← Все вакансии/Senior/Tines
SeniorRemoteUnited States (Remote)

Senior Manager, Product Security

T
Tines
Уровень
Senior
Формат
Remote
О роли

Описание вакансии

About the Role

We're seeking a Senior Manager, Product Security to lead and scale our product security program in an AI-forward engineering environment. Reporting to our Head of IT Operations & Information Security, you’ll be responsible for setting the direction of product security, developing a high-performing team, and partnering with engineering and product leaders to ensure security keeps pace with our growth.

This is a hands-on leadership role for someone who can move fluidly between strategy, people management, and technical execution. You’ll establish priorities based on risk, create scalable security processes and guardrails, and help teams make sound security decisions without introducing unnecessary friction.

A core part of this role is using AI and automation as force multipliers, building a product security program that can match the velocity of AI-assisted development while addressing the risks introduced by AI-powered products, agentic systems, and rapidly evolving engineering practices.

This position can be based remotely in the United States.

Key Responsibilities
  • Product Security Strategy: Define and execute the product security strategy, roadmap, operating model, and success metrics in alignment with company objectives and product risk.
  • Team Leadership: Hire, manage, mentor, and develop product security engineers, creating a culture of technical excellence, accountability, curiosity, and sustainable execution.
  • Cross-Functional Partnership: Build strong relationships with engineering, product, infrastructure, legal, compliance, and executive stakeholders. Influence product and architectural decisions through clear, risk-based guidance.
  • Secure Product Development: Establish scalable security practices throughout the software development lifecycle, including security requirements, architecture reviews, threat modeling, testing, and remediation.
  • AI-Augmented Security: Use AI and automation to expand product security coverage and reduce manual toil, including automated review, vulnerability triage, risk identification, and agentic security workflows.
  • AI Product Security: Partner with product and engineering teams to identify and mitigate risks in AI-powered features and systems, including prompt injection, data leakage, model abuse, excessive agency, and insecure tool use.
  • Security Architecture: Guide the design and implementation of secure architectures and platform controls that support a growing portfolio of cloud-native, multi-tenant products.
  • Risk Management and Prioritization: Develop a consistent framework for identifying, communicating, prioritizing, and accepting product security risks. Ensure engineering effort is focused on the issues that matter most.
  • Vulnerability Management: Own the product vulnerability management lifecycle, including internal findings, customer reports, penetration tests, vulnerability disclosure, and bug bounty submissions. Drive timely, risk-based remediation.
  • Security Automation and Developer Enablement: Build or sponsor secure-by-default tooling, paved roads, and automated controls using Tines, CI/CD integrations, and AI-driven capabilities.
  • Security Incident Response: Serve as a product security leader during incidents, coordinate technical investigation and remediation, participate in the on-call program, and ensure lessons learned result in durable improvements.
  • Security Education and Culture: Develop security champions, training, documentation, and technical guidance that help engineering teams independently make secure decisions, including when using AI-assisted development tools.
  • Program Measurement and Communication: Establish meaningful measures of product security effectiveness and communicate risks, investments, progress, and tradeoffs clearly to technical and executive audiences.
  • External Security Engagement: Support customer and partner security conversations, coordinate independent security assessments, and represent Tines in relevant security communities where appropriate.
Qualifications
  • 8+ years of experience in application security, product security, or closely related security engineering roles, including experience securing cloud-native SaaS products.
  • 5+ years of people management or technical leadership experience, with a track record of developing engineers and building effective security teams or programs.
  • Demonstrated ability to define product security strategy, translate strategy into an executable roadmap, and prioritize investments based on business and technical risk.
  • Strong technical foundation in modern application security, secure architecture, threat modeling, OWASP Top 10, and secure SDLC practices.
  • Experience partnering with engineering and product leaders to deliver security outcomes without creating unnecessary fric
Стек и навыки

С чем работаем