Director, Product Security
NULL NULL NULL NULL NULL NULL NULL NULL
full-time
Posted on:
Location Type: Remote
Location: North Dakota • United States
Visit company websiteExplore more
Salary
💰 $160,000 - $175,000 per year
Job Level
About the role
- Drive the multi‑year Product Security strategy, aligning roadmap priorities with product architecture, business goals, and customer trust requirements.
- Oversee security architecture for cloud‑native platforms, leading threat modeling, secure design reviews, and implementation of scalable security controls across the SDLC.
- Integrate DevSecOps and shift‑left practices, embedding SAST, DAST, SCA, and automated security testing into CI/CD pipelines in partnership with DevOps and engineering teams.
- Lead vulnerability management operations, including triage, remediation oversight, verification, bug bounty programs, and third‑party penetration testing.
- Ensure compliance with major security and privacy frameworks (SOC 2, ISO 27001, GDPR, HIPAA) and serve as the technical lead for customer security assessments, audits, and inquiries.
- Act as the executive technical representative for Tier‑1 customers, communicating architecture, threat modeling, SBOM/SCA findings, resilience, DR posture, and overall security assurance.
- Build and lead a high‑performing product security organization, providing coaching, performance management, and fostering a collaborative, high‑trust engineering culture.
- Maintain customer‑facing security documentation, including whitepapers, security portals, data residency details, encryption standards, and incident response posture.
Requirements
- 10+ years in Cybersecurity, with at least 5 years in a leadership role focused on Product or Application Security.
- Strong understanding of secure coding practices (OWASP Top 10), cloud security (AWS/GCP/Azure), and container orchestration (Kubernetes).
- B.S. or M.S. in Computer Science, Cybersecurity, or a related field (or equivalent practical experience).
- CISSP, CISM, or CSSLP preferred but not mandatory.
- Proficiency in secure SDLC/DevSecOps practices and in communicating security risk and controls to technical and non-technical stakeholders.
Benefits
- Competitive Benefits package – Eligibility starts the month after hire, with tiered options to choose from.
- Compensation Reviews, Career Growth Opportunities
- Flexible Remote Schedules
- Generous PTO Plans and Paid Holidays
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
Product Security strategysecurity architecturethreat modelingsecure design reviewsSASTDASTSCAautomated security testingvulnerability managementsecure coding practices
Soft Skills
leadershipcoachingperformance managementcommunicationcollaborationtrust building
Certifications
CISSPCISMCSSLP