Назад
Company hidden
2 дня назад

Product Security Principal

159 075 - 242 112$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Principal (Application Security/Cloud Security): Embedding security expertise across assigned product lines by designing application-specific controls, threat models, security architectures, and secure development practices with an accent on cloud security, IAM, DevSecOps, and regulatory control design. Focus on coordinating vulnerability assessments and penetration testing, managing emerging risks, and driving remediation across the technology supply chain.

Location: New York, NY 10018; onsite, full time

Salary: $159,075.00–$242,112.00 per year

Company

hirify.global is a banking and financial services organization.

What you will do

  • Serve as the embedded security subject matter expert and thought leader for assigned product lines.
  • Define application security requirements, threat models, security architecture, authentication and authorization designs, and data-handling standards.
  • Lead vulnerability assessments, penetration testing coordination, secure code reviews, and security validation activities.
  • Prepare security assessments, release validation materials, and incident response plans for Technology Review Boards.
  • Monitor Key Risk Indicators, manage emerging security issues, identify root causes, and drive remediation.
  • Partner with engineering, SRE, business architecture, audit, regulatory, and third-party oversight teams on technology risk.

Requirements

  • 8+ years of experience in information security, cybersecurity, or technology risk management within a regulated organization.
  • Experience with the Three Lines of Defense model and translating policy and regulatory requirements into control designs for engineers and architects.
  • Expert knowledge of application security, threat modeling, and secure software development lifecycle practices.
  • Strong understanding of cloud security architecture, IAM, secrets management, data protection, vulnerability assessment, penetration testing, and secure code review.
  • Experience with DevSecOps tooling, CI/CD security integration, code scanning, and container security at build and runtime.
  • Ability to communicate complex security concepts clearly, influence stakeholders without direct authority, and present recommendations to review boards and executive leadership.

Nice to have

  • Undergraduate degree or equivalent.
  • Public cloud experience with Azure or AWS, including hardening, resiliency, data protection, and access management.
  • Experience with APIs, microservices, SSDLC, financial services, or comparable regulated industries.
  • CISSP, CISM, or an equivalent security certification.

Culture & Benefits

  • Medical, dental, vision, life, and disability insurance.
  • Comprehensive leave program.
  • Minimal travel required.
  • Work involves collaboration across product, technology, cybersecurity, and business teams.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →