Director of Product and Application Security at SailPoint overseeing security strategy and team management. Leading integration of security in product development for SaaS, on-prem, and AI products.
Responsibilities
Develop and lead the enterprise-wide product security and resilience strategy, aligning with business goals and regulatory requirements.
Partner with Dev/Ops, engineering, product management, and infrastructure teams to integrate security into SDLC, DevSecOps, and CI/CD pipelines.
Establish and oversee secure architecture patterns, threat modeling practices, and resilience engineering frameworks.
Drive adoption of security automation, vulnerability management, and secure coding standards across product teams.
Build and mentor a high-performing team of product security architects, engineers, and software security specialists.
Monitor emerging threats, technologies, and compliance trends to proactively evolve the security posture.
Collaborate with legal, compliance, and risk teams to ensure alignment with global standards and certifications.
Define and track KPIs to measure program effectiveness and maturity.
Requirements
7+ years in leadership roles, preferably in product or application security.
Certifications like CISSP, CISM, CISA, CEH, GCIH, GCIA, are beneficial.
Experience with secure software development practices and tools.
Experience and knowledge of artificial intelligence software security, including OWASP AI Security and Privacy Guide, NIST AI Risk Management Framework, Cybersecurity AI (CAI), Open SSF AI/ML Security Framework.
Experience with regulatory frameworks (e.g., NIST, ISO 27001, GDPR).
Strategic Vision & Execution - Ability to define and communicate a clear vision for product security and resilience aligned with enterprise goals.
Influence & Collaboration – Demonstrable experience building strong partnerships across an organization to drive secure-by-design culture.
Technical Leadership - Deep understanding of product security issues (like XXE, SSRF, Injections, etc.), modern software development (fully automated CI/CD, REST, OAuth2) including multi-cloud (AWS, Azure, GCP, Containers, Kubernetes) architectures, particularly Amazon Web Services, Kubernetes, and software bill of materials (SBOM).
Change Management – Experience leading organizational change initiatives to embed security and resilience into product development lifecycles.
Experience building relationships with software engineering teams, including managing mature product security including final security reviews, and, risk-driven product scoring/metrics.
Talent Development - Demonstrable experience building high-performing teams through coaching, mentoring, and career development.
Risk-Based Decision Making – Experience making informed decisions through balancing business priorities, technical constraints, and risk exposure.
Executive Communication – Experience communicating complex technical concepts and ongoing program updates clearly to non-technical stakeholders and executive leadership.
Benefits
Health and wellness coverage: Medical, dental, and vision insurance
Disability coverage: Short-term and long-term disability
Life protection: Life insurance and Accidental Death & Dismemberment (AD&D)
Additional life coverage options: Supplemental life insurance for employees, spouses, and children
Flexible spending accounts for health care, and dependent care; limited purpose flexible spending account
Financial security: 401(k) Savings and Investment Plan with company matching
Time off benefits: Flexible vacation policy
Holidays: 8 paid holidays annually
Sick leave
Parental support: Paid parental leave
Employee Assistance Program (EAP) and Care Counselors
Voluntary benefits: Legal Assistance, Critical Illness, Accident, Hospital Indemnity and Pet Insurance options
Health Savings Account (HSA) with employer contribution
Cybersecurity Intern supporting Keenova's security program through hands - on experiences and mentorship. Engaging in various cybersecurity functions and contributing to meaningful projects.
Senior Security Engineer securing Cloudflare's global network and enterprise infrastructure. Working closely with engineering, IT, and compliance teams to address security risks at scale.
Senior IAM Systems Support Analyst providing L2 support expertise for CyberArk Agentic AI. Collaborating with security and development teams on IAM operations and compliance.
Senior Security Engineer focusing on hardening enterprise endpoints for cyber defense. Collaborating with NetSec and DataSec teams to minimize risks and enforce security protocols.
Security Consultant assessing and implementing security measures for organizations. Collaborating with clients to enhance their security posture and protect sensitive data.
Manager overseeing leadership protection and event security for GEICO. Responsible for security planning, threat analysis, and incident management during company events.
Cybersecurity Consultant managing TDR delivery team to enhance client security posture. Collaborating with clients and leading technical contributions in cybersecurity services.
Cyber Security & Compliance Lead protecting data and systems at Displayr. Responsible for risk management, compliance frameworks, and innovative security solutions using AI.
Lead Engineer in Security Engineering at Allstate overseeing security controls and product security teams. Collaborating with global stakeholders to manage security architecture and meet key performance indicators.
AI Security Architect focusing on AI security and governance for Voya Financial's applications and projects. Leading initiatives in artificial intelligence and securing innovative technology solutions.