# Senior Manager, Product Security

**Company:** [Tines](https://hotfix.jobs/companies/tines)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 8+ years
**Skills:** Application Security, Product Security, Secure Architecture, Threat Modeling, Owasp Top 10, Secure Sdlc, Ai Security, AWS, Docker, Kubernetes, SAST, DAST, Sca, DevSecOps, Tines
**Posted:** 2026-08-27

> Leads and scales the product security program for cloud-native, AI-powered SaaS products, combining strategy, team leadership, secure architecture, vulnerability management, and hands-on technical execution. Requires 8+ years in application or product security and significant people-management or technical-leadership experience.

## Job Description

## Responsibilities
- Define and execute the product security strategy, roadmap, operating model, and success metrics.
- Hire, manage, mentor, and develop product security engineers.
- Partner with engineering, product, infrastructure, legal, compliance, and executive stakeholders.
- Establish secure software development lifecycle practices, including security requirements, architecture reviews, threat modeling, testing, and remediation.
- Use AI and automation for security review, vulnerability triage, risk identification, and agentic security workflows.
- Identify and mitigate risks in AI-powered products and systems, including prompt injection, data leakage, model abuse, excessive agency, and insecure tool use.
- Guide secure cloud-native, multi-tenant architectures and platform controls.
- Develop risk management and prioritization frameworks.
- Own vulnerability management, including internal findings, customer reports, penetration tests, vulnerability disclosure, and bug bounty submissions.
- Build secure-by-default tooling, paved roads, CI/CD integrations, and automated controls.
- Lead product security activities during incidents and drive post-incident improvements.
- Develop security champions, training, documentation, and technical guidance.
- Measure and communicate product security effectiveness, risks, investments, and tradeoffs.
- Support customer and partner security conversations and independent security assessments.

## Requirements
- 8+ years of experience in application security, product security, or related security engineering roles, including securing cloud-native SaaS products.
- 5+ years of people management or technical leadership experience.
- Experience defining product security strategy and executable roadmaps based on business and technical risk.
- Strong foundation in application security, secure architecture, threat modeling, OWASP Top 10, and secure SDLC practices.
- Experience partnering with engineering and product leaders to deliver security outcomes.
- Experience using AI and automation to scale security programs.
- Experience securing cloud environments, preferably AWS, and containerized infrastructure with Docker and Kubernetes.
- Working knowledge of modern programming languages and the ability to evaluate code, architecture, and technical designs.
- Experience with application security testing and vulnerability management technologies, including SAST, DAST, SCA, secrets detection, and CI/CD security integrations.
- Strong understanding of DevSecOps and secure-by-default developer workflows.
- Experience coordinating product security incident response.
- Excellent written and verbal communication skills.
- Experience operating a vulnerability disclosure or bug bounty program.
- Strong judgment, analytical thinking, organizational skills, and an empathetic, accountable leadership style.

## Nice to Haves
- Experience building product security teams or programs during rapid growth.
- Experience securing AI/ML systems and LLM-powered features.
- Familiarity with LLM red-teaming, MITRE ATLAS, and the OWASP Top 10 for LLM Applications.
- Experience building agentic or automated security workflows using Tines or a similar platform.
- Experience with Ruby, TypeScript, and/or Rust.

## Similar jobs

- [SOC Lead](https://hotfix.jobs/jobs/1b4ce51d-67b7-4000-a328-a6f0e74f22a6) - Idme - McLean, VA - $96k – $112k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/9286e91d-ca35-4449-bb47-da0dc51b2aaa) - ConductorOne - Remote - $100k – $200k/yr
- [Security GRC Lead](https://hotfix.jobs/jobs/2eb261b0-5ff9-435d-b0fb-eaf5933051d1) - Mercor - San Francisco, CA - $350k – $425k/yr
- [Lead, Security Controls Assurance - SOX](https://hotfix.jobs/jobs/a1c11627-c920-4e31-abc6-2e170042a626) - Anthropic - San Francisco, CA - $410k – $510k/yr
- [Senior Platform Security Engineer](https://hotfix.jobs/jobs/3ac667bf-62fa-4280-8ccb-2af3468d8579) - Discord - $196k – $245k/yr

**Apply:** https://hotfix.jobs/jobs/87d3d264-489e-43d4-880a-682cc34daaa0
**Canonical:** https://hotfix.jobs/jobs/87d3d264-489e-43d4-880a-682cc34daaa0