4 дня назад
Head of PSC Engineering (Product Security)
250 000 - 300 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Head of PSC Engineering (Product Security): Leading a distributed product security engineering team delivering penetration testing, firmware analysis, PSIRT-as-a-Service, and compliance services with an accent on people leadership, delivery quality, capacity planning, and customer outcomes. Focus on scaling managed services, operationalizing playbooks and SLAs, integrating field-built tooling into the product, and reviewing high-stakes technical security work.
Location: Remote, United States or Canada. No relocation required. Occasional travel is expected for customer executive reviews, on-site engagements, conferences, and team gatherings.
Compensation: $250,000–$300,000, plus bonus, equity, and full benefits.
Company
provides a product security platform for connected devices and embedded systems, helping organizations identify vulnerabilities, manage software supply-chain risks, and meet security and compliance requirements.
What you will do
- Hire, onboard, coach, and develop PSC Engineers while setting objectives, conducting performance reviews, and addressing underperformance.
- Own technical delivery across customer engagements, including scoping, staffing, deliverable reviews, debriefs, Level 2 support, quality criteria, and delivery KPIs.
- Plan team capacity, balance billable engagements with managed-service shifts and capability development, and manage utilization.
- Build and scale PSIRT-as-a-Service and Standards and Regulations Compliance-as-a-Service through runbooks, staffing models, SLAs, and platform capabilities.
- Connect field-built security tooling with the product roadmap and represent PSC Engineering in the Product Paving Council.
- Lead senior customer relationships, service reviews, escalations, technical scoping, and expansion efforts with Sales.
Requirements
- 3+ years of direct people management, including hiring, supervision, development, performance cycles, and handling underperformance.
- Experience mentoring, coaching, and teaching engineers, plus formal management or leadership training.
- 8+ years in product security, embedded and connected-device security, application security, or offensive security, including substantial customer-facing services, consulting, or managed-services experience.
- Hands-on expertise in at least two areas including firmware and binary analysis, embedded or IoT penetration testing, TARA, SBOM and software composition analysis, vulnerability disclosure, CVE/CNA workflows, or PSIRT operations.
- Experience running technical delivery against SLAs, SLOs, quality standards, capacity plans, and utilization targets in a billable environment.
- Knowledge of the EU Cyber Resilience Act and relevant standards including IEC 62443, RED EN 18031, FDA premarket cybersecurity requirements, ETSI EN 303 645, NIST SSDF, ISO/IEC 29147 and 30111, CVSS, VEX, SPDX, and CycloneDX.
Nice to have
- Experience building a managed service or consulting offering, including processes, runbooks, staffing models, and SLAs.
- CISSP, CSSLP, GIAC, OSCP, CISM, CRISC, ISO/IEC 27001 Lead Implementer, or IEC 62443 Cybersecurity Expert credentials.
- Experience securing aerospace, medical, automotive, energy, or industrial cyber-physical systems.
- Knowledge of JSIG, ICD 503, or NIST SP 800-160; clearance eligibility.
Culture & Benefits
- Fully distributed workforce with a remote-first culture.
- Bonus, equity, and full benefits.
- Mission-driven work focused on securing connected products, IoT, critical infrastructure, and embedded systems.
- Culture centered on customer focus, ownership, transparency, integrity, urgency, learning, and measurable results.
- Occasional travel for customer engagements, conferences, and team gatherings.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
9 дней назад
Vice President of Engineering (Cybersecurity)
250 000 - 275 000$
10 дней назад
Vice President, Information Security - Manufacturing Plant Security, Product Security & Application Security (Cybersecurity)
250 000 - 350 000$
4 дня назад
Senior Software Engineer (AI Security)
125 000 - 209 000$
5 дней назад
Principal Embedded Systems Security Engineer (Aerospace)
225 000 - 330 000$
5 дней назад
Staff Embedded Systems Security Engineer (Aerospace)
200 000 - 305 000$
5 дней назад
Security Engineer (AI)
150 000 - 180 000$