AVP of Product Security
SemperisIdentity Threat company
Dallas, United StatesDirector
KKR
Insight Partners
Ten Eleven Ventures
Paladin Capital Group
Atrium Health Strategic Fund
Tech Pioneers Fund
Leadership & General Management
About the role
TL;DR
Drive security into product development and build a formal vulnerability management program.
- •The AVP of Product Security will drive security into product development, embedding security into the Software Development Lifecycle SDLC, and building a formal vulnerability management program.
- •Key Responsibilities Establish secure by design standards and the target state security architecture across product development.
- •Shift security left into product and engineering to reduce risk and cost.
- •Build a formal vulnerability management program encompassing both traditional vulnerability management and AI.
- •Enable secure AI adoption across our products and internal systems.
- •Define security architecture patterns that drive clarity with the business and enable the right guardrails.
- •Own risk based prioritization, remediation SLAs, and executive reporting for enterprise vulnerability management.
- •Provide senior technical leadership and create clear, consistent standards across Product, Engineering, and Security.
- •Build proactive security leadership and trusted partnerships across Product, Engineering, and Security teams.
- •Recruit, develop, and lead a strong team of product security engineers and security architects.
- •Requirements 10+ years of information security experience, including 5+ years leading product security, security architecture, and/or vulnerability management functions.
- •Proven experience embedding security into the Software Development Lifecycle SDLC at a software or SaaS company.
- •Deep security architecture expertise across cloud native and hybrid environments (Azure preferred).
- •Hands on experience implementing AI and ML security controls.
- •Experience building or maturing enterprise vulnerability management programs.
- •A track record of influencing at the executive level and driving alignment across Product, Engineering, and Security organizations.
- •Strong communication skills, with the ability to translate technical risk into clear business terms that enable decisions.
Required skills
Penetration TestingAzureSOC 2
Domain expertise
cybersecurity
Tech stack
Penetration TestingAzureSOC 2