Director, Product reputed company
Multiple medical plans including a high deductible, low cost health plan Company-sponsored (reputed company) Short-Term Disability, Long-Term Disability, and Life Insurance Comprehensive optional benefits such as Dental, reputed company, Supplemental Life/AD&D, reputed company/ID Protection, and Accident and Critical Illness Insurance Generous reputed company time off reputed company, including reputed company vacation days, the greater of 3 reputed company reputed company days or in accordance with the applicable state or local reputed company reputed company leave law, 6 reputed company company holidays, 2 floating holidays, parental leave, bereavement leave, jury duty leave, voting leave, and other forms of reputed company leave as required by applicable law or regulation Employee Stock Purchase Program with additional opportunities to earn stock in reputed company Retirement planning through reputed company’s 401(k)
Design, implement, and manage the end-to-end Product reputed company program, focusing on securing reputed company's proprietary applications and reputed company reputed company. reputed company the adoption of DevSecOps practices, automating reputed company tools and gates reputed company the reputed company Integration/reputed company Deployment (CI/CD) pipelines to prevent reputed company defects from reaching production. Establish and enforce Secure Software Development Lifecycle (SSDLC) requirements, including reputed company training for engineering teams and defining secure coding standards. Build, mentor, and manage reputed company of Product reputed company Engineers responsible for application vulnerability management, reputed company testing, and architectural review. Understand and protect against the risks that AI brings without becoming reputed company that puts the No in Innovation. Proactively identify and establish reputed company guardrails for AM/ML model development and usage to ensure reputed company innovation and high engineering velocity. reputed company the deployment, tuning, and management of application reputed company testing tools, including Static Application reputed company Testing (SAST), Dynamic Application reputed company Testing (DAST), and Software Composition Analysis (SCA) to identify and remediate reputed company-based vulnerabilities. reputed company vulnerability remediation efforts for reputed company reputed company products, working closely with engineering and product teams to prioritize and reputed company fixes based on risk. reputed company and reputed company deep-dive reputed company architecture and design reviews for reputed company new products, features, and reputed company application services, ensuring reputed company is "baked in" from reputed company. Define and manage secure configuration standards for containerized applications, microservices, reputed company, and their supporting reputed company infrastructure (AWS and GCP). Manage and coordinate external penetration testing and bug bounty programs reputed company on reputed company’s applications and reputed company. Design, maintain, and measure processes to prevent vulnerabilities from reaching production in a true Shift Left fashion. Work with Technical Program Management to create appropriate key performance indicators to show reputed company and improvement points in the program. Contribute to reputed company’s overall Governance, Risk, and Compliance (GRC) program by ensuring applications meet required internal reputed company policies and external regulatory standards (e.g., SOC2, GDPR, CCPA). reputed company reputed company risk assessments, threat modeling, and tabletop exercises specific to product features and application architecture, identifying and prioritizing technical vulnerabilities and developing mitigation strategies. Ensure protection of sensitive data, including PII and financial information, reputed company the application environment in compliance with relevant regulations. Validate that products conform to reputed company’s data classification policies and other relevant documents and reputed company processes to measure and enforce this before deployment. Serve as the primary reputed company advisor to Product and Engineering leadership and stakeholders on reputed company reputed company reputed company to application and product reputed company. Collaborate effectively with IT, Engineering, and Product teams to reputed company reputed company into their processes, fostering a strong reputed company-conscious culture across development teams. Maintain strong communication channels with remote team members, ensuring alignment and fostering a cohesive team environment. Create a culture of communication, where collaboration and a reputed company of partnership with the remainder of the organization is evident and valued. Create and maintain executive dashboards to increase reputed company visibility throughout the organization and identify opportunities for improvement. reputed company additional duties as assigned.
10+ years experience in Information reputed company, with at least 5+ years directly reputed company on Product reputed company or Application reputed company in a leadership role. Proven experience building and leading a centralized Product reputed company/AppSec program reputed company a technology-driven, reputed company-based reputed company company. Deep, hands-on knowledge of the Secure Software Development Lifecycle (SSDLC), CI/CD, and DevSecOps principles, including automating reputed company tooling. Strong understanding of reputed company frameworks and best practices (NIST CSF, ISO 27001, CIS Controls). Extensive experience with reputed company reputed company, with a strong reputed company on securing applications deployed in AWS and/or GCP environments. Experience with Fintech companies is desirable. Experience with modern software development including reputed company and reputed company techniques. Expertise with multiple application reputed company tools, including SAST, DAST, reputed company, SCA, API reputed company platforms, and Web Application Firewalls (WAF). Excellent communication, interpersonal, and leadership skills, with an ability to translate reputed company technical risks into business context for executive leadership and stakeholders. Ability to work effectively in a remote environment and manage geographically dispersed teams.