Director of Product Security
Leads ID.me’s Product Security program and security engineering team, partnering with Product and Engineering to reduce risk through practical, developer-aligned controls. Requires strong technical depth across application and cloud security, outcome-based leadership, and experience building security programs in fast-moving cloud-native environments.
About the job
Responsibilities
- Own the Product Security program end to end, including threat modeling, secure code and architecture reviews, software composition analysis, secret scanning, vulnerability management, cloud security posture management, and configuration management.
- Integrate scalable, shift-left security controls across the secure software development lifecycle.
- Build, grow, and lead a team of security engineers, supporting their development, growth, and well-being.
- Define clear, outcome-oriented security requirements and enable Engineering teams to self-serve.
- Partner with Product and Engineering during design and architecture to implement secure-by-design practices.
- Build and maintain security tools and services that help engineers ship secure products efficiently.
- Own penetration testing and red-team execution, findings, scope, and remediation outcomes.
- Drive risk reduction and issue remediation to closure while applying practical, appropriately scoped security judgment.
- Champion AI-augmented security workflows and collaborate across Product Security, Security Operations, Governance, Risk and Compliance, IT, and Physical Security.
Requirements
- Demonstrated outcome-based leadership and accountability for security results.
- Experience partnering effectively with Engineering in a fast-moving environment.
- Technical depth in threat modeling, code and architecture review, SCA/SAST, secret scanning, vulnerability management, and cloud security posture management.
- Experience building or maturing an Application Security, Security Engineering, or Product Security program in a cloud-native environment.
- Experience with GCP, GitHub, Kubernetes/GKE, Apigee, Terraform, and modern CI/CD is strongly preferred.
- Experience with Socket.dev, Sysdig, Trivy, DependencyTrack, or HackerOne is strongly preferred.
- Experience with AI-augmented security workflows using Claude, Gemini, or Vertex AI is strongly preferred.
- Growth-stage experience building security programs rather than only maintaining them is strongly preferred.
Compensation and Benefits
- Annual base salary: $243,699–$271,644 USD.
- Base salary excludes bonus, equity, and benefits.
- Benefits include medical, dental, vision, health savings and flexible spending accounts, commuter benefits, life and disability insurance, 401(k) with company match, parental leave, paid time off, company holidays, employee assistance, pet insurance, learning and development benefits, and other wellbeing programs.
Skills
Threat Modeling, Application Security, Security Engineering, Vulnerability Management, Cloud Security Posture Management, Sca, SAST, Secret Scanning, GCP, GitHub, Kubernetes, Terraform, CI/CD, Penetration Testing, Red Team
Similar jobs
Security Engineering jobsLeads Exa’s company-wide security strategy, architecture, engineering, governance, incident response, and team development across AI infrastructure, cloud, products, and corporate systems. Requires executive-level security accountability and deep technical credibility in a rapidly scaling technology company.
Leads GameChanger’s Information Security and Technology strategy, teams, roadmap, and risk decisions, with primary focus on product and application security. Requires 10+ years of security experience, broad security-program leadership, and experience managing technical leaders and partnering with Engineering and executives.
Leads Chronograph’s information security and IT strategy, combining executive leadership with hands-on oversight of cloud, application, AI, corporate, and compliance security. Requires at least seven years of security experience, broad technical depth, assurance-program leadership, and strong executive communication.
Leads LogicGate’s internal security organization, compliance posture, risk management, and customer trust program while serving as Deputy CISO. Requires 7–10 years of information security experience, substantial people leadership, SaaS compliance expertise, and strong technical knowledge of modern security architectures.
Leads technical security, compliance (SOC 2, GDPR, ISO 42001), vulnerability management, and infrastructure hardening for a fast-growing fintech. Requires 3-7 years in security engineering with hands-on AWS, vuln tooling, and audit experience.