
Principal Product Manager, Security
Posted 11 hours ago

Posted 11 hours ago
This is a fully remote position, open to applicants in United States, +1 more country.
β’ Collaborate with product managers and feature teams from the outset to pinpoint security requirements and assess threat-model impacts.
β’ Ensure that security needs are clearly visible, prioritized, and appropriately resourced.
β’ Convert the needs of feature teams into prioritized security tasks.
β’ Make Security Engineering priorities transparent across the organization.
β’ Manage the independent roadmap for platform-level security investments, which includes key management and recovery, cryptographic foundations, authentication, and preparedness for post-quantum cryptography.
β’ Establish strategies for agentic access to credentials and secrets for non-human identities and AI agents, as well as trust models related to tools and protocols such as MCP.
β’ Evaluate real-world security risks against user friction by analyzing adoption, support, and telemetry data.
β’ Document and justify accepted residual-risk decisions.
β’ Interact with security researchers and oversee the bug bounty program.
β’ Present at conferences and contribute to the credential-security community.
β’ Mentor product managers on security considerations and elevate the standards for security-critical product development.
β’ Define and advocate for product strategy, prioritize tasks, collaborate across Engineering, Design, Security Research, and GTM, and assess quality and business outcomes.
β’ Over 10 years of experience in product management, including substantial involvement with security-critical products or platforms in a SaaS setting.
β’ Exceptional candidates with a similar level of experience, such as security engineers or researchers who transitioned into product roles, will also be considered.
β’ Extensive knowledge of cryptography, authentication protocols, identity and access management, zero-knowledge and end-to-end encrypted system design, and threat modeling.
β’ Proficient understanding of the credential and identity landscape, including passkeys and WebAuthn/FIDO.
β’ Proven track record of gaining credibility with security engineering teams.
β’ Competence in interpreting and reasoning through technical specifications, security audits, and cryptographic design documents.
β’ Experience in making and defending risk-based trade-offs.
β’ History of delivering security features that users embrace while utilizing friction and adoption data for enhancements.
β’ Experience in setting strategies at the platform or infrastructure level and influencing roadmaps without formal authority.
β’ Ability to convey information clearly from a security research paper to an executive summary.
β’ Strong perspective on changes within the security landscape and the ability to relate them to roadmap decisions.
β’ Established presence in the security community through conference presentations, publications, research, open-source contributions, or standards involvement is a strong advantage.
β’ Hands-on experience in AI security is a strong plus.
β’ Familiarity with SOC 2, FedRAMP, or FIPS is a strong plus.
β’ Previous experience in vulnerability disclosure, incident response, or threat intelligence is a strong plus.
β’ Background in running or closely collaborating with a bug bounty program or researcher community is a strong plus.
β’ Must already be legally authorized to work in the United States or Canada; no work authorization, relocation assistance, or visa sponsorship will be provided.
β’ Successful candidates must pass a background check.
β’ 15% annual bonus.
β’ Health benefits.
β’ Dental benefits.
β’ 401(k) or RRSP, depending on the country.
β’ Generous paid time off.
β’ Equity grant / RSU program for most employees.
β’ Incentive programs, where applicable.
β’ Maternity and parental leave top-up programs.
β’ Retirement matching program.
β’ Free 1Password account.
β’ Paid volunteer days.
β’ Peer-to-peer recognition through Bonusly.
β’ Remote-first work environment.
β’ Opportunities for travel for in-person engagement, including offsites, team meetings, and customer/industry events.
β’ Accommodation available upon request during recruitment.
Cotiviti
Affirm
Get handpicked remote jobs straight to your inbox weekly.