Principal Product Security Program Leader

AMD

San Jose (CA)

Hybrid

USD 180,000 - 240,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work
Benefits at a glance

Job summary

AMD is seeking an experienced Product Security Leader to own end-to-end security governance for the Adaptive & Embedded Computing business unit. You will coordinate vulnerability response, SDL governance, and regulatory compliance, partnering with the PSO, Legal, and security SMEs across hardware, firmware, and software tooling teams.

This high-visibility role requires leadership in PSIRT-like activities, triage of vulnerability reports, and ensuring compliance with EU CRA, GDPR, SBOM, and

Qualifications

  • Expert level product security leadership in semiconductor or embedded systems.
  • Experience with PSIRT or CVD programs and coordinated disclosure with researchers and OEMs.
  • Familiarity with SAST tooling and secure SDLC frameworks (ISO/SAE 21434, NIST SSDF).
  • Understanding of EU Cyber Resilience Act (CRA), GDPR, and global cybersecurity regulations.
  • Experience partnering with Legal, Corporate Communications, and Compliance on regulated disclosures and customer-facing assessments.
  • Strong executive communication and ability to translate findings into business impact.

Responsibilities

  • Own product security governance for the business unit—interface with Product Security Office on vulnerability management, SDL health, and remediation progress.
  • Coordinate response across embedded security experts to triage and resolve vulnerability reports from researchers, internal teams, and customers.
  • Maintain and evolve the security threat model for AMD's adaptive-computing design tools.
  • Partner with Legal and Compliance to align the unit with CRA, GDPR, SBOM and disclosure obligations.
  • Facilitate customer-facing security assessments and due-diligence requests.
  • Serve as incident lead for high-severity vulnerabilities and drive timely disclosure with partners and customers.
  • Brief leadership on security posture, incidents, and program health.

Skills

Product security leadership
PSIRT program management
Regulatory compliance
SAST tooling
threat modeling
Secure SDLC frameworks
Executive communication
Cross-functional collaboration

Tools

Coverity
CodeQL
Black Duck
SPDX
CycloneDX

Job description

ADVANCE YOUR CAREER. ADVANCE THE WORLD.

At AMD, we believe technology can change lives for the better. It can heal us, entertain us, and make us more connected, productive, and understanding of the world around us. And we're looking for talent who feel the same: people who want to leave the planet better than they found it, those who don't shy away from humanity's challenges but are determined to help solve them.

AMD is powering the next generation of supercomputing, high-performance computing, cloud, and AI. Whether you're designing next-gen processors, enabling AI breakthroughs, or creating go-to-market plans, every role at AMD contributes to something bigger - technology that moves the world forward.

About the Role

AMD is seeking an experienced Product Security Leader to serve as the primary point of accountability for product security across the Adaptive & Embedded Computing (AECG) business unit. This role owns end-to-end coordination of vulnerability response, secure development lifecycle (SDL) governance, and regulatory compliance for AMD's Adaptive and Embedded Computing product lines. The successful candidate will partner closely with AMD's Product Security Office (PSO), Corporate Legal and business-unit security subject matter experts across hardware, firmware, and software tooling teams.

This is a high-visibility role that is critical to meeting AMD's security commitments to its customers, including the EU Cyber Resilience Act (CRA), GDPR, and contractual security obligations with hyperscale and OEM partners.

Key Responsibilities
  • Own product security governance for the business unit — primary interface with AMD's Product Security Office on vulnerability management, SDL health, and remediation progress.
  • Coordinate response across embedded security experts spanning silicon, firmware, and software tooling to triage and resolve vulnerability reports from researchers, internal teams, and customers.
  • Maintain and evolve the security threat model for AMD's adaptive-computing design tools.
  • Partner with Legal and Compliance to align the business unit with the EU Cyber Resilience Act, GDPR, and related regulatory requirements, including SBOM and vulnerability disclosure obligations.
  • Facilitate customer-facing security assessments and due-diligence requests.
  • Serve as incident lead for high-severity vulnerabilities and active exploit reports, driving timely resolution and coordinated disclosure with partners and customers.
  • Brief business-unit and executive leadership on security posture, material incidents, and program health.
Required Qualifications
  • Expert level of product security, PSIRT, or Security Design Lifecycle leadership experience in semiconductor, EDA software, embedded systems, or a comparable industry; FPGA / adaptive computing experience is a strong plus.
  • Demonstrated leadership with a PSIRT or product coordinated vulnerability disclosure (CVD) program, including triage, CVSS scoring, CVE assignment, security bulletin/advisory authoring, and coordinated disclosure with hyperscalers, OEMs, and independent security researchers.
  • Working expertise with SAST tooling (e.g., Coverity, CodeQL), SCA/SBOM tooling (e.g., Black Duck, SPDX, CycloneDX), threat modeling methodologies, and secure SDLC frameworks (eg, ISO/SAE 21434, NIST SSDF).
  • Demonstrated familiarity with the EU Cyber Resilience Act (CRA), GDPR, and adjacent global cybersecurity regulations, with the ability to translate regulatory text into engineering requirements.
  • Track record partnering with Legal, Corporate Communications, and Compliance teams on regulated disclosures and customer-facing security assessments.
  • Strong executive communication skills: able to produce concise status reporting, brief senior leadership, and translate technical findings into business and customer impact.
Preferred Qualifications
  • Experience with FPGA design tool flows (e.g., Vivado, Vitis, Vitis HLS) and embedded software stacks (e.g., PetaLinux, Yocto, Xen).
  • Familiarity with information security management standards such as ISO/IEC 27001, in addition to product-security-specific frameworks.
  • Active participation in industry security groups such as the FIRST PSIRT SIG, OpenSSF working groups, OCP Security, or PSIRT Services Framework contributors.
  • Familiarity with bug bounty platform operations, including researcher engagement and reputation management.
  • Experience contributing to or interpreting regulator guidance (e.g., ENISA, national cybersecurity agencies) and participation in relevant standards bodies (e.g., TCG, IETF, IEEE).
  • Relevant industry certifications a plus: CISSP, CISM, CSSLP, or equivalent.

This role is not eligible for visa sponsorship.

#LI-BW2

#LI-HYBRID

Benefits offered are described: AMD benefits at a glance.

AMD and its subsidiaries are equal opportunity, inclusive employers and will consider all applicants without regard to age, ancestry, color, marital status, medical condition, mental or physical disability, national origin, race, religion, political and/or third-party affiliation, sex, pregnancy, sexual orientation, gender identity, military or veteran status, or any other characteristic protected by law. We encourage applications from all qualified candidates and will accommodate applicants' needs under the respective laws throughout all stages of the recruitment and selection process.

AMD may use Artificial Intelligence to help screen, assess or select applicants for this position. AMD's "Responsible AI Policy" is available here.

This posting is for an existing vacancy.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Product Security Program Leader
Principal Product Security Program Leader

Advanced Micro Devices • San Jose (CA), Northern (KY)

Hybrid
USD 240,000 - 360,000
Director Security Technology Engineering
Director Security Technology Engineering

Advanced Micro Devices • Austin (TX)

Hybrid
USD 150,000 - 230,000
AMD benefits
Director Security Technology Engineering
Director Security Technology Engineering

Socket.dev • Austin (TX)

On-site
USD 180,000 - 240,000
SoC Security Architect
SoC Security Architect

Advanced Micro Devices, Inc. • Santa Clara (CA)

Hybrid
USD 130,000 - 165,000
Comprehensive benefits plan
Flexible work environment
Career development opportunities
Security Software Engineer
Security Software Engineer

Advanced Micro Devices • San Jose (CA)

On-site
USD 100,000 - 130,000
Comprehensive AMD benefits
Collaborative work environment
Security Software Engineer
Security Software Engineer

AMD • United States

Hybrid
USD 140,000 - 210,000
SoC Security Architect
SoC Security Architect

Advanced Micro Devices • Austin (TX)

Hybrid
USD 120,000 - 160,000
Product Manager - Embedded Platforms
Product Manager - Embedded Platforms

Advanced Micro Devices • Austin (TX)

On-site
USD 120,000 - 180,000
AMD benefits at a glance
Senior Product Security Leader – Embedded & AI Systems
Senior Product Security Leader – Embedded & AI Systems

AMD • San Jose (CA)

Hybrid
USD 180,000 - 240,000
Hybrid work
Benefits at a glance
Embedded Systems Architect – Aerospace & Defense
Embedded Systems Architect – Aerospace & Defense

Advanced Micro Devices • San Jose (CA)

Hybrid
USD 180,000 - 240,000
AMD benefits
Hybrid work model