> Markdown version of [/jobs/ext/2298957-senior-technical-program-manager-security-infrastructure](https://www.wearedevelopers.com/jobs/ext/2298957-senior-technical-program-manager-security-infrastructure). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Technical Program Manager, Security & Infrastructure - **Company:** True Anomaly - **Location:** Denver, CO, United States - **Experience:** Expert - **Salary:** $140,000.0 - $210,000.0 - **Contract:** Permanent contract - **Skills:** Confluence, JIRA, SARS Software Products, Atlassian Tools, National Industrial Security Program Operating Manual (NISPOM) - **Published:** August 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9126530/senior-technical-program-manager-security-infrastructure ## About the Role * 8+ years of technical program or project management, with a meaningful portion in a federal, defense, or otherwise regulated environment, and a demonstrated track record of owning complex programs end-to-end at a senior level. * Core TPM craft, demonstrated at scale: structured intake and prioritization, dependency and critical-path management, schedule and risk management, and driving programs to closure across multiple concurrent efforts. This is first and foremost a program management role; domain fluency supports it, but does not substitute for it. * Technical judgment in a security context: enough fluency in federal authorization and security engineering to read the substance of the work, tell a real blocker from a soft one, and pressure-test estimates rather than taking them at face value. You won't author the technical content, but you must reason about it credibly. * Stakeholder and communication discipline: running a reliable status/risk/milestone cadence and tailoring it for audiences from engineers to executive leadership (and, where relevant, customers). * Experience owning delivery for teams you don't manage, where your leverage is cadence, visibility, and escalation rather than reporting lines. * Fluency with Atlassian tooling (Jira/Confluence) for program tracking and documentation. * Comfort operating in a matrixed structure: applying a defined program/portfolio methodology while taking day-to-day priorities from an embedded team. * U.S. citizenship and eligibility to obtain and hold a U.S. security clearance., * Direct experience with higher DoD Impact Levels (IL4/IL5, and IL6 where classified), DISA STIGs, and/or FedRAMP (Moderate+). * Exposure to industrial security (NISPOM/INDSEC) requirements and DCSA processes, and familiarity with operational security disciplines (OPSEC, PERSEC, COMSEC) in a cleared environment. * Demonstrated ability to drive an ATO or equivalent federal authorization effort to completion, in coordination with the responsible security officers. * Background in space systems, aerospace, or defense hardware/software delivery. * Experience standing up or maturing program/PMO processes, not just running existing ones. ## Description We're hiring a Senior Technical Program Manager to drive the GOVSEC/INDSEC portfolio: the programs, authorization efforts, and cross-functional execution that keep TA's regulated workloads compliant and mission-ready. This is a senior, hands-on execution role for someone who can operate independently across a broad portfolio and hold operationally busy teams to realistic commitments. It's also a matrixed role. It reports into the CISO organization's technical program management function, which sets your program methodology and portfolio standards, and is embedded within the GOVSEC/INDSEC team, which drives your day-to-day work intake and priorities. Within GOVSEC/INDSEC, you'll partner primarily with its Director for program priorities and execution, coordinate day-to-day with the team's Manager and personnel, and interface directly with the VP on portfolio status, risk, and key trade-off decisions. You'll also partner closely with cybersecurity engineering, GRC, IT program leadership as well as cross-functionally across program delivery teams. Comfort operating credibly across all levels, driving detail with managers and engineers, and communicating crisply with executive leadership is essential. What You'll Own * End-to-end program management for GOVSEC/INDSEC initiatives, from intake through delivery, using Jira and Confluence for tracking and documentation. * Driving schedule and delivery for ATO/RMF efforts owned by the responsible security officers (ISSM/ISSOs). You track artifact production (SSPs, POA&Ms, SARs), surface blockers, and keep control implementation and remediation on timeline. You keep the effort moving; the security officers own the technical authorization content. * Cross-functional coordination across security engineering, GRC, IT, and program/mission teams to unblock compliance-gating work. * Execution rigor across GOVSEC/INDSEC's operational security disciplines (OPSEC, PERSEC, and COMSEC programs), bringing cadence, tracking, and accountability to recurring and milestone-driven work these teams own and execute. * Cadence and reporting: status, risk, and milestone communication calibrated for both engineering teams and executive/customer stakeholders. * Capacity and roadmap planning for the GOVSEC portfolio, making trade-offs explicit and distinguishing committed work from aspirational. * Capacity stewardship across the portfolio: maintaining a clear picture of team capacity against both planned project work and ongoing operational efforts, surfacing contention early, and enforcing the discipline that keeps commitments realistic. When planned and operational demands collide, you make the trade-off visible and drive it to an explicit decision by leadership rather than letting capacity be silently over-committed. ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [42 x 2 Canvases Later: Two Years, Two Minds, Many Lessons](https://www.wearedevelopers.com/videos/1458-42-x-2-canvases-later-two-years-two-minds-many-lessons) - [The Future of Developer Experience with GenAI: Driving Engineering Excellence](https://www.wearedevelopers.com/videos/1107-the-future-of-developer-experience-with-genai-driving-engineering-excellence) - [A Founder's Journey : From Startup Chaos to Purposeful Growth](https://www.wearedevelopers.com/videos/1926-a-founder-s-journey-from-startup-chaos-to-purposeful-growth) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Should Tech Managers Be Developers First? Pros and Cons](https://www.wearedevelopers.com/magazine/327-should-tech-managers-be-developers-first-pros-and-cons) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [From developer to manager – what does it take to become an engineering manager?](https://www.wearedevelopers.com/magazine/42-from-developer-to-manager-what-does-it-take-to-become-an-engineering-manager)