Role Overview
We are looking for a senior security leader to define and scale end-to-end Product Security across modern cloud-native and AI-driven systems.
You will own security across the full lifecycle—from secure design and threat modeling, to DevSecOps pipeline security, to AI/LLM security governance, to vulnerability management and PSIRT operations.
This is a hands-on leadership role requiring deep technical expertise and the ability to influence engineering teams at scale while enabling fast, secure product delivery.
What You Will Own (Outcomes)
1. Secure-by-Design Engineering
- Define and enforce Secure SDLC standards across product engineering teams
- Lead architecture-level security reviews for high-risk systems and features
- Drive threat modeling (STRIDE / MITRE ATT&CK)
- Establish reusable secure design patterns (identity, secrets, crypto, data protection)
2. DevSecOps at Scale
- Embed security controls into CI/CD pipelines (shift-left + shift-right)
- Operationalize SAST / SCA / Secrets scanning / IaC security
- Implement DAST and runtime security validation
- Drive SBOM generation, artifact signing, and provenance controls
- Define release security gates and remediation SLAs
Embed security controls in CI/CD pipelines (pre-commit- deploy): SAST, SCA, secret scanning, IaC/K8s policy-as-code, SBOM generation, artifact signing and provenance.
- Operationalize DAST via Veracode integration patterns and developer runbooks; track fix SLAs, break-glass criteria, and remediation metrics.
- Partner with Cloud & Platform teams to ensure telemetry, detection, and incident hooks align with SOC/SIEM runbooks.
3. AI / LLM & Data Security
- Define and implement AI/ML and LLM security controls
- Secure AI lifecycle: training, inference, deployment
- Mitigate prompt injection, data leakage, and model abuse risks
- Enforce data protection via DLP frameworks (e.g., Microsoft Purview)
- Establish AI governance, lineage, and monitoring .
- Engineer AI security guardrails: prompt/input validation, output filtering, model abuse monitoring, adversarial testing (prompt injection, data exfiltration, hallucination risk), dataset/model lineage, and access controls.
- Integrate AI security tests into CI/CD pipelines and enforce Microsoft Purview DLP policies to prevent data leakage in AI-assisted development.
4. Product Security Incident Response (PSIRT)
- Lead vulnerability intake, triage, and coordinated disclosure
- Drive patching, remediation tracking, and customer communication
- Align PSIRT with supply chain and GRC frameworks
- Track KPIs (MTTR, vuln aging, exploitability, SBOM coverage)
5. Security Leadership & Metrics
- Define product security metrics and reporting
- Influence engineering leadership and drive adoption of standards
- Act as a trusted advisor across Product, Engineering, and Security teams
Basic Qualifications
- 8+ years in Application Security / Product Security / Security Engineering
- 3+ years leading DevSecOps or AppSec programs
- Strong experience with CI/CD security (Azure DevOps / similar)
- Hands-on expertise in SAST, DAST, SCA, threat modeling
- Experience securing cloud-native systems (AWS / Azure / GCP)
Preferred Qualifications
- Experience in Product Security/AppSec roles at top-tier product companies
- Experience building or scaling PSIRT programs
- Familiarity with SBOM (SPDX / CycloneDX), SLSA, Sigstore, Cosign
- Exposure to AI/ML or LLM security in production environments
AI/ML Security Certifications & Coursework (Preferred)
- ISO/IEC 42001 Lead Implementer (AI governance and risk management for enterprise systems)
- Certified AI Risk Manager (CAIRM) (AI risk identification and mitigation)
- Training aligned to NIST AI Risk Management Framework (governance, risk, and compliance for AI systems)
Cloud AI & Security Certifications (Strong Practical Signal):
- Microsoft Certified: Azure AI Engineer Associate
- Microsoft Certified: Azure Security Engineer Associate
- AWS Certified Machine Learning – Specialty
- AWS Certified Security – Specialty
Nice to have these certifications but not mandatory or core for Product Security Manager more valuable for cloud security or AI/ML engineering roles.