Principal Technical Program Manager, Security
POS- 29555
About You:
You’re a highly technical, execution-driven program leader who thrives working alongside security engineers and product leaders to ship meaningful security improvements at scale. You bring structure to complex, fast-moving initiatives without slowing them down, and you earn trust with engineers and senior leaders alike by understanding the work deeply enough to drive it forward. You shape platform direction, influence executive decisions, and connect security program outcomes to long-term business impact. You’re comfortable operating autonomously in ambiguous environments, know how to navigate organizational complexity, and use AI as a genuine force multiplier in your daily work.
About Us:
The HubSpot Security team is dedicated to helping businesses grow better by safeguarding the systems and data that power our global CRM platform. With more than 125,000 customers in over 100 countries, HubSpot’s security posture is essential to our mission and a competitive differentiator.
As part of the Security Governance and Risk team, you’ll:
Partner closely with security engineering teams to drive the Security Product Line’s highest-priority initiatives from planning through delivery.
Operate at the intersection of security, engineering, and governance, keeping complex multi-team programs moving and unblocking what needs to get done.
Shape how the Security Governance group operates at scale, building the operating rhythms, frameworks, and tooling that let security teams do their best work.
Join a culture that values transparency, learning, and authenticity.
In this role you will…
Security Engineering Partnership (Core Focus)
Serve as an embedded TPM for security engineering teams, owning program execution for the Security Product Line’s most complex and strategically important initiatives.
Drive end-to-end delivery of large-scale security programs spanning detection and response, identity and access, infrastructure security, application security, and more.
Partner with security engineering leads and product managers to define roadmaps, sequence work, manage dependencies to keep initiatives on track.
Navigate ambiguity and organizational complexity independently, escalating the right things to the right people and clearing blockers before they become delays.Champion scalable processes and durable systems within the security organization, raising the operational bar across the product line.
Own portfolio-level KPIs, building reporting that connects program delivery to customer, reliability, and business outcomes.
Serve as a thought leader within the TPM function, sharing strategies,approaches, and AI enabled workflows that elevate how the whole team works.
SOX Compliance for UBB (Near-Term Priority)
In the near term, this role will focus on supporting SOX compliance for HubSpot’s Usage-Based Billing features. The goal is to build a streamlined, repeatable process for bringing UBB features into SOX compliance, at which point this role hands off to a more sustainable operating model and shifts fully into security engineering TPM support.
Partner with FinTech and FinOps program management to coordinate SOX compliance work across Engineering, Finance, and Security, keeping the program moving and stakeholders aligned.
Drive implementation of SOX-compliant technical controls, partnering closely with engineering teams to sequence the work, remove blockers, and get features across the line.
Ensure UBB features are integrated into the right SOX control frameworks and that engineering teams understand compliance requirements well enough to build compliantly from the start.
Build a repeatable, scalable playbook so new UBB features can be evaluated, instrumented, and brought into SOX compliance without starting from scratch each time.
AI-Powered Execution
Actively use AI tools (e.g., Claude, ChatGPT, or similar) to accelerate program planning, documentation, risk analysis, and stakeholder communications.
Model AI-fluent working habits for the team, sharing workflows and prompting strategies that multiply output quality and speed.
Identify where AI materially changes how security engineering programs are planned, executed, or measured, and translate those opportunities into program strategy and investment priorities.
We are looking for people who have…
12+ years of technical program management experience, with a significant portion embedded with security or software engineering teams in a SaaS or cloud environment.
Deep enough technical fluency to earn credibility with security engineers, understand the work, and ask the right questions without needing to be a practitioner.
Experience partnering with senior security engineering leaders to shape platform direction, technical standards, and execution guardrails, and the ability to connect security program outcomes to long-term business leverage and security risk.
Hands-on experience leading security programs across domains such as detection and response, identity and access management, infrastructure security, application security, and more.
The ability to build durable operating systems: program structures, escalation paths, reporting cadences, and tooling that outlast individual initiatives.
Familiarity with compliance security frameworks and standards such as SOX, ISO 27001, NIST, SOC 2, or MITRE ATT&CK sufficient to navigate security conversations and program requirements.
Demonstrated AI fluency, with a habit of using AI tools to improve the quality, speed, and consistency of program management work. You don’t just know these tools exist; you use them daily and have strong opinions on how they fit into a TPM’s workflow.
Experience as a force multiplier for a TPM team, including developing methodologies, mentoring peers, and raising the bar on program quality.
Excellent written and verbal communication skills, with the ability to translate complex technical and operational topics for diverse audiences.
Nice to have:
Hands-on experience working with security engineering teams on major platform or infrastructure security initiatives.
Familiarity with SaaS architecture and cloud infrastructure (AWS/GCP) at a depth that helps you understand security engineering trade-offs.
Certification(s) such as PMP, CISM, CISSP, or CISA.
Prior experience with Usage-Based Billing or revenue recognition controls in a SaaS context.
Hands-on experience with Asana, GitHub, or similar tools to manage large-scale security programs.
Experience integrating AI tools into security or engineering workflows, such as using LLMs for documentation, risk summarization, or program reporting.
Pay & Benefits
The cash compensation below includes base salary, on-target commission for employees in eligible roles, and annual bonus targets under HubSpot’s bonus plan for eligible roles. In addition to cash compensation, some roles are eligible to participate in HubSpot’s equity plan to receive restricted stock units (RSUs). Some roles may also be eligible for overtime pay. Individual compensation packages are tailored to your skills, experience, qualifications, and other job-related reasons.
This resource will help guide how we recommend thinking about the range you see. Learn more about HubSpot’s compensation philosophy.
Benefits are also an important piece of your total compensation package. Explore the benefits and perks HubSpot offers to help employees grow better.
At HubSpot, fair compensation practices aren’t just about checking off the box for legal compliance. It’s about living out our value of transparency with our employees, candidates, and community.
Annual Cash Compensation Range:
$172,700—$246,700 USD