Product Security Lead
- Hiring from
- United States
- Work type
- Remote
- Posted
- Sep 24, 2026
Is this job info correct?
Position: Product Security Lead
Location: REMOTE
Duration: Long Term Contract
Experience:
10+ Years in Information Security with strong expertise in Product Security, DevSecOps, Security Operations (SecOps), and SOC Operations.
Role Summary:
Candidate will possess deep expertise in secure software development, application security, cloud security, DevSecOps automation, threat modeling, vulnerability management, incident response, and SOC operations.
This role will work closely with Engineering, Product Management, DevOps, Infrastructure, and Security teams to build secure products and establish a mature security posture across the organization.
Key Responsibilities:
Product Security
Define and implement product security strategy and roadmap.
Conduct security architecture reviews and threat modeling exercises.
Perform secure design reviews for applications, APIs, microservices, and cloud-native products.
Establish and enforce secure SDLC (SSDLC) practices.
Drive application security assessments including:
SAST
DAST
IAST
Software Composition Analysis (SCA)
API Security Testing
Penetration Testing
Review and remediate findings from security assessments.
Establish product security standards aligned with industry frameworks.
DevSecOps
Integrate security controls into CI/CD pipelines.
Automate security testing and compliance checks.
Implement security gates and policy enforcement within development workflows.
Support container and Kubernetes security initiatives.
Secure cloud deployments across AWS, Azure, and GCP.
Define Infrastructure-as-Code (IaC) security controls.
Drive secrets management and secure configuration practices.
Security Operations (SecOps)
Lead vulnerability management programs.
Develop risk-based remediation strategies.
Manage security monitoring and incident response activities.
Collaborate with infrastructure and engineering teams for security hardening.
Lead root cause analysis and post-incident reviews.
Maintain security metrics and reporting dashboards.
SOC
Oversee SOC monitoring and alert triage processes.
Develop and optimize SIEM detection use cases.
Lead threat hunting initiatives.
Manage incident response lifecycle:
Detection
Analysis
Containment
Eradication
Recovery
Drive EDR/XDR implementation and enhancement activities.
Improve SOC maturity through automation and process optimization.
Qualifications Required:
Bachelor's degree in Computer Science, Information Security, or related field.
10+ years of Cybersecurity experience.
5+ years in Product Security or Application Security leadership roles.
Experience managing security teams and cross-functional stakeholders.
Hands-on experience with cloud-native and SaaS environments.
Preferred Certifications
CISSP
CSSLP
CCSP
AWS Security Specialty
Azure Security Engineer Associate
Location: REMOTE
Duration: Long Term Contract
Experience:
10+ Years in Information Security with strong expertise in Product Security, DevSecOps, Security Operations (SecOps), and SOC Operations.
Role Summary:
Candidate will possess deep expertise in secure software development, application security, cloud security, DevSecOps automation, threat modeling, vulnerability management, incident response, and SOC operations.
This role will work closely with Engineering, Product Management, DevOps, Infrastructure, and Security teams to build secure products and establish a mature security posture across the organization.
Key Responsibilities:
Product Security
Define and implement product security strategy and roadmap.
Conduct security architecture reviews and threat modeling exercises.
Perform secure design reviews for applications, APIs, microservices, and cloud-native products.
Establish and enforce secure SDLC (SSDLC) practices.
Drive application security assessments including:
SAST
DAST
IAST
Software Composition Analysis (SCA)
API Security Testing
Penetration Testing
Review and remediate findings from security assessments.
Establish product security standards aligned with industry frameworks.
DevSecOps
Integrate security controls into CI/CD pipelines.
Automate security testing and compliance checks.
Implement security gates and policy enforcement within development workflows.
Support container and Kubernetes security initiatives.
Secure cloud deployments across AWS, Azure, and GCP.
Define Infrastructure-as-Code (IaC) security controls.
Drive secrets management and secure configuration practices.
Security Operations (SecOps)
Lead vulnerability management programs.
Develop risk-based remediation strategies.
Manage security monitoring and incident response activities.
Collaborate with infrastructure and engineering teams for security hardening.
Lead root cause analysis and post-incident reviews.
Maintain security metrics and reporting dashboards.
SOC
Oversee SOC monitoring and alert triage processes.
Develop and optimize SIEM detection use cases.
Lead threat hunting initiatives.
Manage incident response lifecycle:
Detection
Analysis
Containment
Eradication
Recovery
Drive EDR/XDR implementation and enhancement activities.
Improve SOC maturity through automation and process optimization.
Qualifications Required:
Bachelor's degree in Computer Science, Information Security, or related field.
10+ years of Cybersecurity experience.
5+ years in Product Security or Application Security leadership roles.
Experience managing security teams and cross-functional stakeholders.
Hands-on experience with cloud-native and SaaS environments.
Preferred Certifications
CISSP
CSSLP
CCSP
AWS Security Specialty
Azure Security Engineer Associate
We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.