Jobs and Careers
ZI

Senior Technical Program Manager, Information Security Risk

Zillow
Remote-USA, United States, United StatesRemotefull_timeVerifiedPosted 9 Jun 2025
💰 $232,500/yr($145,500/yr$232,500/yr)

About the role

About the team

The ZG Information Security team builds cutting-edge solutions to protect our technology stack, products, and services. We are deeply embedded across the business to ensure security is built into the fabric of how we design, develop, and deliver. Our mission is to proactively identify and manage security risks while enabling the company’s innovation and growth. We work closely with Engineering, IT, Legal, Privacy, and Compliance teams to build scalable risk management programs and promote a culture of security across the organization.

About the role

This high-visibility, high-impact role drives the end-to-end strategy, execution, and continuous improvement of technical programs that form the backbone of Zillow’s security risk posture. You will influence enterprise-wide risk assessments, regulatory and compliance readiness, third-party risk management, and cross-functional security initiatives that span business and engineering domains.

As a Senior Technical Program Manager, You Will Get To

  • Lead and deliver critical security risk programs from initiation through execution, defining scope, success criteria, milestones, and delivery timelines in partnership with InfoSec and cross-functional teams.

  • Operationalize the risk lifecycle—including identification, assessment, remediation planning, and closure—across business units and technology environments.

  • Manage the lifecycle of information security policies and standards, partnering with subject matter experts to ensure clarity, applicability, and audit readiness.

  • Run scalable programs to evaluate and track third-party risks, ensuring alignment with Zillow’s security expectations.

  • Build reporting dashboards and communication mechanisms to surface key risk indicators, trends, and mitigation progress to technical and executive stakeholders, supporting compliance objectives.

  • Drive programmatic readiness for regulatory obligations (SOX, GLBA, SOC 2, etc.), aligning technical teams with audit and compliance objectives.

  • Collaborate across Engineering, IT, Legal, and Business teams to align on risk priorities, remove blockers, and ensure program success.

  • Proactively identify opportunities to improve existing programs and processes, embedding automation, risk quantification, and data-driven insights.

This role has been categorized as a Remote position. “Remote” employees do not have a permanent corporate office workplace and, instead, work from a physical location of their choice, which must be identified to the Company. U.S. employees may live in any of the 50 United States, with limited exceptions.

In California, Colorado, Connecticut, Hawaii, Maryland, Massachusetts, Nevada, New Jersey, New York, Vermont, Washington state, and Washington DC the standard base pay range for this role is $145,500.00 - $232,500.00 Annually. This base pay range is specific to California, Colorado, Connecticut, Hawaii, Maryland, Massachusetts, Nevada, New Jersey, New York, Vermont, Washington state, and Washington DC and may not be applicable to other locations.

In addition to a competitive base salary this position is also eligible for equity awards based on factors such as experience, performance and location. Actual amounts will vary depending on experience, performance and location.

Who you are

  • Proven success driving complex technical programs with multiple workstreams and dependencies, ideally in cybersecurity, risk, or compliance.

  • Solid understanding of security domains including vulnerability management, IAM, encryption, security tooling, and cloud security practices.

  • Strong at designing and running repeatable, scalable programs with clear outcomes and stakeholder alignment.

  • Familiar with NIST, ISO 27001, FAIR, or similar standards to guide prioritization and decision-making.

  • Skilled at translating technical risk into business impact, and tailoring messaging for engineering teams, executives, and auditors.

  • Comfortable navigating ambiguity, prioritizing competing demands, and building strong cross-functional partnerships.

  • PMP, CISSP, CISM, CRISC, or equivalent experience preferred.

  • Here at Zillow – we value the experience and perspective of candidates with non-traditional backgrounds. We encourage you to apply if you have transferable skills or related experiences.

Get to know us

Zillow is reimagining real estate

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Zillow

View company profile →