Lead Product Security
Core
Senior technical leadership role embedding security throughout the product development lifecycle, shaping secure architecture, threat modeling, and secure-by-default standards.
Role type
Senior IC product security lead (technical leadership)
Builds
Secure software products, secure development tooling, and security enablement programs
Domain
Software product security, cloud security, AI/LLM security, supply chain security
Required skills
Secure architecture design, threat modeling, secure code review, security requirements definition, Security Champions program management, SCA/SAST/DAST tooling, cloud security (AWS/Azure/GCP), penetration test coordination, PSIRT processes, AI/LLM security risk assessment, regulatory compliance (EU Cyber Resilience Act)
Preferred skills
BSIMM/SAMM frameworks, customer security questionnaire support, relevant security certifications (CSSLP, CISSP, etc.)
Technologies
SCA, SAST, DAST, secret scanning, SBOM, container security, infrastructure-as-code, AWS, Azure, GCP
Responsibilities
Lead security architecture and design reviews; coach engineers on threat modeling; define security baselines and standards; build secure SDLC practices (SCA, SAST, DAST); conduct deep secure code reviews; strengthen supply chain and release security; develop Security Champions program; mentor engineers on secure design; coordinate penetration tests and third-party assessments; partner with PSIRT on vulnerability response; assess security maturity using frameworks; support regulatory requirements; provide expertise for security questionnaires and audits; support incident response.
Seniority
Senior, hands-on IC with leadership influence
