F5 is seeking a highly experienced and results-driven Technical Program Manager (TPM) to lead and manage critical programs focused on software security- This is a senior level role that will drive initiatives that enhance F5 s security posture by implementing best practices for vulnerability management, security scanners, CVE tracking, Security Software Development Life Cycle (SDLC), and more- The ideal candidate will have a deep understanding of security programs, a strong technical background in software development, and a proven track record of successfully delivering cross-functional initiatives in complex environments-
As a trusted leader, you will collaborate closely with engineering, security, product, and operations teams to ensure F5 s products and processes meet the highest security standards while enabling business objectives-
Key Responsibilities:
-
Program Management:
-
Strategically plan and deliver programs and initiatives across key security and vulnerability management areas, including implementation of security tools (scanners, CI/CD integrations), tracking and addressing vulnerabilities (e-g-, CVEs), and enforcing best practices throughout the software development lifecycle-
-
Own program roadmaps, timelines, deliverables, and reporting, ensuring execution aligns with business goals, security requirements, and resource capacity-
-
Drive key metrics and outcomes for security, tracking improvements in vulnerability remediation, compliance, and overall risk reduction-
-
Security SDLC and Vulnerability Management:
-
Partner with engineering and security teams to integrate Security SDLC (Secure Software Development Lifecycle) best practices into the development process, ensuring security is considered and implemented at every stage-
-
Manage programs for vulnerability detection, assessment, and remediation to ensure timely resolution of security risks identified across F5 products and environments-
-
Develop and implement governance processes for tracking and addressing externally reported vulnerabilities, such as Common Vulnerabilities and Exposures (CVEs) , ensuring effective prioritization and swift resolution-
-
Cross-Functional Collaboration:
-
Build strong relationships with software engineering, product management, cybersecurity, IT, and operations teams to foster alignment across security-related goals and projects-
-
Act as the central point of coordination for security initiatives, driving progress and ensuring accountability across stakeholders-
-
Facilitate efficient communication between technical and non-technical teams to ensure clarity around priorities, goals, and timelines-
-
Risk and Compliance Management:
-
Drive alignment on security requirements, risk tolerance, and compliance needs, partnering with internal and external security auditors where required-
-
Ensure teams are meeting corporate and industry security standards, including regulatory and policy compliance, while achieving development velocity-
-
Proactively identify and manage security risks through effective mitigation planning and ongoing tracking-
-
Process Improvement and Tooling:
-
Evaluate current security program practices, tools, and workflows, identifying gaps and opportunities for improvement in efficiency and effectiveness-
-
Lead the implementation of automated tools for static and dynamic code analysis, dependency scanning, and configuration management to identify and address vulnerabilities earlier in the development process-
-
Metrics and Reporting:
-
Define, track, and report on KPIs and success metrics for security efforts, including vulnerability remediation rates, defect density reduction, and SLAs for incident response-
-
Provide clear and actionable updates to executive leadership and key stakeholders on the status of security programs, progress, risks, and outcomes-
Qualifications:
Preferred Qualifications:
-
Project management certification (e-g-, PMP, PgMP, or PMI-ACP) or security-related certifications (e-g-, CISSP, CISM, or CISA)-
-
Experience with cloud security and platform-oriented vulnerability management tools like Bugzilla or similar-
-
Familiarity with emerging cybersecurity trends and zero-day vulnerability exploitation techniques-
-
Knowledge of networking and application delivery technologies (F5 experience is a plus!)