A hands-on Security Technical Program Manager who can drive SaaS security posture work, coordinate stakeholders, push through backlog items, and keep engineering + IT aligned. Needs strong SSPM experience (Obsidian preferred) and comfort running technical programs.
TOP MUST-HAVES
- Security TPM or Program Manager with SaaS Security Posture Management (SSPM) experience
- Experience with Obsidian or another SSPM platform
- Strong cross-functional coordination (IT, engineering, security)
- Ability to run security projects end-to-end
- Strong documentation, follow-up, and communication skills
- Bonus: OAuth token automation or identity lifecycle exposure
DAY-TO-DAY RESPONSIBILITIES
1. SaaS Security Posture (Main Focus)
- Drive integration of SaaS apps into Obsidian
- Push backlog reduction and track metrics
- Coordinate stakeholders + follow-ups
- Support development of detection packages for new SaaS apps
- Build processes, procedures, and governance frameworks
2. Drift Security Incident Action Items
- Track the remediation work
- Ensure teams close security findings
- Document lessons learned
3. OAuth Token Automation Research
- Recommend approaches for automated token deactivation
- Identify signals that should trigger revocation
4. General Enterprise Security Support
- Help with various security coordination tasks as they arise
SUCCESS LOOKS LIKE
- SaaS apps onboarded into Obsidian
- Drift incident items closed
- Clear automation recommendations delivered
- Processes + documentation built