Senior Manager, Product Security
Leads and scales the product security program for cloud-native, AI-powered SaaS products, combining strategy, team leadership, secure architecture, vulnerability management, and hands-on technical execution. Requires 8+ years in application or product security and significant people-management or technical-leadership experience.
About the job
Responsibilities
- Define and execute the product security strategy, roadmap, operating model, and success metrics.
- Hire, manage, mentor, and develop product security engineers.
- Partner with engineering, product, infrastructure, legal, compliance, and executive stakeholders.
- Establish secure software development lifecycle practices, including security requirements, architecture reviews, threat modeling, testing, and remediation.
- Use AI and automation for security review, vulnerability triage, risk identification, and agentic security workflows.
- Identify and mitigate risks in AI-powered products and systems, including prompt injection, data leakage, model abuse, excessive agency, and insecure tool use.
- Guide secure cloud-native, multi-tenant architectures and platform controls.
- Develop risk management and prioritization frameworks.
- Own vulnerability management, including internal findings, customer reports, penetration tests, vulnerability disclosure, and bug bounty submissions.
- Build secure-by-default tooling, paved roads, CI/CD integrations, and automated controls.
- Lead product security activities during incidents and drive post-incident improvements.
- Develop security champions, training, documentation, and technical guidance.
- Measure and communicate product security effectiveness, risks, investments, and tradeoffs.
- Support customer and partner security conversations and independent security assessments.
Requirements
- 8+ years of experience in application security, product security, or related security engineering roles, including securing cloud-native SaaS products.
- 5+ years of people management or technical leadership experience.
- Experience defining product security strategy and executable roadmaps based on business and technical risk.
- Strong foundation in application security, secure architecture, threat modeling, OWASP Top 10, and secure SDLC practices.
- Experience partnering with engineering and product leaders to deliver security outcomes.
- Experience using AI and automation to scale security programs.
- Experience securing cloud environments, preferably AWS, and containerized infrastructure with Docker and Kubernetes.
- Working knowledge of modern programming languages and the ability to evaluate code, architecture, and technical designs.
- Experience with application security testing and vulnerability management technologies, including SAST, DAST, SCA, secrets detection, and CI/CD security integrations.
- Strong understanding of DevSecOps and secure-by-default developer workflows.
- Experience coordinating product security incident response.
- Excellent written and verbal communication skills.
- Experience operating a vulnerability disclosure or bug bounty program.
- Strong judgment, analytical thinking, organizational skills, and an empathetic, accountable leadership style.
Nice to Haves
- Experience building product security teams or programs during rapid growth.
- Experience securing AI/ML systems and LLM-powered features.
- Familiarity with LLM red-teaming, MITRE ATLAS, and the OWASP Top 10 for LLM Applications.
- Experience building agentic or automated security workflows using Tines or a similar platform.
- Experience with Ruby, TypeScript, and/or Rust.
Skills
Application Security, Product Security, Secure Architecture, Threat Modeling, Owasp Top 10, Secure Sdlc, Ai Security, AWS, Docker, Kubernetes, SAST, DAST, Sca, DevSecOps, Tines
Similar jobs
Security Engineering jobsLeads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.
Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.
Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.
Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.
Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.