Technical Program Manager – Program Management

Zero-to-one program execution: How would you stand up a complex cross-functional program from scratch, such as a new SOC 2 compliance or security framework, across 10 distinct engineering teams without slowing core product delivery?

Compliance work only survives contact with a roadmap if it's designed to feel like a small, visible tax — not a competing project fighting for the same engineers' time. The core move is doing as much of the work centrally as possible before anything lands in an individual team's backlog, then federating just enough that no single group owns implementation for all ten teams at once.

  1. 1.Secure sponsorship and define the "why now" — get a CTO/CISO-level executive sponsor, tie the program to a concrete business driver (e.g., blocked enterprise deals), and narrow scope (Type I vs. II, which Trust Service Criteria) up front.
  2. 2.Run the gap assessment centrally — map SOC 2 control families against current state with a small core team, producing a gap list tagged by owning team, effort, and whether it's one-time or ongoing.
  3. 3.Build a federated governance structure — one compliance champion per team at ~10–15% time translates requirements into that team's own backlog, while the TPM owns the cross-team tracker, risk register, and audit timeline.
  4. 4.Sequence work so it never competes with the roadmap — knock out 40–60% of controls centrally in Phase 1 (SSO/MFA, logging, policy), absorb what's genuinely team-specific into Phase 2 through shared tooling, then run Phase 3 as automated continuous monitoring.
  5. 5.Make it "compliance as code," not tickets — enforce controls in existing tooling (branch protection, CI gates, IaC policy checks), automate evidence collection with a compliance platform, and budget a fixed capacity tax inside each team's own sprint planning.
  6. 6.Run a cadence and prove audit readiness before the audit — hold a biweekly champion sync and monthly exec readout, then run a mock audit 4–6 weeks out to catch gaps before they become findings.

This holds up because most of the compliance surface area is absorbed centrally before a single team ever sees it, the champion model keeps the remainder inside each team's own planning process instead of a competing backlog, and automation removes the ongoing manual burden — so ten teams experience this as a small, visible tax, not a program that displaces their roadmap.