Skip to content
ChimeChime

Manager, Product Security

Leads a team securing cloud infrastructure, sensitive data, and AI systems in products. Influences engineering roadmaps, embeds security in designs, and manages AI risks like prompt injection and data leakage. Requires 5+ years security engineering and 2+ years leading engineers.

About the job

Responsibilities

  • Own the security posture of cloud infrastructure, data systems, and AI-enabled applications across product surfaces
  • Influence data, ML, and infrastructure team roadmaps and drive alignment on security priorities without direct authority
  • Partner with engineering and product teams to embed security into system design and development workflows
  • Lead and grow a team of security engineers, setting a high bar for technical execution, ownership, and impact
  • Define and execute strategy for securing cloud-native architectures and sensitive data at scale
  • Establish guardrails and secure design patterns for AI adoption, including safe integration of third-party and internal AI systems
  • Identify and mitigate risks related to AI systems, including prompt injection, data leakage, and misuse of models or APIs
  • Build scalable controls and automation around identity, access, encryption, and data protection
  • Operate effectively within a POD model, shifting focus across security domains based on business needs
  • Lead and support response efforts for security incidents related to cloud, data, and AI risks

Requirements

  • 5+ years of experience in security engineering, with significant experience in cloud and/or data security
  • 2+ years of experience managing or leading security engineers
  • Strong understanding of cloud platforms (AWS, GCP), Infrastructure as Code (IaC), and modern infrastructure patterns
  • Experience designing or securing systems that handle sensitive or regulated data
  • Experience securing or evaluating AI/ML systems, or demonstrated ability to operate effectively in ambiguous and emerging security domains
  • Strong technical judgment and the ability to go deep in architecture and security discussions when needed
  • Experience operating in fast-paced, product-driven environments with shifting priorities
  • Strong communication skills with the ability to translate security risks into business impact

Compensation

Base salary $152,000 - $210,000, plus bonus, equity, and benefits.

Skills

AWS, GCP, Infrastructure As Code, Ai Security, Ml Security, Cloud Security, Data Security, Identity Management, Access Control, Encryption, Prompt Injection Mitigation, Data Leakage Prevention

Figma

Figma

United States

Federal Compliance Manager
$153k+/yrRemote5+ YOESecurity Engineering

Manages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.

Modal

Modal

New York, NY

Detection And Response Engineer
$150k+/yrOn-siteSecurity Engineering

Build automated detection, investigation, and incident-response systems for a cloud-native platform. The role requires strong software engineering, security incident investigation, cloud infrastructure, Kubernetes, Linux, networking, and SQL experience, with opportunities to apply LLMs to security operations.

Vannevar

Vannevar

United States

Application Security Engineer
$160k+/yrRemote5+ YOESecurity Engineering

The Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.

Wiz

Wiz

Washington, DC

Cyber Threat Intel Analyst
$160k+/yrOn-site3+ YOESecurity Engineering

The Cyber Threat Intel Analyst tracks, investigates, attributes, and reports on advanced threats targeting cloud, AI, and developer environments. The role requires at least three years of security or threat research experience and strong technical analysis and writing skills.

Fireworks AI

Fireworks AI

San Mateo, CA

GRC Analyst
$160k+/yrOn-site3+ YOESecurity Engineering

The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.