# Product Manager: Security

**Company:** [CodeRabbit](https://hotfix.jobs/companies/coderabbit)
**Location:** Bengaluru, India
**Role:** Product Management
**Experience:** 5+ years
**Skills:** SAST, DAST, Secrets Scanning, Infrastructure As Code, Software Composition Analysis, Vulnerability Research, Application Security, Penetration Testing, Detection Engineering, LLMs, Agentic Systems, APIs, GitHub, GitLab, Bitbucket
**Posted:** 2026-08-20

> Own the direction and quality bar for an AI-driven application security scanner, shaping detection capabilities, findings workflows, and AppSec buyer adoption. Requires 5–8 years of security experience, strong technical product management skills, and deep knowledge of vulnerability detection and exploitation.

## Job Description

## Responsibilities
- Own the security product end to end, including deep codebase scans and security findings in pull request reviews.
- Set roadmap priorities across **SAST**, secrets detection, infrastructure-as-code misconfiguration, dependency, and supply-chain analysis.
- Define detection-quality standards, including precision, recall, severity, exploitability, and acceptable noise.
- Lead the findings experience: triage, dismissal and feedback loops, remediation flows, reporting, and severity grading.
- Translate benchmarks, evaluations, and real-world detection results into product decisions and customer-facing proof.
- Own the AppSec and CISO buyer perspective alongside developer users.
- Partner with Sales on enterprise security evaluations and competitive positioning.
- Shape pricing and packaging with Growth and Finance.
- Work daily with engineers building the agentic scanning pipeline and establish the quality bar for shipped detection changes.

## Requirements
- 5–8 years of experience in the security space through security product management or hands-on application security, penetration testing, vulnerability research, or detection engineering.
- Product management experience with deeply technical products, ideally in B2B SaaS or developer tools.
- Practical knowledge of vulnerability classes and exploitation, including the ability to evaluate severity and disputed false positives.
- Knowledge of SAST, DAST, secrets scanning, IaC security, and software composition analysis.
- Technical fluency sufficient to read code, understand APIs, and collaborate closely with engineers.
- Strong written and verbal communication skills, including experience writing PRDs and tickets.
- Ability to work through ambiguity, create clear specifications, and operate with high ownership.

## Nice-to-Haves
- Hands-on practitioner experience with CVEs, bug bounties, CTFs, or penetration-testing findings.
- Experience shipping products built on LLMs or agentic systems.
- Vendor-side experience in SAST, ASPM, or software composition analysis.
- Working knowledge of GitHub, GitLab, Bitbucket, or Azure DevOps.

## Compensation and Benefits
- Competitive salary, equity, and benefits.
- Professional development opportunities.
- Opportunity to work on cutting-edge technology with real-world impact in a collaborative environment.

## Similar jobs

- [Product Manager](https://hotfix.jobs/jobs/64f0aa7c-3daa-4178-946d-280de66c639e) - Origin - Bengaluru, India
- [Product Manager, Learn Chess with Dr. Wolf](https://hotfix.jobs/jobs/413de1b0-4411-4535-988d-a587c3123c86) - Chess.com - Remote
- [Technical Product Manager - RCM](https://hotfix.jobs/jobs/dffa3d75-6d8c-4915-9651-2fabda96ea75) - Flaglerhealth - Remote
- [Senior Product Manager, Fintech](https://hotfix.jobs/jobs/ba666e00-d366-4bf7-a0e4-742c1c547442) - LeafLink - Remote - $115k – $155k/yr
- [Senior Product Manager - AI/ML](https://hotfix.jobs/jobs/b05be6f3-56ef-46bf-b673-13f1d10ab6c1) - Clickhouse - Remote - $170k – $242k/yr

**Apply:** https://hotfix.jobs/jobs/af779600-cf5b-4ab0-8477-b81e5fee9daf
**Canonical:** https://hotfix.jobs/jobs/af779600-cf5b-4ab0-8477-b81e5fee9daf