Source description
About the role
Operating Standard Enforcement: Apply a single operating standard across every security project. Drive project hygiene at scale: ownership, dates, scope, plans, status. Review and act on AI-generated drafts that flag gaps, propose fixes and surface stale work to project owners.
Intake and Triage: Own the front door for security requests across Slack channels, ticket forms and direct asks. Classify, route, set expectations with requestors and capture demand as data. Train the AI classification system through your corrections and feedback.
Status and Reporting: Produce per-person, per-project and program-level status briefs and the reports the security org commits to (weekly operating reviews, monthly engineering-relevant metrics, quarterly roadmap progress). Edit AI-drafted reports for narrative, framing and the relationship context the data does not capture.
Capacity and Commitment: Maintain a working model of team capacity and project commitments. Flag slippage early. Surface overcommitment to leadership before dates slip. Apply judgment for factors the data does not see (team morale, growth needs, strategic context).
Interruption Work Tracking: Inventory and measure the categories of interruption work the team handles (elevation requests, threat model processing, team requests, secret rotations, vulnerability alerts and others). Propose new projects to reduce unplanned work and improve processing efficiency.
Prioritization: Place new work in the priority queue using stated criteria of impact, urgency, dependencies and capacity. Apply judgment for political and strategic context.
AI System Partnership: Work directly with the AI engineering function as an internal customer. File feature requests, validate output quality, define what good looks like and shape the system over time. You are the product owner for the program management capability that supports your work.
Operating Standard Evolution : Refine the operating standard as edge cases surface. Propose updates, build team buy-in and roll out changes consistently.
Cross-Company Representation: Represent the security organization's program management practice to peers, stakeholders, and leadership across the company. Ensure all program reporting provides an accurate, transparent, and objective view of current progress and risks.
More at JumpCloud
