8 дней назад
Product Security Manager (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Product Security Manager (AI): Leading product security strategy and hands-on security engineering for M-Files products, cloud services, and AI-native capabilities with an accent on secure development, vulnerability management, and Azure cloud security. Focus on building security programs, integrating SAST/DAST/SCA and container scanning into CI/CD, managing software supply chain risks, and driving remediation across engineering teams.
Location: Hybrid role based in Finland, with offices in Tampere and Helsinki. Valid residency and work authorization in Finland are required; relocation support and visa sponsorship are not available.
Company
develops a context-first document management system that supports secure collaboration, automated workflows, governance, and AI-enabled information management for more than 6,000 customers.
What you will do
- Lead the Product Security team, strategy, roadmap, prioritization, coaching, and technical security baseline across the company.
- Embed the secure development lifecycle through threat modeling, security architecture reviews, secure coding guidance, and AI-assisted and manual code reviews.
- Integrate SAST, DAST, SCA, container scanning, SBOM generation, and dependency monitoring into CI/CD and software supply chain processes.
- Own vulnerability advisories, disclosure programs, vulnerability metrics, penetration testing, and remediation workflows.
- Drive Azure cloud security posture management, including Microsoft Defender for Cloud recommendations, Defender, and Sentinel monitoring.
- Support customer-facing security work and collaboration with Legal, Privacy, Compliance, engineering, cloud operations, and external auditors.
Requirements
- Bachelor's or Master's degree in Computer Science, Information Security, or a related technical field.
- At least 5 years of hands-on product or application security experience, including enterprise-scale security programs and technical team leadership or mentoring.
- Strong knowledge of cloud-native architectures, AKS/Kubernetes, container security, and cloud security posture management.
- Deep understanding of threat modeling, secure architecture, OWASP ASVS/Top 10, SAST/DAST/SCA tooling, penetration testing, vulnerability management, and CVSS prioritization.
- Working knowledge of SOC 2, ISO/IEC 27001, GDPR, NIS 2, and CRA, with strong communication skills for technical, non-technical, and executive audiences.
- Must already hold valid residency and work authorization in Finland.
Nice to have
- Relevant security certifications such as Microsoft SC-100, AZ-500, OSCP, or CSSLP.
- Experience or strong interest in applying AI tools to code review, threat modeling, reporting, and other security activities.
Culture & Benefits
- International, supportive, and collaborative work environment.
- Flexible remote work within the hybrid arrangement, with travel opportunities for team meetings and events.
- Career progression and personal development opportunities.
- Opportunity to influence product security at a fast-growing company.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →