Product Security Lead in Haciendas del Canada, Nuevo León at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Product Security Lead based in Canada.
This role leads the Product Security function and reports directly to the Chief Information Security Officer.
You will define the security strategy, roadmap, and operating model while embedding security throughout the product and engineering lifecycle.
The position combines hands-on technical leadership with strategic influence across application security, cloud platforms, connected devices, and product engineering.
You will help teams adopt secure-by-design practices through threat modeling, architectural reviews, secure coding, and automated security controls.
The role also plays an important part in customer and commercial engagements by translating security maturity into support for enterprise opportunities.
You will work across Security, Engineering, Product, Sales, GRC, Cloud Operations, and other teams to manage product risk and strengthen resilience.
This is a high-impact leadership opportunity in a remote environment focused on secure innovation and connected infrastructure.
- Define, build, and lead the vision, roadmap, and operating model for the Product Security function.
- Serve as a trusted security advisor to the CISO, Product leadership, Engineering leadership, and other senior stakeholders.
- Embed security-by-design principles throughout the Secure Software Development Lifecycle (SSDLC).
- Lead threat modeling, secure design reviews, architectural risk assessments, and other proactive product security activities.
- Partner with Engineering teams to implement secure coding practices and security gates within CI/CD pipelines.
- Influence cloud and platform architecture to strengthen resilience, network segmentation, least-privilege access, and defense-in-depth controls.
- Lead product-level risk identification and manage the vulnerability lifecycle across application code, APIs, cloud services, and embedded components.
- Oversee penetration testing activities, vulnerability remediation, and risk tracking to ensure issues are addressed effectively.
- Partner with GRC, Sales, and Revenue Operations teams on RFPs, RFIs, customer security reviews, and enterprise engagements.
- Act as a technical authority in customer-facing security discussions and communicate security capabilities in a commercially relevant way.
- Translate regulatory, contractual, and audit requirements into practical and scalable product security controls.
- Apply relevant requirements from frameworks and standards including ISO 27001, SOC 2, NIST, and Tx-RAMP.
- Collaborate with Security Operations and Cloud Operations to establish product telemetry and logging requirements.
- Help ensure secure-by-default deployment patterns and effective integration with incident response processes.
- Continuously improve product security practices, tooling, processes, and operating models as threats and business requirements evolve.
- Extensive technical experience in application security, product security, secure engineering, or cloud security.
- Experience working in SaaS, critical infrastructure, connected technology, or similarly complex environments is highly valuable.
- Strong hands-on experience with Secure Software Development Lifecycle practices, including threat modeling, SAST/DAST, secure design, and automated security controls.
- Proven ability to integrate security gates and controls into modern CI/CD pipelines.
- Strong understanding of security frameworks and control mapping, including ISO 27001, SOC 2, NIST CSF, and NIST 800-53.
- Working knowledge of NIST SP 800-82 and security considerations for OT/ICS or connected infrastructure.
- Demonstrated experience securing connected devices, IoT, or OT-adjacent systems.
- Strong expertise in cloud-native architectures, with AWS experience preferred.
- Experience securing APIs, microservices, cloud services, and distributed platforms.
- Practical knowledge of vulnerability management, penetration testing, security assessments, and product risk management.
- Strong experience with the OWASP security tool suite and the CISA Cyber Security Evaluation Tool (CSET).
- Ability to influence senior Engineering and Product stakeholders without relying on direct reporting authority.
- Excellent communication skills, with the ability to translate complex technical risks for executives, auditors, customers, and non-technical stakeholders.
- Strong analytical and critical-thinking abilities, with sound judgment when managing complex or high-impact security decisions.
- Ability to operate effectively in ambiguous, fast-moving environments while maintaining strong ownership and attention to detail.
- Strong cross-functional collaboration skills and the ability to build consensus across technical and business teams.
- Base salary of CA$163,000–CA$198,000, depending on skills, experience, market conditions, and primary work location.
- Equity opportunities.
- Discretionary bonus and variable incentive opportunities.
- Comprehensive health benefits from day one.
- 24/7 virtual healthcare access.
- Dedicated wellness programs and resources.
- RRSP/401K matching plan to support long-term financial planning.
- Flexible vacation policy.
- Mio-Days designed to provide additional time to recharge.
- Flexible work options within a remote environment.
- Internet subsidy and remote work allowance.
- Enhanced leave programs for new parents.
- Opportunity to lead and shape a strategic Product Security function.
- High-impact collaboration with Security, Engineering, Product, Cloud Operations, Sales, and GRC teams.
- Opportunity to work on security challenges involving cloud platforms, connected devices, IoT, and critical infrastructure.
- Inclusive and diverse working environment.
- Accessibility accommodations available throughout the hiring process where required.