1

Senior Security Program Manager Jobs in Santa Rosa, CA

Senior GRC Engineer

Bodega Bay, CA · On-site

$135K - $186K/yr

This is an early-stage program, and you will frame problems as often as you solve them * Partner with Security Governance Partners, Compliance, and Engineering teams to find the manual processes most ...

Clinical Operations Team Build | Bay Area | CTA/ CRA, Clinical Trial Manager, and Clinical Program ... Early hires here are positioned for the senior seats as the programme scales. * Leadership. An ...

Clinical Operations Team Build | Bay Area | CTA/ CRA, Clinical Trial Manager, and Clinical Program ... Early hires here are positioned for the senior seats as the programme scales. * Leadership. An ...

Director of Security

Calistoga, CA · On-site

$95K - $106K/yr

Promote associate engagement through regular communication, recognition programs, and performance ... You have proven experience in leading a Security department at a senior management level. * You ...

Promote associate engagement through regular communication, recognition programs, and performance ... You have proven experience in leading a Security department at a senior management level. * You ...

Support NERSC's security risk management program and policy and compliance efforts, including ... Experience delivering presentations to senior management and/or large stakeholders. * Strong ...

Senior Project Engineer

Healdsburg, CA · On-site

$170K - $215K/yr

... complex security challenges. We strive for an inclusive, collaborative team environment that ... This role operates at the intersection of engineering execution and program management, ensuring ...

Country Trade Compliance Manager (CTCM) __ Your role and responsibilities The Senior Leader, U.S ... of Industry and Security (BIS), Directorate of Defense Trade Controls (DDTC), and OFAC, as ...

Showing results 41-60

Senior Security Program Manager information

See Santa Rosa, CA salary details

$42.6K

$125.9K

$170K

How much do senior security program manager jobs pay per year?

As of Sep 9, 2026, the average yearly pay for senior security program manager in Santa Rosa, CA is $125,901.00, according to ZipRecruiter salary data. Most workers in this role earn between $126,800.00 and $127,400.00 per year, depending on experience, location, and employer.

What does a senior security program manager do?

A Senior Security Program Manager is responsible for overseeing and coordinating an organization's security programs and initiatives. They lead teams to develop, implement, and maintain security policies, procedures, and controls to protect information and assets from threats. This role involves collaborating with stakeholders, managing security projects, ensuring compliance with regulations, and responding to security incidents. Senior Security Program Managers also analyze risks and develop strategies to mitigate them, ensuring the organization's overall security posture is robust and effective.

How does a senior security program manager typically collaborate with cross-functional teams to implement security initiatives?

A Senior Security Program Manager often works closely with IT, engineering, compliance, and executive teams to develop and execute security programs. They act as a bridge between technical experts and business stakeholders, ensuring that security measures align with organizational goals. This role involves leading meetings, coordinating project timelines, and facilitating communication to address risks and ensure regulatory compliance. Effective collaboration is essential, as many security initiatives require buy-in and active participation from multiple departments.

What are the key skills and qualifications needed to thrive as a senior security program manager, and why are they important?

To thrive as a Senior Security Program Manager, you need deep expertise in information security, risk management, and program leadership, often supported by a bachelor’s or master’s degree in a related field and relevant certifications like CISSP or CISM. Familiarity with security frameworks (such as NIST or ISO 27001), project management tools, and GRC (governance, risk, and compliance) systems is typically required. Strong communication, stakeholder management, and strategic thinking are vital soft skills that set top performers apart. These abilities are essential for effectively leading security initiatives, ensuring compliance, and aligning security goals with business objectives.

What is the difference between Senior Security Program Manager vs Security Analyst?

AspectSenior Security Program ManagerSecurity Analyst
CredentialsCertifications like CISSP, CISM, PMPCertifications like Security+, GIAC, CEH
Work EnvironmentOversees security programs, manages teams, develops policiesMonitors security systems, analyzes threats, conducts assessments
Employer & Industry UsageUsed in large organizations, corporations, government agenciesCommon in IT departments, security firms, and tech companies

The Senior Security Program Manager focuses on managing security initiatives, policies, and teams, while the Security Analyst primarily monitors and analyzes security threats. Both roles require relevant certifications and are integral to organizational security, but they differ in scope and responsibilities.

What job categories do people searching Senior Security Program Manager jobs in Santa Rosa, CA look for?

The top searched job categories for Senior Security Program Manager jobs in Santa Rosa, CA are:

What cities near Santa Rosa, CA are hiring for Senior Security Program Manager jobs?

Cities near Santa Rosa, CA with the most Senior Security Program Manager job openings:

Senior GRC Engineer

Bodega Bay, CA • On-site

$135K - $186K/yr

Full-time

Posted 7 days ago


Key responsibilities

  • Build and operate data pipelines and integrations that aggregate, normalize, and join risk, control, and asset signals from various systems across Block.

  • Translate security standards and compliance requirements into policy-as-code and develop agentic AI workflows for evidence analysis, control monitoring, classification, and assessment.

  • Automate evidence collection and continuous control monitoring to replace manual, point-in-time audit processes.


Block rating

7.9

Company rating: 7.9 out of 10

Based on 16 frontline employees who took The Breakroom Quiz

9th of 21 rated payment service providers


Job description

Block is one company built from many blocks, all united by the same purpose of economic empowerment. The blocks that form our foundational teams - People, Finance, Counsel, Hardware, Information Security, Platform Infrastructure Engineering, and more - provide support and guidance at the corporate level. They work across business groups and around the globe, spanning time zones and disciplines to develop inclusive People policies, forecast finances, give legal counsel, safeguard systems, nurture new initiatives, and more. Every challenge creates possibilities, and we need different perspectives to see them all. Bring yours to Block.

The Role

Block Information Security is an engineering-driven team focused on scaling security through innovation. Our Security Governance team designs and promotes the frameworks and standards that safeguard customer data, elevate security considerations across the company, and simplify regulatory and compliance obligations. The team also operates the agent-first platform that turns those frameworks into running systems.

Most of governance is a data problem. The risk, control, and asset information needed to answer "are we secure and compliant?" is dispersed across dozens of systems: source control, service registries, identity providers, data warehouses, ticketing, CI/CD. GRC Engineers treat that as an engineering problem. You'll build the data pipelines, integrations, and agentic AI workflows that turn manual governance processes into products that run continuously, produce measurable results, and hold up to audit end to end.

You Will
  • Build and operate the pipelines and integrations that aggregate, normalize, and join risk, control, and asset signals from systems of record across Block, including source control, the service registry, identity, ticketing, data platforms, and CI/CD
  • Translate security standards and compliance requirements into policy-as-code: enforceable, testable rules that run continuously. For example, "every production service has an accountable owner" becomes a versioned, tested check instead of a quarterly spreadsheet
  • Design agentic AI workflows that pair LLM reasoning with deterministic, auditable decision layers for evidence analysis, control monitoring, classification, and assessment
  • Build the evals, benchmarks, and calibration harnesses that keep automated governance honest
  • Automate evidence collection and continuous control monitoring to replace point-in-time audit preparation
  • Define the technical approach for ambiguous, cross-team problem spaces. This is an early-stage program, and you will frame problems as often as you solve them
  • Partner with Security Governance Partners, Compliance, and Engineering teams to find the manual processes most worth turning into product
  • Help govern Block's own AI systems: the same platform that automates governance also assesses the autonomy and safety of Block's agents
  • Contribute to technical design discussions, evaluating the security and reliability properties of the platform itself
You Have
  • 7+ years building production software in backend, platform, data, or security engineering
  • Multi-year ownership of a production system, including on-call, SLOs, and the maintenance work that starts after launch
  • Proficiency with at least one of Python, Kotlin, Java, or Go, and comfort reading unfamiliar codebases
  • Hands-on experience building with LLMs (prompting, tool use, agents, or LLM-backed features) and opinions about where model judgment belongs and where it doesn't. Judgment matters more here than volume
  • Experience with integration patterns: REST APIs, webhooks, authentication flows, event-driven architectures
  • Experience pulling, normalizing, and joining data from multiple imperfect sources, and handling the edge cases gracefully
  • Experience defining technical direction where the problem was ambiguous, and carrying it across team boundaries
  • Attention to detail balanced with pragmatism about risk-based prioritization

Nice to have (optional):

  • Working knowledge of a security or compliance framework such as PCI DSS, SOX, SOC 2, ISO 27001, or NIST. Prior GRC experience is not required; we can teach the governance side
  • Production-scale LLM or agentic systems experience
Technologies You Are Familiar With 
  • Languages & Frameworks: Python, Java, Kotlin, Go
  • AI: LLM APIs (we build on Claude), agent frameworks and tool-use patterns such as Model Context Protocol, eval harnesses
  • APIs & Data: HTTP, JSON, gRPC, Protocol Buffers, SQL, Snowflake
  • Infrastructure: AWS, GCP, Kubernetes, Terraform, CI/CD (Buildkite), event-driven architecture

We're working to build a more inclusive economy where our customers have equal access to opportunity, and we strive to live by these same values in building our workplace. Block is an equal opportunity employer evaluating all employees and job applicants without regard to identity or any legally protected class. We will consider qualified applicants with arrest or conviction records for employment in accordance with state and local laws and "fair chance" ordinances.
We believe in being fair, and are committed to an inclusive interview experience, including providing reasonable accommodations to disabled applicants throughout the recruitment process. We encourage applicants to share any needed accommodations with their recruiter, who will treat these requests as confidentially as possible. Want to learn more about what we're doing to build a workplace that is fair and square? Check out our I+D page.

While there is no specific deadline to apply for this role, U.S. roles are typically open for an average of 55 days before being filled by a successful candidate. Please refer to the date listed at the top of this job page for when this role was first posted.


What Block employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom