Назад
Company hidden
57 минут назад

Product Security Incident Response Lead (IoT)

185 000 - 230 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Product Security Incident Response Lead (IoT): Lead and operate the Product Security Incident Response Team (PSIRT) managing vulnerabilities across hardware, firmware, and cloud systems with an accent on coordinated vulnerability disclosure and cross-functional remediation. Focus on driving technical remediation strategies, managing CVE Numbering Authority operations, and authoring clear security advisories.

Location: Remote - Must be based in the United States

Salary: $185,000–$230,000 + Equity

Company

hirify.global builds connected hardware devices and cloud platforms to support public safety, with over $1B in funding and a team of 1,700 people.

What you will do

  • Own the operational model and execution of the Product Security Incident Response Team (PSIRT) for all product vulnerabilities.
  • Lead the CVE Numbering Authority (CNA) operations including vulnerability intake, triage SLAs, severity rubrics, and public CVE publishing.
  • Drive cross-functional remediation efforts across hardware, firmware, device and cloud SRE, mobile, legal, communications, and support teams.
  • Author clear and accurate public security advisories, internal postmortems, and executive summaries.
  • Establish metrics and reporting for PSIRT performance tracking.
  • Act as an individual contributor driving execution and policy adherence through cross-functional influence.

Requirements

  • Must have experience leading or running a PSIRT or coordinated vulnerability disclosure function, ideally in connected hardware or IoT.
  • Operational experience as a CVE Numbering Authority (CNA) or implementing FIRST PSIRT Services Framework.
  • Hands-on technical background in embedded/firmware security, Linux or Android device security, AWS cloud security, or mobile application security.
  • Expertise applying CVSS, CWE, EPSS, and SSVC frameworks for vulnerability risk evaluation.
  • Strong written communication skills to translate complex vulnerabilities into clear advisories for diverse audiences.
  • Location requirement: Must be based in the United States.

Culture & Benefits

  • Remote work with priority given to candidates in Atlanta and Boston for hub-based roles.
  • Equity participation through stock options.
  • Inclusive and diverse work environment with accommodations for disabilities.
  • Competitive base salary determined by experience and market indicators.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →