Hashtag Web3 Logo
a16z crypto logo

Partner 20, Staff Security Technical Program Manager

San Francisco, California, United States$243k – $284k/yrPosted today

Founded in Silicon Valley in 2009 by Marc Andreessen and Ben Horowitz, Andreessen Horowitz (aka a16z) is a venture capital firm that backs bold entrepreneurs building the future through technology. We are stage agnostic. We invest in seed to venture to growth-stage technology companies, across AI, bio + healthcare, consumer, crypto, enterprise, fintech, games, and companies building toward American dynamism. a16z has $100B+ under management across multiple funds.

We've established a team that is defined by respect for the entrepreneur and the company-building process; we know what it's like to be in the founder's shoes. We've invested in companies like Anduril, Airbnb, Coinbase, Cursor, Databricks, Deel, Figma, GitHub, Roblox, SpaceX, and Stripe. Our team is at the forefront of new technology, helping founders and their companies impact and change the world.

Key Responsibilities

We're hiring a Staff Security Technical Program Manager to run the operating system of the a16z Security team. You'll own the firm's vulnerability management program, drive cross-team security initiatives to completion, and own the planning rhythm that keeps the team and its stakeholders aligned: sprints, OKRs, timelines, and the documentation and ticketing hygiene that make all of it real.

Security at a16z moves fast and touches every part of the firm. We work in close partnership with teams across the firm. Your job is to keep that work on schedule, keep decisions written down, and make sure nothing gets dropped between teams. Leadership should be able to get the real status from you, and engineers should see you as someone who removes obstacles, not someone who adds process.

This role requires an in-office presence 2 days a week, Tuesday and Thursday, in our San Francisco, CA office, with occasional days in our Menlo Park, CA office.

To join our team, you should be excited to

  • Own security remediation across the firm, end to end: Pull findings from threat models, code reviews, penetration tests, vulnerability management, audits, and incident postmortems into a single tracked backlog, and manage it with clear owners, priorities, remediation SLAs
  • Run the vulnerability management program: Scan coverage, patching cadence, exceptions and risk acceptance, and reporting that shows leadership where risk stands
  • Work with stakeholders to keep vendor security reviews fast and consistent, and keep requesters informed on where their review stands
  • Drive cross-team security initiatives from kickoff through delivery, coordinating work across Security, IT, Legal, HR, and Compliance, and partnering with owners to keep commitments on track
  • Build and run the team's execution rhythm: Sprint planning, quarterly OKRs, and ticket hygiene that keeps the work visible
  • Raise the bar on documentation: Program docs, runbooks, decision records, and postmortem follow-ups that stay findable and current
  • Define and track the metrics that tell us whether our programs are working, and turn them into actionable insights

Qualifications & Requirements

  • 7+ years of technical program management experience, with at least 3 years running security programs
  • A track record of owning a vulnerability management program at scale: SLAs, remediation tracking across teams you don't control, executive reporting, and measurable risk reduction
  • Technical fluency to be credible with security engineers: you can read a finding, understand severity and exploitability, and push back on a risk rating with reasons.
  • Knows the common SaaS tools (okta, Slack,GSuite etc) of an enterprise stack well enough to talk through their security issues with the teams that own them.
  • Deep hands-on experience with agile execution: sprint planning, OKR frameworks, ticketing systems (Jira, Linear, or equivalent), documentation platforms like Confluence or Notion, and building program reporting in spreadsheets or BI dashboards.
  • Writing that is clear, brief, and structured
  • Ability to build strong working relationships across functions like IT, Legal, Compliance, and engineering, and execute through those partnerships: work gets done with other teams, not around them.
  • Low ego, high empathy, and the capacity to collaborate effectively with diverse teams The anticipated salary range for this role is between $243,000 - $284,000, actual starting pay may vary based on a range of factors which can include experience, skills, and scope.

This role is eligible to participate in the a16z carry program and various discretionary bonus programs as well as benefit and perquisite plans including health, dental, vision, disability, life insurance, 401K plan, vacation, and sick leave.

a16z culture

  • We do only first class business and only in a first class way
  • We take a long view of relationships, because we are in the relationship business
  • We believe in the future and bet the firm that way
  • We are all different, we recognize that, and we win
  • We celebrate the good times
  • We do it for the team
  • We play to win At a16z we are always looking to hire the absolute best talent and recognize that diversity in our experiences and backgrounds is what makes us stronger. We hire candidates of any race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital or family status, disability, Veteran status, and any other status. These differences are what enables us to work towards the future we envision for ourselves, our portfolio companies, and the World.

Our organization participates in E-Verify. Click to learn about E-Verify. Andreessen Horowitz hereby reserves the right to make use of any unsolicited resumes received from outside recruiting agencies and / or individual recruiters without being responsible for payment of any fees asserted from the use of unsolicited resumes.

About a16z crypto

a16z Crypto is a venture capital fund managed by Andreessen Horowitz that invests in Web3, crypto protocols, and blockchain technology.