Lead Technical Program Manager, Information Security Management System
Company: Google
Location: Cupertino
Posted on: March 20, 2026
|
|
|
Job Description:
Minimum qualifications: Bachelors degree in a technical field,
or equivalent practical experience. 8 years of experience in
technical program management, managing cross-functional engineering
or security programs. Preferred qualifications: Experience mapping
complex regulatory requirements to technical implementations in
modern software development and infrastructure environments.
Experience managing compliance or GRC frameworks (e.g., ISO 27001,
SOC2, NIS2) across a large and federated product portfolio.
Understanding of information security principles, cloud
architectures, and enterprise control frameworks. Track record of
driving large-scale, cross-organizational initiatives, defining
governance structures, and establishing accountability models in a
federated or matrixed corporate environment. Exceptional executive
presence and influencing skills, with the ability to negotiate,
untangle complex organizational problems, and drive alignment with
executive engineering leaders (Director/VP level) without direct
reporting lines. About the job A problem isn’t truly solved until
it’s solved for all. That’s why Googlers build products that help
create opportunities for everyone, whether down the street or
across the globe. As a Technical Program Manager at Google, you’ll
use your technical expertise to lead complex, multi-disciplinary
projects from start to finish. You’ll work with stakeholders to
plan requirements, identify risks, manage project schedules, and
communicate clearly with cross-functional partners across the
company. Youre equally comfortable explaining your teams analyses
and recommendations to executives as you are discussing the
technical tradeoffs in product development with engineers. Googles
Information Security Management System (ISMS) and common controls
are the foundational underpinning for 400 products to meet
compliance obligations with several critical regulations and
standards. This is a unique opportunity to re-imagine the security
compliance function from the ground up, establishing a scalable,
data-driven, and AI-enabled model. Concurrently in the short term,
we will ensure Google consistently and efficiently fulfills all its
immediate obligations. As the Lead Technical Program Manager, you
will be the primary bridge between our centralized compliance
function and Google’s vast ecosystem of Product Areas (e.g.,
Search, YouTube, Android, Cloud). While many security controls are
central, a significant portion of our compliance posture relies on
federated people, processes, and technologies spanning 400
products. You will design and implement the engagement frameworks,
governance structures, and accountability models necessary to scale
compliance across these federated environments. This requires a
unique blend of deep technical security acumen and exceptional
executive influencing skills to drive alignment and accountability
without direct authority. The US base salary range for this
full-time position is $192,000-$278,000 bonus equity benefits. Our
salary ranges are determined by role, level, and location. Within
the range, individual pay is determined by work location and
additional factors, including job-related skills, experience, and
relevant education or training. Your recruiter can share more about
the specific salary range for your preferred location during the
hiring process. Please note that the compensation details listed in
US role postings reflect the base salary only, and do not include
bonus, equity, or benefits. Learn more about benefits at Google .
Responsibilities Establish clear responsibility and accountability
models for federated controls across Googles product areas. Drive
the structure and execution of continuous, cross-functional
engagement with product area leaders. Act as the central compliance
ambassador, ensuring ISMS requirements are integrated seamlessly
into engineering roadmaps. Partner with security and engineering
teams to ensure local controls meet regulatory (ISO, SOC, NIS2)
standards. Guide product areas through complex audit preparations,
facilitate evidence collection, and help defend federated
implementations to external auditors. Collaborate closely with
local risk teams. Identify synergies, converge redundant efforts,
and amplify a unified approach to product area security risk and
compliance reporting to reduce friction for engineering teams.
Leverage your technical background to deeply understand team
architectures and operations. Translate central compliance and
regulatory mandates into practical, engineer-friendly technical
requirements.
Keywords: Google, Rancho Cordova , Lead Technical Program Manager, Information Security Management System, IT / Software / Systems , Cupertino, California