Lead Product Security in Haciendas del Canada, Nuevo León at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead Product Security based in Canada.
This is a senior technical leadership role responsible for embedding security throughout the product development lifecycle.
You will shape secure architecture, design reviews, threat modeling, and secure-by-default standards across product engineering.
The role combines hands-on security expertise with developer enablement, mentoring, and organizational security maturity.
You will work across application security tooling, secure code review, product supply chain security, and vulnerability response.
A key focus is scaling security capabilities through Security Champions, training, reusable guidance, and measurable improvement programs.
You will collaborate closely with engineering, security operations, PSIRT, and other stakeholders on high-impact security initiatives.
The position offers broad autonomy and the opportunity to influence how secure software is designed, built, assessed, and maintained.
- Lead security architecture and design reviews across core product lines, providing actionable guidance before implementation begins.
- Contribute to and scale threat modeling practices by coaching engineers to conduct their own models and reviewing results.
- Define security requirements, design gates, product security baselines, and standards that establish a practical definition of secure-by-default.
- Build and measure secure development lifecycle practices across SCA, SAST, DAST, secret scanning, dependency management, and build pipeline integrity.
- Conduct deep secure code reviews in high-risk areas such as authentication, authorization, cryptography, secrets management, and input validation.
- Strengthen product supply chain and release security, including SBOM generation and the integrity of build and distribution artifacts.
- Develop and expand the Security Champions program through recruitment, training, enablement content, office hours, and outcome tracking.
- Mentor engineers and security professionals on secure design, threat modeling, and secure code review to scale security expertise across teams.
- Coordinate penetration tests and third-party security assessments, triaging findings and driving remediation through completion.
- Partner with PSIRT on product vulnerability triage, remediation, and coordinated response, using root-cause insights to improve engineering and SDLC controls.
- Assess product security maturity using frameworks such as BSIMM or SAMM and drive a prioritized improvement roadmap.
- Support secure-by-design regulatory requirements, including the EU Cyber Resilience Act, through technical evidence and process improvements.
- Provide subject matter expertise for customer security questionnaires, audits, RFPs, and security escalations, while building reusable, vetted response documentation.
- Support incident response involving product code, build systems, or product infrastructure with product-specific security expertise and remediation guidance.
- Lead discrete technical workstreams, track milestones, and contribute to application security tooling evaluations and proof-of-concepts.
- Bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience.
- 8+ years of experience in product security, application security, or software security engineering, with strong hands-on experience in secure design reviews, threat modeling, and secure code review.
- Experience building or operating a Security Champions program, developer security training initiative, or comparable security enablement program.
- Strong knowledge of application security tooling, including SCA, SAST, DAST, and secret scanning, along with an understanding of their detection capabilities and limitations.
- Practical secure coding and code review experience in at least one commercial software programming language, with the ability to assess unfamiliar code.
- Experience defining security requirements, standards, or design gates that have been adopted by engineering teams.
- Familiarity with AWS, Azure, or GCP from a product security perspective, including container and infrastructure-as-code security.
- Experience coordinating penetration tests or third-party assessments and driving identified issues through remediation.
- Demonstrated ability to mentor engineers and lead technical initiatives without relying on formal management authority.
- Awareness of AI and LLM security risks, including prompt injection, sensitive data exposure, and the OWASP Top 10 for LLM Applications.
- Practical experience using AI and LLM tools to accelerate security work, with sound judgment around validating AI-generated outputs before they are acted upon or shared.
- Strong written and verbal communication skills, with the ability to explain technical security concepts to engineering, security, and non-technical stakeholders.
- Experience with PSIRT or equivalent product vulnerability response processes, including CVSS scoring and coordinated disclosure, is a plus.
- Familiarity with BSIMM, SAMM, secure-by-design practices, or EU Cyber Resilience Act requirements is a plus.
- Certifications such as CSSLP, CISSP, GWAPT, OSWE, or relevant cloud security certifications are a plus.
- Experience supporting customer security questionnaires, RFPs, or third-party risk assessments is a plus.
- Comfortable working extensively at a computer and participating in occasional phone-based communication, with the ability to lift or move items up to 20 pounds when required.
- Willingness to travel occasionally as needed.
- CAD $117,000–$150,000 salary range.
- Remote position based in Canada.
- Opportunity to influence product security strategy and secure software development practices at scale.
- Broad technical ownership with significant autonomy and cross-functional exposure.
- Opportunities to mentor engineers and develop security capabilities across product teams.
- Exposure to modern application security, cloud security, AI/LLM security, software supply chain security, and vulnerability management.
- Potential opportunities to contribute to regulatory readiness and security maturity initiatives.
- Occasional travel opportunities as required by the role.