[TPM] Technical Product Manager (Compliance Domain)
About Agoda
At Agoda, we bridge the world through travel. Our story began in 2005, when two lifelong friends and entrepreneurs, driven by their passion for travel, launched Agoda to make it easier for everyone to explore the world.
Today, we are part of Booking Holdings [NASDAQ: BKNG], with a diverse team of over 7,000 people from 90 countries, working together in offices around the globe. Every day, we connect people to destinations and experiences, with our great deals across our millions of hotels and holiday properties, flights, and experiences worldwide.
No two days are the same at Agoda. Data and technology are at the heart of our culture, fueling our curiosity and innovation. If you’re ready to begin your best journey and help build travel for the world, join us.
Technical Product Manager – Secure Production Platforms
Get to Know our Team
Agoda’s Technical Product Management (TPM) organization drives internal platforms and tools that enable thousands of engineers to build, ship, and operate worldclass products efficiently and reliably. Our TPMs bridge business, data, and technology—translating complex engineering and operational needs into scalable solutions that empower teams across the company.
The Secure Production Platforms domain owns the systems, controls, and guardrails that ensure production services are secure, trusted, and compliant by design. This includes service identity and authentication frameworks, access control models, secrets lifecycle management, secure service discovery, and policy enforcement embedded directly into our production runtime platforms.
Our mission is to make secure operation the default—building reusable patterns and strong guardrails that protect customer data and platform integrity while preserving engineering velocity and autonomy.
The Opportunity
As a Technical Product Manager for Secure Production Platforms, you will define and evolve the platforms that govern how services authenticate, authorize, discover, and securely interact in production.
This is a technically deep TPM role. You are comfortable participating in detailed discussions about authentication flows, service identity models, policy enforcement, and secrets management. You partner closely with Security, Platform Engineering, Infrastructure, and service teams to standardize secure patterns across the organization.
You are not expected to be a security architect or regulatory specialist. Instead, you translate security principles into scalable platform capabilities, intuitive developer workflows, and consistent best practices adopted across many teams.
In This Role, You’ll Get To:
- Own the full product lifecycle for secure production platforms—from discovery and design through adoption and continuous improvement.
- Define a coherent long term vision for service identity, authentication, authorization, and secure runtime controls.
- Partner with Security and Platform Engineering to standardize service to service authentication and secure communication models (e.g., mTLS, token based identity, workload identity).
- Drive best practices in secrets lifecycle management, including secure storage, rotation, revocation, and least privilege access patterns.
- Establish consistent access control frameworks and reduce privilege sprawl across production environments.
- Embed enforceable guardrails and policy controls directly into runtime platforms to minimize manual interventions and inconsistent implementations.
- Provide clear documentation and guidance that helps engineering teams comply with platform standards efficiently.
- Identify systemic risks in authentication, access patterns, and secret usage, and prioritize investments that reduce risk at scale.
- Define and track measurable indicators of adoption, access standardization, and secure configuration coverage.
- Balance strong security controls with developer experience, ensuring platforms remain practical, scalable, and widely adopted.
- Communicate clearly and confidently across engineers and leadership, particularly when evolving organization wide security controls.
- Demonstrate strong ownership and execution, driving initiatives from concept through broad adoption across a large engineering organization.
- Stay current with industry practices in Zero Trust architectures, identity frameworks, and policy as code approaches, applying them pragmatically.
What You’ll Need to Succeed:
- Strong working understanding of authentication and authorization concepts such as OAuth2, OIDC, mTLS, service identity, RBAC, ABAC, and IAMstylepolicy models.
- Practical familiarity with secrets management best practices, including secure storage, dynamic credentials, rotation strategies, least privilege, and auditability.
- Understanding of service discovery and secure communication patterns in distributed systems.
- Ability to contribute meaningfully to architectural discussions around access control and policy enforcement in production environments.
- Experience guiding engineering teams toward consistent platform standards and best practices.
- 3+ years of experience in technical product or program management within a highly technical environment.
- Experience working closely with security engineering, infrastructure, or internal platform teams.
- Strong product thinking and communication skills, with the ability to influence technical direction without direct authority.
- Data driven mindset; comfortable defining metrics and measuring adoption and control effectiveness.
- Excellent stakeholder management skills in environments where platform controls may require behavior change.
- Highly organized and adaptable, comfortable operating in technically complex and evolving spaces.
- Hands on experience with product and delivery tools such as JIRA and Confluence.
- Ownership mindset focused on building durable, automation firs security platforms that scale across a large engineering organization.
Discover more about working at Agoda
- Agoda Careers https://careersatagoda.com
- Facebook https://www.facebook.com/agodacareers/
- LinkedIn https://www.linkedin.com/company/agoda
- YouTube https://www.youtube.com/agodalife
Equal Opportunity Employer
At Agoda, we pride ourselves on being a company represented by people of all different backgrounds and orientations. We prioritize attracting diverse talent and cultivating an inclusive environment that encourages collaboration and innovation. Employment at Agoda is based solely on a person’s merit and qualifications. We are committed to providing equal employment opportunity regardless of sex, age, race, color, national origin, religion, marital status, pregnancy, sexual orientation, gender identity, disability, citizenship, veteran or military status, and other legally protected characteristics.
We will keep your application on file so that we can consider you for future vacancies and you can always ask to have your details removed from the file. For more details please read our privacy policy.
Disclaimer
We do not accept any terms or conditions, nor do we recognize any agency’s representation of a candidate, from unsolicited third-party or agency submissions. If we receive unsolicited or speculative CVs, we reserve the right to contact and hire the candidate directly without any obligation to pay a recruitment fee.