Назад
Company hidden
4 часа назад

Product Manager (Security)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
India
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Manager (Security) (AI-driven code security): Owning an AI-driven vulnerability scanner that combines LLM-based vulnerability hunting, static analysis, secrets detection, infrastructure-as-code checks, and dependency and supply-chain analysis with an accent on detection quality, exploitability grading, and actionable findings. Focus on defining precision and recall standards, reducing false positives, shaping AppSec and CISO workflows, and turning benchmark evidence into product decisions.

Location: On-site in Bengaluru, India

Company

hirify.global develops an AI code review platform that analyzes pull requests, IDE changes, and CLI commits, with a focus on safe and fast software delivery.

What you will do

  • Own the security product end to end, including deep codebase scans and security findings in pull request reviews.
  • Prioritize vulnerability classes and capabilities across SAST, secrets detection, infrastructure-as-code misconfiguration, dependency, and software supply-chain analysis.
  • Define detection-quality standards for precision, recall, coverage, severity, and exploitability.
  • Design finding presentation, triage, dismissal, feedback, remediation, and reporting workflows.
  • Translate benchmarks, evaluations, and real-world detection results into product decisions and customer-facing evidence.
  • Partner with engineering, Sales, Growth, and Finance on scanning priorities, enterprise evaluations, competitive positioning, pricing, and packaging.

Requirements

  • 5–8 years of experience in the security space, including security product management or hands-on application security, penetration testing, vulnerability research, or detection engineering.
  • Product management experience with deeply technical products, ideally in B2B SaaS or developer tools.
  • Practical understanding of vulnerability classes, exploitation, severity assessment, and false-positive investigation.
  • Knowledge of SAST, DAST, secrets scanning, IaC security, and software composition analysis.
  • Technical fluency with code and APIs, plus the ability to collaborate closely with security engineers and AppSec teams.
  • Strong written communication, ownership, and ability to turn ambiguous problems into clear specifications.

Nice to have

  • Hands-on experience demonstrated through CVEs, bug bounty work, CTFs, or penetration-testing findings.
  • Experience shipping LLM- or agentic-system products.
  • Vendor-side experience with SAST, ASPM, or software composition analysis.
  • Power-user or product-management experience with GitHub, GitLab, Bitbucket, or Azure DevOps.

Culture & Benefits

  • Work with cutting-edge technology focused on AI-driven code security.
  • Collaborative, innovative environment centered on collective intelligence and complex technical challenges.
  • Competitive salary, equity, and benefits.
  • Professional development opportunities.

Hiring process

  • Submit a resume and relevant project samples or GitHub profiles.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →