
Product Security Lead
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in Canada, +1 more country.
• Establish, develop, and oversee Miovision’s Product Security division, encompassing its vision, roadmap, and operational framework.
• Provide guidance to the CISO, Product, and Engineering leadership teams.
• Integrate security-by-design principles into the engineering development process.
• Direct threat modeling efforts, secure design evaluations, and architectural risk analyses.
• Collaborate with the Engineering team to implement secure coding practices and security checkpoints in the CI/CD pipeline.
• Shape cloud and platform architecture by utilizing strategies such as network segmentation, least-privilege access, resilience, and defense-in-depth.
• Manage product-level risk assessment and oversee the vulnerability management process for product code, APIs, cloud services, and embedded components.
• Supervise penetration testing activities and track remediation efforts.
• Work alongside GRC, Sales, and RevOps on RFPs, RFIs, and customer security evaluations.
• Act as a technical expert in discussions with customers.
• Convert ISO 27001, SOC 2, NIST, and Tx-RAMP standards into actionable product-level security controls.
• Partner with Security Operations and Cloud Ops to enhance product telemetry, logging, secure default deployment patterns, and incident-response integration.
• Significant technical expertise in application security, product security, secure engineering, or cloud security, preferably in SaaS or critical-infrastructure sectors.
• Practical experience implementing Secure Software Development Lifecycle methodologies.
• Familiarity with SAST/DAST integration, threat modeling, and automated security gates within contemporary CI/CD pipelines.
• Proficient in mapping security controls to ISO 27001, SOC 2, NIST CSF / 800-53.
• Working knowledge of NIST SP 800-82 (OT/ICS Security).
• Demonstrated success in securing connected devices, IoT, or OT-related systems.
• Strong knowledge of cloud-native architectures, preferably AWS, along with APIs and microservices.
• Capability to influence senior engineers and product leaders without direct supervision.
• Skill in articulating technical risks to auditors, executives, and non-technical stakeholders.
• Analytical mindset coupled with outstanding critical-thinking abilities.
• Hands-on experience with the OWASP security tool suite and CISA Cyber Security Evaluation Tool (CSET).
• Comprehensive health benefits.
• 24/7 access to virtual healthcare.
• Dedicated wellness programs.
• RRSP/401K Matching Plan.
• Variable Incentive Plan.
• Unique Mio-Days.
• Flexible vacation policy.
• Flexible work arrangements.
• Internet subsidy.
• Remote work allowance.
• Enhanced leave for new parents.
• Equity opportunities.
• Bonus incentives.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.