Skip to content

Product Security Manager

Own the full product security lifecycle for space communications systems, from threat modeling and secure architecture to penetration testing, vulnerability management, cryptography, and compliance with FedRAMP, CMMC, and NIST standards. Requires 5+ years of product/application security leadership, deep expertise in SAST/DAST, secrets management, CI/CD hardening, and applied cryptography; TS/SCI clearance eligibility required.

About the job

Responsibilities

  • Own application security across the full software development lifecycle, ensuring security requirements are defined, validated, and enforced from design through production release.
  • Conduct security architecture reviews and threat modeling for new product features, platform changes, and third-party integrations.
  • Establish and maintain secure coding standards, security review gates, and developer security training programs.
  • Serve as the primary security liaison for product engineering teams, translating compliance and security requirements into actionable engineering guidance.
  • Deploy, manage, and continuously improve SAST and DAST tooling integrated into development workflows.
  • Own the vulnerability management program end-to-end: discovery, triage, prioritization, remediation tracking, and reporting across product and infrastructure systems.
  • Conduct and coordinate penetration testing against products and infrastructure, including scoping, execution, findings management, and remediation validation.
  • Build and maintain container security scanning, dependency analysis, and SCA pipelines.
  • Integrate automated security validation and policy enforcement into CI/CD pipelines.
  • Own secrets management infrastructure, including deployment, policy configuration, access controls, and audit logging for platforms such as HashiCorp Vault.
  • Implement and enforce controls for secure artifact management, signing, and supply chain integrity across build and deployment pipelines.
  • Review and harden Infrastructure as Code, GitOps workflows, and deployment automation for security misconfigurations and policy violations.
  • Design and implement cryptographic controls for data at rest, data in transit, and satellite communication protocols, ensuring alignment with NIST standards and government customer requirements.
  • Evaluate and advise on cryptographic library selection, key management architecture, and certificate lifecycle management.
  • Identify and remediate cryptographic weaknesses across product systems.
  • Hire and develop product security engineers as the team scales.
  • Collaborate with network operations, mission management, and compliance teams.
  • Build security documentation, audit evidence, and reporting standards that satisfy FedRAMP, CMMC, and NIST 800-171 requirements.

Basic Qualifications

  • 5+ years in product security, application security, or a closely related security engineering discipline, with demonstrated technical leadership experience.
  • Deep expertise in SAST and DAST tooling, including tool selection, integration into CI/CD pipelines, and results-driven vulnerability remediation programs.
  • Hands-on experience conducting or coordinating penetration testing engagements, including scoping, execution, and remediation validation.
  • Strong applied cryptography knowledge, including symmetric and asymmetric encryption, PKI, key management, and secure protocol design.
  • Experience owning vulnerability management programs, including prioritization frameworks, SLA enforcement, and executive reporting.
  • Proficiency with secrets management platforms such as HashiCorp Vault, including policy design and access control architecture.
  • Experience securing CI/CD pipelines and GitOps workflows, including IaC security review and automated security gate implementation.
  • Proficiency in one or more general-purpose programming languages (Python, Go, Rust, or equivalent).
  • Familiarity with government compliance frameworks including NIST 800-171, CMMC, and FedRAMP.
  • Ability to obtain and maintain a TS/SCI clearance.
  • U.S. citizenship or status as a lawful permanent resident required to conform with ITAR export regulations.

Preferred Qualifications

  • Active TS clearance or higher.
  • Experience with HashiCorp Vault, Terraform, and ArgoCD in production environments.
  • Hands-on experience with container security scanning, admission controllers, and microservices security patterns.
  • Familiarity with software supply chain security frameworks and tooling (SLSA, Sigstore, SBOM generation).
  • Background in aerospace, defense, critical infrastructure, or other regulated industries.
  • Experience with DFARS compliance, ITAR, and government contracting security requirements.
  • Familiarity with eMASS or similar government assessment and authorization tools.
  • CISSP, CSSLP, OSCP, or equivalent professional certification.

Skills

Application Security, Threat Modeling, Penetration Testing, SAST, DAST, Vulnerability Management, Cryptography, Hashicorp Vault, Ci/Cd Security, GitOps, Terraform, Argo CD, Python, Go, Rust

DataVisor

DataVisor

Mountain View, CA

Security Engineer
$120k+/yrOn-site5+ YOESecurity Engineering

The Security Engineer will secure AWS and Google Cloud environments, monitor infrastructure, and assess AI/LLM deployments, MCP integrations, and agentic workflows. The role requires 5+ years of security engineering experience, including 2+ years in AI/ML security, plus cloud security and compliance expertise.

GameChanger

GameChanger

United States

Security Engineer, Application Security
$120k+/yrRemote3+ YOESecurity Engineering

The Security Engineer will lead application security across the SDLC, integrating DevSecOps controls, conducting threat modeling and secure code reviews, and managing application vulnerabilities. The role requires 3+ years of application security experience plus hands-on expertise with AWS, Kubernetes, IaC, CI/CD, and mobile or web security.

Plaid

Plaid

New York, NY
Security Analyst, Third-Party Ecosystem Risk Management
$119k+/yrHybrid4+ YOESecurity Engineering

Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.

Pinterest

Pinterest

United States

Security GRC Analyst
$124k+/yrRemote4+ YOESecurity Engineering

The Security GRC Analyst will manage security risks, policies, audits, control testing, and compliance reporting while partnering with technical and business stakeholders. The role requires 4+ years of GRC or security assurance experience and familiarity with major security frameworks.

Icarus

Icarus

El Segundo, CA

Network Engineer
$115k+/yrOn-site5+ YOESecurity Engineering

Own network engineering and government cybersecurity compliance for on-site and field-deployed aerospace systems. The role requires 5+ years of experience, end-to-end IATT/ATO experience, strong networking skills, and familiarity with DoD security frameworks and tactical communications.