> Markdown version of [/jobs/ext/1180445-security-technical-program-manager](https://www.wearedevelopers.com/jobs/ext/1180445-security-technical-program-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Technical Program Manager - **Company:** Asana - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $194,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Asana, Software Security - **Published:** July 4, 2026 - **Apply:** https://asana.com/jobs/apply/7959069 ## About the Role Skills & expertise Continuous improvement Communication skills, * Demonstrated ability to lead large-scale, cross-functional programs from ambiguous inception through delivery * Track record of operating with high autonomy - you create the structure rather than waiting for it * Strong understanding of security with the ability to engage technical teams and communicate clearly to executive stakeholders * Exceptional written and verbal communication, with proven ability to influence without authority at all levels * 8+ years of TPM experience, with meaningful time in a security context (security engineering, GRC, product security, infra security, or similar) * At Asana, we're committed to building teams that include a variety of backgrounds, perspectives, and skills, as this is critical to helping us achieve our mission. If you're interested in this role and don't meet every listed requirement, we still encourage you to apply ## Description * At Asana, security is foundational to our mission of helping teams work together effortlessly * Our Security organization protects Asana's employees, users, and customers by proactively addressing threats, enabling secure product development, and embedding security into the fabric of how we operate * We partner closely with Engineering, Product, IT, Legal, and Compliance to build and maintain trust at scale * As a Security Technical Program Manager, you'll be the connective tissue across the entire Security organization, driving the strategy, programs, and operational rhythms that make the team highly effective and externally visible * This is a high-impact, high-autonomy role * You'll define how Security as a function operates: how it plans, how it measures itself, how it communicates progress, and how it executes on its biggest bets * You won't just run programs, you'll shape the operating model that makes all programs run better * Lead high-impact, cross-functional special projects that span organizational boundaries, from standing up new security capabilities and maturity programs to company-wide strategic initiatives * Own the Security organization's annual and quarterly planning cycles, translating multi-year security strategy into a prioritized, executable roadmap * Drive the prioritization and communication of security asks across stakeholders, building a unified framework that influences how partner teams plan and prioritize security work * Define and own the Security team's KPI framework, covering risk posture, program health, and strategic goal progress * Build dashboards and reporting cadences that give leadership real-time visibility into what's working, what's at risk, and where decisions are needed * Establish and continuously improve the operating cadences (All Hands meetings, program reviews, OKR check-ins) that keep the organization aligned and moving fast * Act as a thought partner to security leadership on org design, process improvement, and operational scale ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [A Founder's Journey : From Startup Chaos to Purposeful Growth](https://www.wearedevelopers.com/videos/1926-a-founder-s-journey-from-startup-chaos-to-purposeful-growth) - [Building Security Champions](https://www.wearedevelopers.com/videos/193-building-security-champions) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Should Tech Managers Be Developers First? Pros and Cons](https://www.wearedevelopers.com/magazine/327-should-tech-managers-be-developers-first-pros-and-cons) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026)