
Senior Product Manager, Application Security
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in California.
• Take charge of the Application Security product strategy and create a multi-quarter roadmap that encompasses visibility, tooling inventory, architecture, risk-surface mapping, procurement, CI/CD enforcement, threat mitigation, Security Champions, architecture reviews, and executive reporting.
• Develop and deliver AI-driven threat modeling and code evaluation features along with a consolidated security risk, signal, and remediation platform.
• Focus on prioritizing critical risk surfaces throughout the Zeta platform.
• Specify requirements, user stories, success metrics, and acceptance criteria for Application Security capabilities.
• Facilitate execution by collaborating with Application Security engineering, platform/DevOps, Architecture, InfoSec, and product engineering teams.
• Implement governance for severity and SLAs, incident intake and escalation, secure coding standards, third-party application integrations, and architecture security assessments.
• Direct AppSec tool strategy and procurement choices, covering risk justification, identifying coverage gaps, budget considerations, and developer-workflow integration.
• Utilize data and KPIs to evaluate security posture and guide prioritization efforts.
• Ensure alignment of AppSec initiatives with company goals while communicating risk, progress, and requests to engineering and executive stakeholders.
• Recognize and mitigate delivery and security risks; conduct post-incident learning sessions.
• Mentor AppSec and related product/engineering colleagues and support the expansion of a Security Champions program.
• Leverage AI tools in product initiatives and defensively apply AI for threat modeling, triage, code review, and remediation guidance with human oversight.
• 4-6+ years of experience in product management with significant responsibility for enterprise Application Security, platform security, DevSecOps, or related security-product areas in SaaS/B2B contexts.
• Comprehensive understanding of contemporary AppSec practices and tools, including SAST, DAST, SCA, container/IaC/secrets scanning, vulnerability management, threat modeling, API security, and secure SDLC.
• Capability to drive enterprise-level security programs, focusing on risk-based prioritization, remediation SLAs, cross-organizational governance, and executive communication regarding risks.
• Strong technical background, ideally with a degree in Computer Science or a related field, though not mandatory.
• Established credibility with security engineers, architects, and engineering leaders concerning authentication/authorization, multi-tenancy, cryptography boundaries, supply chain, and AI/LLM security risks.
• Experience in delivering security products or workflows aimed at developers, such as CI/CD gates, IDE/MR integrations, security dashboards, or remediation orchestration.
• Exceptional communication skills and the ability to influence stakeholders across Engineering, InfoSec, DevOps/Infrastructure, Architecture, and leadership levels.
• Aptitude for working independently in ambiguous situations while developing sustainable processes, metrics, and operational rhythms.
• Preferred: Experience with AI-enhanced security capabilities.
• Preferred: Familiarity with MarTech/AdTech or large-scale multi-tenant platforms managing sensitive customer information.
• Preferred: Background in evaluating AppSec tools and vendor management, including Snyk, Wiz, Rapid7, or similar products.
• Unlimited PTO
• Comprehensive medical, dental, and vision coverage
• Employee Equity
• Employee Discounts
• Virtual Wellness Classes
• Pet Insurance
Sapio Sciences LLC
Mercor
Mercor
RealPage, Inc.
Get handpicked remote jobs straight to your inbox weekly.