Remote job
Manager, Product Security Engineering
Job details
About this role
Role overview
Lead a product security engineering team while remaining hands-on as a practicing security engineer, splitting time roughly evenly between people leadership and individual technical contribution. The role is anchored in driving certification, accreditation, and hardening efforts such as DISA STIGs, SOC 2, and ISO 27001, while guiding a team that hunts and patches vulnerabilities in commercial cybersecurity products.
Responsibilities
- Manage, mentor, and grow the product security engineering team, covering hiring, career development, and performance management for engineers at multiple levels - Personally own and drive certification and accreditation initiatives, including DISA STIG hardening and authorization packages, SOC 2, and ISO 27001 - Translate technical strategy into an executable roadmap and hold the team accountable to delivery - Contribute directly to vulnerability remediation, SAST/DAST tooling, security assessments, and PSIRT response alongside the team - Prioritize and track vulnerability hunting and patching work, including novel zero-day issues, aligned with certification deadlines and customer commitments - Coordinate with Compliance, Legal, and Sales Engineering to respond to customer security questionnaires, audits, and certification renewals - Track and report on certification posture, audit readiness, and vulnerability remediation SLAs to engineering leadership
Requirements
- Five or more years of direct cybersecurity or product security experience - One to two or more years managing or leading a team of security engineers, or demonstrated player-coach experience - Direct, hands-on experience obtaining or maintaining compliance certifications such as SOC 2 Type II, ISO 27001, FedRAMP, or similar, and DISA STIG hardening and authorization processes - Experience with SAST/DAST implementation and integrating security tooling into CI/CD pipelines - Experience with security in cloud (AWS, Azure, GCP), on-premise, and virtualized environments - Excellent communication and cross-functional collaboration skills, comfortable representing product security to Compliance, Legal, Sales, and customers
Nice to have
- Knowledge of ICS/OT security
Benefits and work setup
- Remote-first role - Salary: $220,000, plus a competitive equity package and a comprehensive benefits plan