Staff TPM, Security
ABOUT THE ROLE
We're looking for a Staff or Senior Staff Technical Program Manager to build the program foundation for Suno's Security organization. Security is scaling its team, processes, technology, and programs all at once, and today there's no dedicated program function to hold that work together. You'll own the cross-functional structure that turns security priorities into programs that run and get finished. You'll start with Vulnerability Management and Security by Design, and you'll also help our IT organization set up operational structures it can own and run on its own. You'll partner closely with Engineering, Research, and Legal, and as the work grows, you'll have the chance to build a team around it.
WHAT YOU'LL DO
- Drive Suno's Vulnerability Management program end-to-end, covering intake, prioritization, remediation tracking, and verified closure with Engineering.
- Stand up Safety and Security by Design as a repeatable program, with clear processes, checklists, launch gates, and accountability across teams.
- Own Security's roadmap and planning artifacts, turning risk priorities into tracked plans with clear owners and milestones.
- Track incident response follow-ups and post-incident corrective actions until they're verified as resolved.
- Build audit-readiness tracking that maps requirements to owners and evidence across teams.
- Serve as the connective tissue between Security and Engineering, Research, and Legal. You'll surface blockers, sequence dependencies, and drive programs to completion.
- Partner with IT to set up processes, tracking systems, and operating cadences that IT then owns and runs independently.
- Help make security part of how Suno builds every new model and feature, in service of making creative fulfillment a daily reality for everyone.
WHAT YOU'LL NEED
MUST-HAVES
- 10+ years of technical program management experience, including significant time running security, infrastructure, or platform programs in a fast-growing engineering organization.
- A track record of building programs from scratch, such as vulnerability management, secure development lifecycle, or launch review, and making them durable and repeatable.
- Enough technical depth to engage credibly with security and software engineers on vulnerabilities, remediation trade-offs, and system dependencies, plus the influence skills to drive outcomes across teams you don't manage.
NICE-TO-HAVES
- Experience supporting security compliance or audit programs (e.g. SOC 2, ISO 27001) from the program side.
- Experience setting up IT operational processes, tooling, or service management practices.
- Prior experience as the first or founding TPM in a security organization, or interest in growing into a program management leadership role as the team scales.