Lead the design, implementation, and continuous improvement of the enterprise Secure Software Development Lifecycle (Secure SDLC) and Product Security program
Drive implementation of a world-class enterprise Product Security and Secure SDLC control framework within the existing IT Target Operating Model
Develop and track Product Security KPIs/KRIs
Ensure alignment of security controls across teams
Oversee execution of threat modeling and design security reviews for high-risk applications and APIs
Integrate security signals from various security teams to produce holistic application risk views
Drive risk-based prioritization by providing inputs into Agile backlogs
Facilitate collaboration across various security functions and the Chief Software Engineering organization
Requirements
6-10 years of combined people leadership and hands-on experience
Bachelor’s or advanced degree in Computer Science/Information Systems or equivalent
Deep understanding of secure SDLC practices
Knowledge of modern application architectures (cloud-native, APIs, microservices, containers)
Familiarity with vulnerability management processes and enterprise remediation practices
Ability to operate effectively as a player-coach
Strong ability to influence across organizational boundaries without direct authority
Strong analytical skills to identify systemic issues across large application portfolios
Excellent communication, presentation, and interpersonal skills