Principal Product Manager (Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Remote within the United States or Canada. Remote work means working from the employee’s home country; travel for offsites, team meetings, and customer or industry events is required as part of the role.
Annual base salary: USD 238,000–357,000 for US-based roles or CAD 208,000–312,000 for Canada-based roles, plus a 15% annual bonus and equity eligibility.
Company
develops password management and Unified Access Management products that help businesses secure identities, application sign-ins, devices, SaaS tools, and AI systems.
What you will do
- Partner with product managers and feature teams to identify security requirements and threat-model implications early in product development.
- Translate product-team needs into prioritized security work and align Security Engineering with company product strategy.
- Own the platform-level security roadmap covering key management and recovery, zero-knowledge cryptographic foundations, authentication, and post-quantum cryptography readiness.
- Define the strategy for agentic access to credentials, secrets for non-human identities and AI agents, and trust models involving tools and protocols such as MCP.
- Balance security risk and user friction using threat models, adoption data, support data, and telemetry, while documenting residual risk decisions.
- Represent in the security community through researcher engagement, bug bounty collaboration, conference participation, and security thought leadership.
Requirements
- 10+ years of product management experience, including significant work on security-critical products or platforms in a SaaS environment.
- Deep knowledge of cryptography, authentication protocols, IAM, zero-knowledge and end-to-end encrypted systems, threat modeling, passkeys, WebAuthn, FIDO, and identity standards.
- Ability to read and reason through technical specifications, security audits, and cryptographic design documents.
- Experience making and communicating risk-based tradeoffs, setting platform or infrastructure strategy, and influencing roadmaps without formal authority.
- Track record of shipping adopted security features and using friction and adoption data to improve them.
- Must be able to work remotely from the United States or Canada and travel for in-person engagement when required.
Nice to have
- Security-community contributions through conference talks, publications, research, open-source work, or standards participation.
- Experience with AI security, agent identity and authorization, prompt injection, or secrets management for automated systems.
- Experience with SOC 2, FedRAMP, FIPS, vulnerability disclosure, incident response, threat intelligence, bug bounty programs, or researcher communities.
Culture & Benefits
- Remote-first work environment with collaboration, transparent communication, feedback, and a high technical bar.
- Health, dental, retirement or RRSP matching, generous paid time off, parental leave top-ups, and equity or RSU programs.
- Paid volunteer days, peer recognition, and a free account.
- AI tools may be used responsibly during the application process, but live interviews must be completed without AI tools.
- Successful applicants complete a background check as permitted by local law.
Hiring process
- Recruitment may include AI-assisted application screening, with an option to opt out.
- Live interviews assess communication, problem-solving, and collaboration without AI assistance.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →