
Senior Manager, Product Security
Posted Aug 27

Posted Aug 27
This is a fully remote position, open to applicants in United States.
β’ Develop and implement the strategy, roadmap, operating model, and success metrics for product security.
β’ Recruit, manage, mentor, and nurture the growth of product security engineers.
β’ Collaborate with engineering, product, infrastructure, legal, compliance, and executive stakeholders.
β’ Implement security practices throughout the software development lifecycle, which includes security requirements, architecture reviews, threat modeling, testing, and remediation.
β’ Leverage AI and automation for automated reviews, vulnerability triage, risk identification, and agentic security workflows.
β’ Identify and mitigate risks associated with AI-powered features and systems.
β’ Provide guidance on secure architectures and platform controls for cloud-native, multi-tenant products.
β’ Create frameworks for identifying, communicating, prioritizing, and accepting product security risks.
β’ Oversee the product vulnerability management lifecycle and facilitate risk-based remediation.
β’ Develop or support secure-by-default tooling, paved roads, and automated controls utilizing Tines, CI/CD integrations, and AI-driven capabilities.
β’ Direct product security initiatives during incidents, coordinating investigation and remediation efforts, participating in the on-call program, and applying lessons learned.
β’ Cultivate security champions, training programs, documentation, and technical guidance.
β’ Establish measures for product security effectiveness and communicate risks, investments, progress, and tradeoffs.
β’ Assist in security discussions with customers and partners and coordinate independent security assessments.
β’ Over 8 years of experience in application security, product security, or related security engineering roles, with a focus on securing cloud-native SaaS products.
β’ At least 5 years of experience in people management or technical leadership.
β’ Proven ability to define product security strategy, convert strategy into an actionable roadmap, and prioritize investments based on business and technical risks.
β’ Strong technical expertise in modern application security, secure architecture, threat modeling, OWASP Top 10, and secure SDLC practices.
β’ Experience collaborating with engineering and product leaders to achieve security objectives.
β’ Familiarity with utilizing AI and automation to enhance security programs.
β’ Experience securing cloud environments, ideally AWS, and containerized infrastructure using Docker and Kubernetes.
β’ Proficient in modern programming languages with the ability to assess code, architecture, and technical designs.
β’ Experience with application security testing and vulnerability management tools, including SAST, DAST, SCA, secrets detection, and CI/CD security integrations.
β’ Strong understanding of DevSecOps practices and secure-by-default developer workflows.
β’ Experience leading or managing product security incident responses.
β’ Excellent written and verbal communication skills.
β’ Background in operating a public vulnerability disclosure or bug bounty program.
β’ Strong judgment, analytical skills, and organizational abilities.
β’ Leadership style based on trust, clarity, empathy, accountability, and technical engagement.
β’ Must have authorization to work for any employer in the U.S.; visa sponsorship is not available.
β’ Equity
β’ Equal employment opportunities
CrowdStrike
Deque Systems, Inc
Deque Systems, Inc
Precision eControl
Get handpicked remote jobs straight to your inbox weekly.