Remote job
Senior Director, Product Security
Job details
About this role
Role overview Lead a product security organization responsible for embedding security, trust, and risk reduction throughout an enterprise software platform. The role combines technical leadership, program ownership, and cross-functional partnership across product, engineering, technology, and digital teams, with accountability for secure delivery from planning through production maintenance.
Responsibilities - Own and evolve the product security program, including security-by-design practices, controls, processes, and risk reduction priorities. - Integrate security into the full software development lifecycle, including architecture, implementation, testing, deployment, and maintenance. - Direct secure coding standards, design reviews, threat modeling, code review practices, developer libraries, and security champions. - Build security into CI/CD pipelines through automated scanning, testing, compliance checks, gating, code-integrity controls, and remediation workflows. - Lead security engineers and architects embedded with product and technology teams, creating practical paved paths that support business delivery. - Translate technical risk into business impact and communicate priorities, trade-offs, and recommendations to senior stakeholders.
Requirements - 12+ years in product security, application security, or closely related security and engineering disciplines, including 8+ years in highly technical leadership roles. - Bachelor’s degree in computer science, cybersecurity, risk management, or a related technical field. - Experience designing and leading product security programs spanning secure architecture, threat modeling, secure coding, tooling, vulnerability management, SDLC, CI/CD, automation, and remediation. - Knowledge of common software and API vulnerabilities, open-source and software-supply-chain risks, and methods for coordinating remediation across product and engineering teams. - Experience introducing, improving, or replacing security tooling such as static and dynamic analysis, vulnerability scanning, and pipeline controls. - Ability to work effectively with cross-functional leaders and explain complex security concerns in clear business terms.
Benefits and work setup Hybrid role requiring access to an office, with a weekly in-office expectation of at least two days, subject to team and local requirements.