Principal Product Security Program Leader

Advanced Micro Devices

San Jose, Northern (CA, KY)

Hybrid

USD 240,000 - 360,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Advanced Micro Devices (AMD) is seeking an experienced Product Security Leader to own end-to-end governance across the Adaptive & Embedded Computing unit. You’ll drive vulnerability response, SDL governance, and regulatory compliance for AMD's product lines, partnering with PSO, Legal, and engineering teams.

The role requires leadership of PSIRT programs, triage of vulnerability reports, and coordination with researchers, OEMs, and hyperscalers.

Qualifications

  • Expert-level product security leadership experience in semiconductors, EDA software, embedded systems, or similar; FPGA/adaptive computing is a plus.

Responsibilities

  • Own product security governance for the business unit, interfacing with Product Security Office on vulnerability management and SDL health.
  • Coordinate response across embedded security teams to triage and resolve vulnerability reports from researchers, internal teams, and customers.
  • Maintain and evolve the security threat model for adaptive-computing design tools.
  • Align the business unit with EU CRA, GDPR, SBOM and vulnerability disclosure obligations with Legal and Compliance.
  • Facilitate customer-facing security assessments and due-diligence requests.
  • Lead incident response for high-severity vulnerabilities and coordinate disclosure with partners and customers.
  • Brief leadership on security posture, incidents, and program health.

Skills

Product security leadership
PSIRT program management
Regulatory compliance knowledge
Executive communication
Vulnerability triage & disclosure

Tools

Coverity
CodeQL
Black Duck
SPDX/CycloneDX

Job description

ADVANCE YOUR CAREER. ADVANCE THE WORLD.

At AMD, we believe technology can change lives for the better. It can heal us, entertain us, and make us more connected, productive, and understanding of the world around us. And we’re looking for talent who feel the same: people who want to leave the planet better than they found it, those who don’t shy away from humanity’s challenges but are determined to help solve them.

AMD is powering the next generation of supercomputing, high-performance computing, cloud, and AI. Whether you’re designing next-gen processors, enabling AI breakthroughs, or creating go-to-market plans, every role at AMD contributes to something bigger — technology that moves the world forward.

About the Role

AMD is seeking an experienced Product Security Leader to serve as the primary point of accountability for product security across the Adaptive & Embedded Computing (AECG) business unit. This role owns end-to-end coordination of vulnerability response, secure development lifecycle (SDL) governance, and regulatory compliance for AMD's Adaptive and Embedded Computing product lines. The successful candidate will partner closely with AMD's Product Security Office (PSO), Corporate Legal and business-unit security subject matter experts across hardware, firmware, and software tooling teams.

This is a high-visibility role that is critical to meeting AMD's security commitments to its customers, including the EU Cyber Resilience Act (CRA), GDPR, and contractual security obligations with hyperscale and OEM partners.

Key Responsibilities
  • Own product security governance for the business unit — primary interface with AMD's Product Security Office on vulnerability management, SDL health, and remediation progress.
  • Coordinate response across embedded security experts spanning silicon, firmware, and software tooling to triage and resolve vulnerability reports from researchers, internal teams, and customers.
  • Maintain and evolve the security threat model for AMD's adaptive-computing design tools.
  • Partner with Legal and Compliance to align the business unit with the EU Cyber Resilience Act, GDPR, and related regulatory requirements, including SBOM and vulnerability disclosure obligations.
  • Facilitate customer-facing security assessments and due-diligence requests.
  • Serve as incident lead for high-severity vulnerabilities and active exploit reports, driving timely resolution and coordinated disclosure with partners and customers.
  • Brief business-unit and executive leadership on security posture, material incidents, and program health.
Required Qualifications
  • Expert level of product security, PSIRT, or Security Design Lifecycle leadership experience in semiconductor, EDA software, embedded systems, or a comparable industry; FPGA / adaptive computing experience is a strong plus.
  • Demonstrated leadership with a PSIRT or product coordinated vulnerability disclosure (CVD) program, including triage, CVSS scoring, CVE assignment, security bulletin/advisory authoring, and coordinated disclosure with hyperscalers, OEMs, and independent security researchers.
  • Working expertise with SAST tooling (e.g., Coverity, CodeQL), SCA/SBOM tooling (e.g., Black Duck, SPDX, CycloneDX), threat modeling methodologies, and secure SDLC frameworks (eg, ISO/SAE 21434, NIST SSDF).
  • Demonstrated familiarity with the EU Cyber Resilience Act (CRA), GDPR, and adjacent global cybersecurity regulations, with the ability to translate regulatory text into engineering requirements.
  • Track record partnering with Legal, Corporate Communications, and Compliance teams on regulated disclosures and customer-facing security assessments.
  • Strong executive communication skills: able to produce concise status reporting, brief senior leadership, and translate technical findings into business and customer impact.
Preferred Qualifications
  • Experience with FPGA design tool flows (e.g., Vivado, Vitis, Vitis HLS) and embedded software stacks (e.g., PetaLinux, Yocto, Xen).
  • Familiarity with information security management standards such as ISO/IEC 27001, in addition to product-security-specific frameworks.
  • Active participation in industry security groups such as the FIRST PSIRT SIG, OpenSSF working groups, OCP Security, or PSIRT Services Framework contributors.
  • Familiarity with bug bounty platform operations, including researcher engagement and reputation management.
  • Experience contributing to or interpreting regulator guidance (e.g., ENISA, national cybersecurity agencies) and participation in relevant standards bodies (e.g., TCG, IETF, IEEE).
  • Relevant industry certifications a plus: CISSP, CISM, CSSLP, or equivalent.

This role is not eligible for visa sponsorship.

#LI-BW2

#LI-HYBRID

Benefits offered are described: AMD benefits at a glance.

AMD does not accept unsolicited resumes from headhunters, recruitment agencies, or fee-based recruitment services. AMD and its subsidiaries are equal opportunity, inclusive employers and will consider all applicants without regard to age, ancestry, color, marital status, medical condition, mental or physical disability, national origin, race, religion, political and/or third-party affiliation, sex, pregnancy, sexual orientation, gender identity, military or veteran status, or any other characteristic protected by law. We encourage applications from all qualified candidates and will accommodate applicants’ needs under the respective laws throughout all stages of the recruitment and selection process.

AMD may use Artificial Intelligence to help screen, assess or select applicants for this position. AMD’s “Responsible AI Policy” is available here.

This posting is for an existing vacancy.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Product Security Program Leader
Principal Product Security Program Leader

AMD • San Jose (CA)

Hybrid
USD 180,000 - 240,000
Hybrid work
Benefits at a glance
Director Security Technology Engineering
Director Security Technology Engineering

Advanced Micro Devices • Austin (TX)

Hybrid
USD 150,000 - 230,000
AMD benefits
Director Security Technology Engineering
Director Security Technology Engineering

Socket.dev • Austin (TX)

On-site
USD 180,000 - 240,000
Security Software Engineer
Security Software Engineer

AMD • United States

Hybrid
USD 140,000 - 210,000
Security Software Engineer
Security Software Engineer

Advanced Micro Devices • San Jose (CA)

On-site
USD 100,000 - 130,000
Comprehensive AMD benefits
Collaborative work environment
SoC Security Architect
SoC Security Architect

Advanced Micro Devices, Inc. • Santa Clara (CA)

Hybrid
USD 130,000 - 165,000
Comprehensive benefits plan
Flexible work environment
Career development opportunities
Product Manager - Embedded Platforms
Product Manager - Embedded Platforms

Advanced Micro Devices • Austin (TX)

On-site
USD 120,000 - 180,000
AMD benefits at a glance
Director Security Technology Engineering
Director Security Technology Engineering

AMD • Austin (TX)

On-site
USD 180,000 - 240,000
SoC Security Architect
SoC Security Architect

Advanced Micro Devices • Austin (TX)

Hybrid
USD 120,000 - 160,000
Embedded Systems Architect – Aerospace & Defense
Embedded Systems Architect – Aerospace & Defense

Advanced Micro Devices • San Jose (CA)

Hybrid
USD 180,000 - 240,000
AMD benefits
Hybrid work model