Senior Technical Program Manager, Information Security Risk
ZillowAbout the role
About the team
The ZG Information Security team builds cutting-edge solutions to protect our technology stack, products, and services. We are deeply embedded across the business to ensure security is built into the fabric of how we design, develop, and deliver. Our mission is to proactively identify and manage security risks while enabling the company’s innovation and growth. We work closely with Engineering, IT, Legal, Privacy, and Compliance teams to build scalable risk management programs and promote a culture of security across the organization.About the role
This high-visibility, high-impact role drives the end-to-end strategy, execution, and continuous improvement of technical programs that form the backbone of Zillow’s security risk posture. You will influence enterprise-wide risk assessments, regulatory and compliance readiness, third-party risk management, and cross-functional security initiatives that span business and engineering domains.
As a Senior Technical Program Manager, You Will Get To
Lead and deliver critical security risk programs from initiation through execution, defining scope, success criteria, milestones, and delivery timelines in partnership with InfoSec and cross-functional teams.
Operationalize the risk lifecycle—including identification, assessment, remediation planning, and closure—across business units and technology environments.
Manage the lifecycle of information security policies and standards, partnering with subject matter experts to ensure clarity, applicability, and audit readiness.
Run scalable programs to evaluate and track third-party risks, ensuring alignment with Zillow’s security expectations.
Build reporting dashboards and communication mechanisms to surface key risk indicators, trends, and mitigation progress to technical and executive stakeholders, supporting compliance objectives.
Drive programmatic readiness for regulatory obligations (SOX, GLBA, SOC 2, etc.), aligning technical teams with audit and compliance objectives.
Collaborate across Engineering, IT, Legal, and Business teams to align on risk priorities, remove blockers, and ensure program success.
Proactively identify opportunities to improve existing programs and processes, embedding automation, risk quantification, and data-driven insights.
Who you are
Proven success driving complex technical programs with multiple workstreams and dependencies, ideally in cybersecurity, risk, or compliance.
Solid understanding of security domains including vulnerability management, IAM, encryption, security tooling, and cloud security practices.
Strong at designing and running repeatable, scalable programs with clear outcomes and stakeholder alignment.
Familiar with NIST, ISO 27001, FAIR, or similar standards to guide prioritization and decision-making.
Skilled at translating technical risk into business impact, and tailoring messaging for engineering teams, executives, and auditors.
Comfortable navigating ambiguity, prioritizing competing demands, and building strong cross-functional partnerships.
PMP, CISSP, CISM, CRISC, or equivalent experience preferred.
Here at Zillow – we value the experience and perspective of candidates with non-traditional backgrounds. We encourage you to apply if you have transferable skills or related experiences.
Get to know us
Zillow is reimagining real estate
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s