
Product Security Lead
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Collaborate with product, engineering, architecture, and data leaders to develop secure solutions from the beginning.
• Evaluate the security of composite business platforms, which include SaaS applications, custom-developed tools, API integrations, data flows, and AI functionalities.
• Detect trust boundaries, sensitive data, and significant risks.
• Conduct architecture and threat assessments and document the results.
• Create and sustain reusable secure-by-design patterns for SaaS, APIs, integrations, data movement, credentials, authorization, and AI-based workflows.
• Convert intricate security requirements into straightforward, actionable designs.
• Promote security during vendor evaluations and SaaS selection processes.
• Evaluate vendor posture, identity, integrations, and data residency in collaboration with enterprise and procurement teams.
• Work with Security Platform Engineering to provide self-service security capabilities, automated guardrails, and scalable workflows.
• Collaborate with Identity & Access and Infrastructure on authentication, authorization, and posture management.
• Set up security protocols for AI-enabled products and workflows, including data boundaries, tool accessibility, prompt risks, and audit controls.
• Offer security expertise for enterprise data strategies, product onboarding, M&A activities, and technology adoption.
• Establish practical patterns for secure data flows and integrations.
• Act as a trusted advisor through office hours and embedded team engagements.
• Mentor teams to empower them to make informed security decisions without needing prior approvals.
• Provide extensive technical influence, mentorship, and leadership as a senior individual contributor.
• Bachelor’s degree in Computer Science, Engineering, Information Security, or equivalent experience.
• 8+ years of experience in security architecture, cloud/SaaS security, solutions architecture, engineering, or SRE/DevOps.
• A minimum of 4 years in a dedicated security position.
• Extensive experience in designing or securing distributed systems that include SaaS, APIs, custom applications, data integrations, and third-party services.
• Capability to quickly analyze unfamiliar architectures, identify security vulnerabilities, and propose practical solutions.
• Strong partnership skills with business, engineering, data, and architecture leaders.
• Ability to adapt security requirements to meet business needs and articulate trade-offs.
• Hands-on engineering or architectural background, complemented by business-facing experience, is preferred.
• Valued experience in SaaS- and integration-heavy environments or AI-enabled workflows.
• Familiarity with data security concepts, including classification, DLP, encryption, data lineage, and governance, is advantageous.
• Background in financial services, wealth management, regulated environments, or M&A-driven technology integration is beneficial.
• Security certifications such as CISSP, CCSP, CSSLP, or cloud security certifications are appreciated but not mandatory.
• Systems-thinking and technical depth across SaaS, APIs, cloud, integrations, data, and AI workflows.
• Excellent communication, facilitation, and documentation skills.
• Practical, enablement-oriented security mindset.
• Adaptability and curiosity.
• Must be legally authorized to work in the United States.
• Eligibility for bonuses/incentive programs.
• Additional compensation and/or benefits may be available.
• Opportunities for progressive advancement and professional development.
• Innovative workplace environment.
• Emphasis on work-life balance.
• Collaborative, forward-thinking teams.
• Diverse culture that supports career aspirations.
• Opportunities to contribute to the community.
AbbVie
Biogen
RunPod
MrBeast
Get handpicked remote jobs straight to your inbox weekly.