About the company
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Manager, Product Security based in United States.
The Senior Manager, Product Security will lead and scale a modern product security program within a fast-moving, AI-forward engineering environment.
Responsibilities
- Define and execute the product security strategy, roadmap, operating model, priorities, and success metrics in alignment with organizational objectives and product risk.
- Lead, hire, mentor, and develop product security engineers while establishing a culture centered on technical excellence, accountability, curiosity, trust, and sustainable execution.
- Partner with Engineering, Product, Infrastructure, Legal, Compliance, and executive stakeholders to influence product and architecture decisions through practical, risk-based security guidance.
- Establish scalable security practices across the software development lifecycle, including security requirements, architecture reviews, threat modeling, security testing, remediation, and secure-by-default development.
- Use AI and automation to expand security coverage and reduce manual work through capabilities such as automated security reviews, vulnerability triage, risk identification, and agentic security workflows.
- Partner with product and engineering teams to identify and mitigate security risks associated with AI-powered features and systems, including prompt injection, data leakage, model abuse, excessive agency, and insecure tool use.
- Guide secure architecture and platform controls for cloud-native, multi-tenant products, APIs, integrations, and workflow systems.
- Establish consistent frameworks for identifying, communicating, prioritizing, and accepting product security risks so engineering resources remain focused on the highest-impact issues.
- Own the product vulnerability management lifecycle, including internal findings, customer reports, penetration tests, vulnerability disclosure, and bug bounty submissions, while driving timely risk-based remediation.
- Build or sponsor secure developer tooling, automated controls, CI/CD integrations, paved roads, and reusable security workflows that make secure development easier and more efficient.
- Provide product security leadership during security incidents, coordinating investigations, remediation, stakeholder communications, on-call participation, and post-incident improvements.
- Develop security champions, training programs, documentation, and technical guidance that enable engineering teams to make secure decisions independently, including when using AI-assisted development tools.
- Establish meaningful product security metrics and communicate risks, investments, progress, and tradeoffs effectively to technical and executive audiences.
- Support customer and partner security discussions, independent security assessments, and relevant external security engagements.
Requirements
- 8+ years of experience in application security, product security, or closely related security engineering roles, including experience securing cloud-native SaaS products.
- 5+ years of people management or technical leadership experience, with demonstrated success developing engineers and building effective security teams or programs.
- Strong experience defining product security strategy, translating strategy into actionable roadmaps, and prioritizing investments according to business and technical risk.
- Deep technical knowledge of modern application security, secure architecture, threat modeling, OWASP Top 10, and secure SDLC practices.
- Proven ability to partner with Engineering and Product leadership to deliver meaningful security outcomes without creating unnecessary friction.
- Experience using AI and automation to scale security programs, including LLM-assisted code review, automated vulnerability triage, or agentic security workflows.
- Experience securing cloud environments, preferably AWS, as well as containerized infrastructure using technologies such as Docker and Kubernetes.
- Working knowledge of modern programming languages and the ability to evaluate application code, architecture, and technical designs; experience with Ruby, TypeScript, and/or Rust is highly desirable.
- Experience with application security testing and vulnerability management technologies, including SAST, DAST, SCA, secrets detection, and CI/CD security integrations.
- Strong understanding of DevSecOps and experience designing secure-by-default developer workflows.
- Experience leading or coordinating product security activities during incident response, including technical investigation, stakeholder communication, and post-incident improvement.
- Excellent written and verbal communication skills, with the ability to explain technical risks, business impact, priorities, and tradeoffs to engineers, technical leaders, and executives.
- Experience operating a public vulne