Product Security Governance Principal

atFifth Third BankRemoteUS flagOhioFull-timeComplianceLead$96.5k – $207.5k/year

Posted 4 days ago

This is a fully remote position, open to applicants in Ohio.

📋 Description

• Oversee and enhance Product Security governance for internally developed customer-facing software, APIs, SDKs, integrations, and associated services.

• Establish product scope, engagement criteria, review expectations, decision-making authorities, escalation processes, and standards for evidence.

• Create and uphold standards, procedures, playbooks, templates, decision documents, risk records, and supplementary guidance.

• Facilitate risk-based decisions concerning security requirements, applicability of controls, exceptions, compensating controls, and accountability.

• Align Product Security practices with enterprise architecture, application security, vulnerability management, risk, compliance, audit, and engineering workflows.

• Spearhead a scalable customer assurance model for relevant products and services.

• Coordinate security summaries, whitepapers, assessment responses, and associated evidence.

• Collaborate with Product, Engineering, Risk, Compliance, Legal, Audit, and customer-facing teams to address customer, deal, regulatory, and audit requirements.

• Direct Product Security coordination for relevant SOC 2 and related readiness initiatives.

• Assist in system scoping, validation of business requirements, readiness assessments, gap analyses, evidence coordination, and engagement with assessment providers.

• Assess product security evidence from threat modeling, penetration testing, security scanning, software supply chain practices, secure development, incident management, and remediation.

• Develop consolidated perspectives on product security risk, control adoption, coverage, and assurance readiness.

• Lead governance forums, readiness reviews, working sessions, and decision-making meetings.

• Identify recurring trends and propose scalable enhancements.

• Deliver updates and recommendations to technical teams, business stakeholders, and senior leadership.

• Contribute to the Product Security strategy, planning, prioritization, and roadmap formulation.

• Foster a culture of shared accountability for secure and trustworthy customer-facing products.


⛳️ Requirements

• A minimum of seven years of progressively responsible experience in Product Security, security governance, cybersecurity assurance, IT risk, security compliance, technology auditing, security architecture, or a related field.

• Proven track record in leading security governance, assurance, readiness, control evaluation, gap analysis, or evidence-review practices within a complex organization.

• Capability to independently assess technical and non-technical evidence, pinpoint material concerns, use sound judgment, and advocate defensible decisions.

• Experience in translating security and compliance requirements into actionable expectations for product and engineering teams.

• Skill in influencing senior stakeholders, fostering constructive challenges, resolving ambiguities, and driving accountable outcomes across Product, Engineering, Information Security, Risk, Compliance, Audit, Legal, and business teams.

• Comprehensive understanding of administrative, technical, and operational security controls throughout the product lifecycle.

• Experience in maintaining governance artifacts such as standards, procedures, control matrices, evidence inventories, decision records, risk records, and action plans.

• Strong communication skills in executive, business, audit, and technical contexts.

• Bachelor’s degree in cybersecurity, information technology, information systems, business, accounting, or a related field, or an equivalent combination of education and relevant experience.

• This position is not eligible for immigration sponsorship.


🏝️ Benefits

• Comprehensive benefits that promote physical, financial, emotional, and social well-being.

• Incentive compensation plan based on company, line of business, and/or individual performance.

• Differentiated compensation offerings.

• Employee and family benefits programs.

People also viewed

Ascensus19 hours ago

Senior Compliance Consultant

US flagFlorida OnlyFull-timeCompliance
ApplyView job
Gainwell Technologies20 hours ago

Compliance Advisor

US flagTexas OnlyFull-timeCompliance$90.9k – $129.9k/year
ApplyView job
Gainwell Technologies20 hours ago

Compliance Advisor

US flagUnited States OnlyFull-timeCompliance$90.9k – $129.9k/year
ApplyView job
Gainwell Technologies20 hours ago

Compliance Advisor

US flagUnited States OnlyFull-timeCompliance$90.9k – $129.9k/year
ApplyView job
Gainwell Technologies20 hours ago

Compliance Advisor

US flagTexas OnlyFull-timeCompliance$90.9k – $129.9k/year
ApplyView job
Avalyn Pharma20 hours ago

Senior Manager, Regulatory Affairs

US flagUnited States OnlyFull-timeCompliance$157k – $173k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers