Lead Product Security

JobgetherCanadaRemoteFull-timeSenior, 5–8 yearsListed 49 minutes ago

Apply now

About this role

Accountabilities:

- Lead security architecture and design reviews across core product lines, providing actionable guidance before implementation begins.

- Contribute to and scale threat modeling practices by coaching engineers to conduct their own models and reviewing results.

- Define security requirements, design gates, product security baselines, and standards that establish a practical definition of secure-by-default.

- Build and measure secure development lifecycle practices across SCA, SAST, DAST, secret scanning, dependency management, and build pipeline integrity.

- Conduct deep secure code reviews in high-risk areas such as authentication, authorization, cryptography, secrets management, and input validation.

- Strengthen product supply chain and release security, including SBOM generation and the integrity of build and distribution artifacts.

- Develop and expand the Security Champions program through recruitment, training, enablement content, office hours, and outcome tracking.

- Mentor engineers and security professionals on secure design, threat modeling, and secure code review to scale security expertise across teams.

- Coordinate penetration tests and third-party security assessments, triaging findings and driving remediation through completion.

- Partner with PSIRT on product vulnerability triage, remediation, and coordinated response, using root-cause insights to improve engineering and SDLC controls.

- Assess product security maturity using frameworks such as BSIMM or SAMM and drive a prioritized improvement roadmap.

- Support secure-by-design regulatory requirements, including the EU Cyber Resilience Act, through technical evidence and process improvements.

- Provide subject matter expertise for customer security questionnaires, audits, RFPs, and security escalations, while building reusable, vetted response documentation.

- Support incident response involving product code, build systems, or product infrastructure with product-specific security expertise and remediation guidance.

- Lead discrete technical workstreams, track milestones, and contribute to application security tooling evaluations and proof-of-concepts.

Requirements

- Bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience.

- 8+ years of experience in product security, application security, or software security engineering, with strong hands-on experience in secure design reviews, threat modeling, and secure code review.

- Experience building or operating a Security Champions program, developer security training initiative, or comparable security enablement program.

- Strong knowledge of application security tooling, including SCA, SAST, DAST, and secret scanning, along with an understanding of their detection capabilities and limitations.

- Practical secure coding and code review experience in at least one commercial software programming language, with the ability to assess unfamiliar code.

- Experience defining security requirements, standards, or design gates that have been adopted by engineering teams.

- Familiarity with AWS, Azure, or GCP from a product security perspective, including container and infrastructure-as-code security.

- Experience coordinating penetration tests or third-party assessments and driving identified issues through remediation.

- Demonstrated ability to mentor engineers and lead technical initiatives without relying on formal management authority.

- Awareness of AI and LLM security risks, including prompt injection, sensitive data exposure, and the OWASP Top 10 for LLM Applications.

- Practical experience using AI and LLM tools to accelerate security work, with sound judgment around validating AI-generated outputs before they are acted upon or shared.

- Strong written and verbal communication skills, with the ability to explain technical security concepts to engineering, security, and non-technical stakeholders.

- Experience with PSIRT or equivalent product vulnerability response processes, including CVSS scoring and coordinated disclosure, is a plus.

- Familiarity with BSIMM, SAMM, secure-by-design practices, or EU Cyber Resilience Act requirements is a plus.

- Certifications such as CSSLP, CISSP, GWAPT, OSWE, or relevant cloud security certifications are a plus.

- Experience supporting customer security questionnaires, RFPs, or third-party risk assessments is a plus.

- Comfortable working extensively at a computer and participating in occasional phone-based communication, with the ability to lift or move items up to 20 pounds when required.

- Willingness to travel occasionally as needed.

Benefits

- CAD $117,000–$150,000 salary range.

- Remote position based in Canada.

- Opportunity to influence product security strategy and secure software development practices at scale.

- Broad technical ownership with significant autonomy and cross-functional exposure.

- Opportunities to mentor engineers and develop security capabilities across product teams.

- Exposure to modern application security, cloud security, AI/LLM security, software supply chain security, and vulnerability management.

- Potential opportunities to contribute to regulatory readiness and security maturity initiatives.

- Occasional travel opportunities as required by the role.

How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
 Why Apply Through Jobgether? 
 
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
 
 
#LI-CL1