Leads and manages comprehensive product security initiatives across the organization's product portfolio, ensuring security is embedded throughout the entire product development lifecycle. Develops strategic security programs, manages cross-functional security teams, and partners with product management, engineering, and business stakeholders to deliver secure products that meet customer and regulatory requirements. Drives the implementation of security frameworks, policies, and tooling while balancing security requirements with business objectives and product delivery timelines.
Required Skills
- Proficiency with modern application security tools, including SAST (e.g., Semgrep, Coverity, Veracode, Checkmarx), SCA (e.g., Black Duck, Synopsys), and secrets management tools (e.g., GitGuardian, TruffleHog, GitHub Advanced Security, HashiCorp Vault)
- Hands-on experience in securing IaC templates and using scanning tools (e.g., Terraform, CloudFormation, Checkov)
- Deep understanding of secure software development practices and integrating security into CI/CD pipelines
- Excellent team leadership and collaboration skills, with the ability to work effectively with cross-functional teams, including product management, engineering, DevOps, and business stakeholders
- Knowledge of container security principles (e.g., Kubernetes, Docker) and security tools
- Strategic product security leadership with experience managing security programs across multiple product lines and development teams
- Strong business acumen and ability to translate security requirements into product roadmap priorities and resource allocation decisions
Roles and RESPONSIBILITIES
- Building and leading high-performing product security teams, establishing security strategy and priorities aligned with business objectives and product roadmaps
- Developing and implementing comprehensive product security programs, including security tooling, processes, and governance frameworks across the product development lifecycle
- Collaborating with product management teams to integrate security requirements into product planning, feature development, and go-to-market strategies
- Managing security risk assessments for products and providing strategic guidance on vulnerability remediation priorities and business impact
- Driving security awareness and training programs for product teams while fostering a security-first culture across the organization
- Monitoring regulatory landscape, industry standards, and emerging threats to continuously evolve product security strategies and compliance requirements
Perks & Benefits
- Comprehensive health, vision, and wellness benefits (Paid parental leave, adoption benefits, life insurance, disability insurance, and 401k plan or international pension/retirement plans
- Flexible time-off policy and hybrid working practices
- Equity opportunities and an employee stock purchase program (ESPP)
- Comprehensive Mental Health and Employee Assistance Program (EAP) benefit