for SOC 2 Type 1 and 2, manage auditor relationships, own evidence collection in Vanta.
  • Own the SLA layer for vulnerability management — weekly dashboard, breach escalation, exception tracking, monthly view to leadership.
  • Manage the policy lifecycle: annual reviews, new policies as scope expands, training rollout, attestation tracking, exception requests.
  • Own people-ops security controls: onboarding/offboarding evidence, access reviews, security awareness training, background-check tracking, permission-management security groups.
  • Manage vendor risk: vendor inventory, pre-procurement assessments, annual reassessments, DPA and sub-processor tracking.
  • Handle customer-facing security: security questionnaires, CAIQs, custom RFPs, customer security calls. You're the named SPM in our trust center.
  • Own the update cadence and the cross-functional process for Product Terms of Service and Privacy Policy when product changes trigger policy revisions.
  • Own risk and incident program: maintain the risk register, run quarterly reviews, own the incident runbook artifact, schedule and run tabletops.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service