Remote Security Program Manager Jobs
Remote security program manager jobs are open across the U.S. at remote-first firms, distributed enterprise teams, and cloud-native companies scaling their security operations. Demand is active in technology, financial services, healthcare, and defense contracting, with employers like Metrea, Centene, and HubSpot hiring now. Scan the live roles below and apply to whichever ones fit.
Find JobsOverview
Showing 5 of 11+ Remote Security Program Manager jobs











POS- 29555
About You:
You're a highly technical, execution-driven program leader who thrives working alongside security engineers and product leaders to ship meaningful security improvements at scale. You bring structure to complex, fast-moving initiatives without slowing them down, and you earn trust with engineers and senior leaders alike by understanding the work deeply enough to drive it forward. You shape platform direction, influence executive decisions, and connect security program outcomes to long-term business impact. You're comfortable operating autonomously in ambiguous environments, know how to navigate organizational complexity, and use AI as a genuine force multiplier in your daily work.
About Us:
The HubSpot Security team is dedicated to helping businesses grow better by safeguarding the systems and data that power our global CRM platform. With more than 125,000 customers in over 100 countries, HubSpot's security posture is essential to our mission and a competitive differentiator.
As part of the Security Governance and Risk team, you'll:
- Partner closely with security engineering teams to drive the Security Product Line's highest-priority initiatives from planning through delivery.
- Operate at the intersection of security, engineering, and governance, keeping complex multi-team programs moving and unblocking what needs to get done.
- Shape how the Security Governance group operates at scale, building the operating rhythms, frameworks, and tooling that let security teams do their best work.
- Join a culture that values transparency, learning, and authenticity.
In this role you will…
Security Engineering Partnership (Core Focus)
- Serve as an embedded TPM for security engineering teams, owning program execution for the Security Product Line's most complex and strategically important initiatives.
- Drive end-to-end delivery of large-scale security programs spanning detection and response, identity and access, infrastructure security, application security, and more.
- Partner with security engineering leads and product managers to define roadmaps, sequence work, manage dependencies to keep initiatives on track.
- Navigate ambiguity and organizational complexity independently, escalating the right things to the right people and clearing blockers before they become delays.Champion scalable processes and durable systems within the security organization, raising the operational bar across the product line.
- Own portfolio-level KPIs, building reporting that connects program delivery to customer, reliability, and business outcomes.
- Serve as a thought leader within the TPM function, sharing strategies,approaches, and AI enabled workflows that elevate how the whole team works.
SOX Compliance for UBB (Near-Term Priority)
In the near term, this role will focus on supporting SOX compliance for HubSpot's Usage-Based Billing features. The goal is to build a streamlined, repeatable process for bringing UBB features into SOX compliance, at which point this role hands off to a more sustainable operating model and shifts fully into security engineering TPM support.
- Partner with FinTech and FinOps program management to coordinate SOX compliance work across Engineering, Finance, and Security, keeping the program moving and stakeholders aligned.
- Drive implementation of SOX-compliant technical controls, partnering closely with engineering teams to sequence the work, remove blockers, and get features across the line.
- Ensure UBB features are integrated into the right SOX control frameworks and that engineering teams understand compliance requirements well enough to build compliantly from the start.
- Build a repeatable, scalable playbook so new UBB features can be evaluated, instrumented, and brought into SOX compliance without starting from scratch each time.
AI-Powered Execution
- Actively use AI tools (e.g., Claude, ChatGPT, or similar) to accelerate program planning, documentation, risk analysis, and stakeholder communications.
- Model AI-fluent working habits for the team, sharing workflows and prompting strategies that multiply output quality and speed.
- Identify where AI materially changes how security engineering programs are planned, executed, or measured, and translate those opportunities into program strategy and investment priorities.
We are looking for people who have…
- 12+ years of technical program management experience, with a significant portion embedded with security or software engineering teams in a SaaS or cloud environment.
- Deep enough technical fluency to earn credibility with security engineers, understand the work, and ask the right questions without needing to be a practitioner.
- Experience partnering with senior security engineering leaders to shape platform direction, technical standards, and execution guardrails, and the ability to connect security program outcomes to long-term business leverage and security risk.
- Hands-on experience leading security programs across domains such as detection and response, identity and access management, infrastructure security, application security, and more.
- The ability to build durable operating systems: program structures, escalation paths, reporting cadences, and tooling that outlast individual initiatives.
- Familiarity with compliance security frameworks and standards such as SOX, ISO 27001, NIST, SOC 2, or MITRE ATT&CK sufficient to navigate security conversations and program requirements.
- Demonstrated AI fluency, with a habit of using AI tools to improve the quality, speed, and consistency of program management work. You don't just know these tools exist; you use them daily and have strong opinions on how they fit into a TPM's workflow.
- Experience as a force multiplier for a TPM team, including developing methodologies, mentoring peers, and raising the bar on program quality.
- Excellent written and verbal communication skills, with the ability to translate complex technical and operational topics for diverse audiences.
Nice to have:
- Hands-on experience working with security engineering teams on major platform or infrastructure security initiatives.
- Familiarity with SaaS architecture and cloud infrastructure (AWS/GCP) at a depth that helps you understand security engineering trade-offs.
- Certification(s) such as PMP, CISM, CISSP, or CISA.
- Prior experience with Usage-Based Billing or revenue recognition controls in a SaaS context.
- Hands-on experience with Asana, GitHub, or similar tools to manage large-scale security programs.
- Experience integrating AI tools into security or engineering workflows, such as using LLMs for documentation, risk summarization, or program reporting.
We know the confidence gap and impostor syndrome can get in the way of meeting spectacular candidates, so please don't hesitate to apply — we'd love to hear from you.
If you need accommodations or assistance due to a disability, please reach out to us using this form.
At HubSpot, we value both flexibility and connection. Whether you're a Remote employee or work from the Office, we want you to start your journey here by building strong connections with your team and peers. If you are joining our Engineering team, you will be required to attend a regional HubSpot office for in-person onboarding. If you join our broader Product team, you'll also attend other in-person events, such as your Product Group Summit and other gatherings, to continue building on those connections.
If you require an accommodation due to travel limitations or other reasons, please inform your recruiter during the hiring process. We are committed to supporting candidates who may need alternative arrangements
Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Germany Applicants: (m/f/d) - link to HubSpot's Career Diversity page here.
India Applicants: link to HubSpot India's equal opportunity policy here.
About HubSpot
HubSpot (NYSE: HUBS) is an AI-powered customer platform with all the software, integrations, and resources customers need to connect marketing, sales, and service. HubSpot's connected platform enables businesses to grow faster by focusing on what matters most: customers.
At HubSpot, bold is our baseline. Our employees around the globe move fast, stay customer-obsessed, and win together. Our culture is grounded in four commitments: Solve for the Customer, Be Bold, Learn Fast, Align, Adapt & Go!, and Deliver with HEART. These commitments shape how we work, lead, and grow.
We're building a company where people can do their best work. We focus on brilliant work, not badge swipes. By combining clarity, ownership, and trust, we create space for big thinking and meaningful progress. And we know that when our employees grow, our customers do too.
Recognized globally for our award-winning culture by Comparably, Glassdoor, Fortune, and more, HubSpot is headquartered in Cambridge, MA, with employees and offices around the world.
Explore more:
- HubSpot Careers
- Life at HubSpot on Instagram
HubSpot may use AI to help screen or assess candidates, but all hiring decisions are always human. More information can be found here. By submitting your application, you agree that HubSpot may collect your personal data for recruiting, global organization planning, and related purposes. We may use CLEAR ID Verification during the hiring process to confirm your identity and help maintain a safe, secure, and trusted experience for all candidates. Refer to HubSpot's Recruiting Privacy Notice for details on data processing and your rights.
See All 11 Remote Security Program Manager Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsRemote Security Program Manager Job Market
Who's Hiring


What Employers Look For
The qualifications that appear most often in remote security program manager jobs.
- Five or more years of experience managing information security programs or projects
- Hands-on experience with NIST Cybersecurity Framework, ISO 27001, or SOC 2 compliance
- Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP) certification
- Demonstrated ability to manage risk assessments, audits, and remediation tracking across an organization
- Experience communicating security program status and risks to executive and non-technical stakeholders
- Familiarity with GRC platforms such as ServiceNow, Archer, or similar governance and risk tools
Tips for Your Remote Security Program Manager Job Search
Show async program management in your materials
Remote employers want evidence you can run security programs without daily in-person check-ins. Include specific examples in your resume and cover letter of driving risk assessments, compliance cycles, or security roadmaps with distributed stakeholders using tools like Jira, Confluence, or Slack.
Apply early to remote roles that fit
Migrate Mate lists remote security program manager openings from across the U.S. in one place. Search the current roles, identify the ones that match your background and seniority level, and apply directly without waiting for postings to circulate elsewhere.
Lead with written communication samples
Remote hiring managers for security program manager roles evaluate how you write before they ever speak with you. Prepare a concise writing sample, such as a program status summary or a risk memo, that you can share or reference when you apply or during early screening.
Target remote-first companies over hybrid retrofits
Remote-first technology firms and cloud-native companies have built their security operations around distributed teams, so remote security program managers integrate faster and face fewer structural friction points than at companies where remote is a recent accommodation.
Remote Security Program Manager Jobs: Frequently Asked Questions
How do I get a remote security program manager job?
Remote security program manager roles go to candidates who can demonstrate self-direction, clear written communication, and the ability to coordinate complex security work without in-person oversight. Remote employers screen heavily for experience managing distributed stakeholders, writing crisp program documentation, and driving compliance or risk programs asynchronously. Certifications like CISSP, CISM, or PMP strengthen your case, and a portfolio of past program outcomes gives hiring managers concrete evidence you deliver without hand-holding.
Which companies hire remote security program managers?
Companies hiring remote security program managers right now include Metrea, Centene, and HubSpot, based on current remote listings on Migrate Mate as of August 2026. Remote-first technology firms, distributed financial services companies, and cloud-based healthcare platforms are the most consistent sources of fully remote openings in this role.
Can you get a remote security program manager job with no experience?
Yes, but remote entry-level openings are harder to land because employers expect you to manage programs independently from day one without in-person guidance. Smaller remote-first companies and startups are more open to candidates early in their careers. Showing documented project coordination, a security certification, and concrete examples of async communication can open doors when direct experience is thin.
Do you need a degree for remote security program manager jobs?
Not always. Many remote employers weigh relevant certifications, demonstrated program management results, and hands-on security experience more heavily than a degree, especially for mid-level and senior roles. A CISSP, CISM, or PMP alongside a clear record of running security initiatives can carry more weight than a diploma when hiring managers are evaluating remote candidates.
See All 11 Remote Security Program Manager Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs