About the company
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Manager, Product Security Engineering based in United States.
Responsibilities
- Manage, mentor, and develop a product security engineering team, including senior-level security professionals, through hiring, coaching, career development, and performance management.
- Own and drive certification and accreditation initiatives, including SOC 2, ISO 27001, DISA STIG hardening, authorization processes, and other customer or regulatory requirements.
- Translate security strategies into actionable roadmaps, priorities, and measurable delivery plans while maintaining alignment with engineering objectives.
- Remain hands-on by contributing to vulnerability remediation, security assessments, SAST/DAST implementation, security tooling improvements, and incident response activities.
- Guide vulnerability management efforts, including identifying and addressing advanced vulnerabilities and ensuring remediation work aligns with business priorities and compliance deadlines.
- Partner with Compliance, Legal, Sales Engineering, and customer teams to support security questionnaires, audits, certification renewals, and customer assurance activities.
- Establish efficient evidence collection, documentation, and reporting processes to maintain audit readiness.
- Track and communicate certification status, vulnerability remediation progress, and security performance metrics to engineering leadership.
- Foster collaboration across engineering teams and promote strong security practices throughout the product development lifecycle.
Requirements
- 5+ years of direct experience in cybersecurity, product security, or related security engineering roles.
- 1–2+ years of experience managing, leading, or mentoring security engineers, or demonstrated player-coach leadership experience.
- Proven experience obtaining or maintaining security certifications and compliance programs such as SOC 2 Type II, ISO 27001, FedRAMP, or similar frameworks.
- Hands-on experience with DISA STIG hardening, authorization processes, or security accreditation initiatives.
- Experience implementing SAST/DAST tools and integrating security practices into CI/CD pipelines.
- Strong understanding of security principles across cloud environments (AWS, Azure, GCP), on-premise infrastructure, and virtualized environments.
- Ability to balance people management responsibilities with individual technical contributions.
- Strong communication skills with the ability to collaborate effectively with engineering, compliance, legal, sales, and customer-facing teams.
- Experience working within Agile development environments and cross-functional product organizations.
- Knowledge of industrial control systems (ICS) or operational technology (OT) security is a plus.
- Strong problem-solving skills, ownership mindset, and ability to drive initiatives independently.
Conditions
- Competitive salary of $220,000.
- Competitive equity package.
- Comprehensive benefits plan.
- Remote-first work environment with flexibility and autonomy.
- Opportunity to lead impactful cybersecurity initiatives protecting essential infrastructure.
- Ability to influence product security strategy and build scalable security practices.
- Collaborative culture built around transparency, trust, and technical excellence.
- Opportunity to work with talented cybersecurity professionals across global teams.