We're hiring a Senior Security Program Manager to run security and compliance as a program at TinyFish. You'll own the operational backbone — Vanta, audits, vulnerability SLAs, policy lifecycle, vendor risk, customer security reviews — so our Security Lead can stay focused on architecture and threat work, and security requirements run smoothly across our enterprise deals.
This is an IC role reporting to the Staff Program Manager, working closely with our Security Lead. You'll be the first hire whose full-time job is running the program rather than building the controls.
TinyFish builds browser-based AI agents that do real work on the open web for enterprise customers. We're a small, technical team shipping fast against serious enterprise buyers who ask serious security questions. We're mid-flight on ISO 27001 certification renewal (Schellman external, Alameda internal) and our security posture is moving from "small startup" to "we can answer a 400-line questionnaire without flinching."