Employer Active
Job Alert
You will be updated with latest job alerts via emailJob Alert
You will be updated with latest job alerts via emailWe are looking for an experienced security leader to build and drive our Product Security program. As Product Security Manager you will shape the securebydesign strategy for all customerfacing products and services oversee architecture reviews and penetration testing and partner closely with engineering and DevOps to embed security controls throughout the development lifecycle. You will own roadmap planning people development and crossfunctional communication.
Key responsibilities
Define and execute the productsecurity roadmap covering design reviews threat modelling penetration tests securecoding standards and testing automation
Lead and mentor a multidisciplinary team of security experts
Conduct risk assessments and threat modelling workshops
Establish and maintain productsecurity playbooks review checklists and engagement models for engineering squads
Coordinate and track vulnerability remediation providing clear risk and status updates to product engineering and executive leadership
Serve as single point of contact for product squads ensuring timely security reviews and pragmatic guidance.
Champion a security champion network organising workshops and sharing bestpractice playbooks to embed securitybydesign throughout the SDLC
Ensure product security processes align with relevant regulations and industry frameworks
Qualifications :
6 years of application or productsecurity experience with 2 years leading teams
Proven trackrecord establishing secure development lifecycle practices threatmodelling penetration testing and vulnerabilitymanagement workflows
Solid understanding of modern cloud and application architectures CI/CD pipelines and offensivesecurity testing techniques
Handson experience in code review threat modelling and penetration testing.
Strong leadership projectmanagement and stakeholdercommunication skills
Excellent written and verbal communication skills capable of conveying risk to technical and nontechnical audiences
Familiarity with common threatmodelling frameworks securecoding standards and industry compliance requirements
Relevant credentials (CISSP CSSLP OSWE/OSCP or comparable) are advantageous
Additional Information :
Remote Work :
Yes
Employment Type :
Fulltime
Remote