We are seeking a Senior Manager Product Security to engage in and improve DevSecOps automation, conduct penetration testing, and promote security culture within the engineering organization.
Requirements
- Engage in and improve DevSecOps automation in a CI/CD pipeline
- Conduct and manage a penetration testing program for both hardware and software platforms
- Integrating threat modeling practices into the product lifecycle
- Actively promote improving the security culture, standards, and education within the engineering organization
- Proactively evolve technology and processes using research on the latest security standard methodologies, trends, threats, and vulnerabilities
- Manage AWS and GCP cloud security governance through various tools which implement CIS benchmark scans, WAF policies, and IaC standards control
- Skills in documenting work and deliverables in a collaborative and clear manner, keeping them up to date as changes are made
- Producing metrics reporting the state of application security programs and performance of development teams against requirements