Product Security Lead

Madison-Davis, LLC

New York (NY)

Hybrid

USD 180,000 - 240,000

Full time

39 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Madison-Davis, LLC is seeking a hands-on Product Security Lead to embed security across application and data lifecycles. You will work with software engineering, platform, and data teams to strengthen secure development, automate security controls, and identify risk earlier in delivery processes.

The role spans application security, cloud security, data security, and AI-security initiatives. You will remain technically involved while helping engineering teams adopt stronger security practices,

Qualifications

  • Hands-on threat-modeling and design-risk-assessment experience.
  • Strong Secure SDLC and DevSecOps expertise.
  • Experience delivering SAST/DAST and software composition analysis capabilities.
  • Solid data-security knowledge and cloud-security experience across IaaS, PaaS, SaaS.

Responsibilities

  • Embed security into application and data lifecycles.
  • Advance secure-development and DevSecOps practices.
  • Integrate automated security testing into CI/CD pipelines.
  • Conduct threat modeling and application-design risk assessments.
  • Deliver and improve SAST, DAST, and software composition analysis capabilities.
  • Validate and prioritize security findings while reducing false positives.
  • Address open-source and third-party dependency risk.
  • Support security across cloud and data environments.
  • Guide security practices for emerging AI-enabled applications.
  • Partner with engineering, platform, and data teams to strengthen security ownership.

Skills

Application security
DevSecOps
Threat modeling
SAST/DAST
Data security
Cloud security
AI security
Communication
Hybrid NYC schedule

Job description

A global financial institution is seeking a hands-on Product Security Lead to embed security throughout application and data lifecycles. The role works closely with software engineering, platform, and data teams to strengthen secure development, automate security controls, assess application designs, and identify risk earlier in the delivery process.

This person will operate across application security, DevSecOps, cloud security, data security, and emerging AI-security initiatives. The position requires someone who can remain technically involved while helping engineering teams adopt stronger security practices.

Responsibilities
  • Embed security into application and data-development lifecycles.
  • Advance secure-development and DevSecOps practices.
  • Integrate automated security testing and policy controls into CI/CD pipelines.
  • Conduct threat modeling and application-design risk assessments.
  • Deliver and improve SAST, DAST, and software composition analysis capabilities.
  • Validate and prioritize security findings while reducing false positives.
  • Address open-source and third-party dependency risk.
  • Support security across cloud and data environments.
  • Guide security practices for emerging AI-enabled applications.
  • Partner with engineering, platform, and data teams to strengthen security ownership.
Role Requirements
  • Extensive experience in product, application, or software-security engineering.
  • Strong Secure SDLC and DevSecOps expertise.
  • Hands-on threat-modeling and design-risk-assessment experience.
  • SAST, DAST, and software composition analysis experience.
  • Strong data-security knowledge.
  • Hands-on cloud-security experience across IaaS, PaaS, and SaaS.
  • Practical knowledge of emerging AI-security risks and controls.
  • Strong communication, stakeholder-management, and influencing skills.
  • Ability to meet the required New York City hybrid schedule.
How We Work
  • Security partners directly with engineering, platform, and data teams.
  • Security controls are expected to be integrated into the development lifecycle.
  • The role balances hands-on technical involvement with security-practice leadership.
  • The position follows a hybrid New York City schedule.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Product Security Lead - Cloud, Data & AI Security | Global Banking and Markets Group
Product Security Lead - Cloud, Data & AI Security | Global Banking and Markets Group

Techfellow Limited • New York (NY)

Hybrid
USD 180,000 - 275,000
Product Security Lead - Hybrid NYC, DevSecOps & Cloud
Product Security Lead - Hybrid NYC, DevSecOps & Cloud

Madison-Davis, LLC • New York (NY)

Hybrid
USD 180,000 - 240,000
Technical Product Security Engineer
Technical Product Security Engineer

Audit Data Search, Inc. • New York (NY)

On-site
USD 130,000 - 160,000
Sr. Lead Cybersecurity Architect - Product Security Lead
Sr. Lead Cybersecurity Architect - Product Security Lead

JPMorgan Chase & Co. • Jersey City (NJ)

On-site
USD 120,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Mode Analytics • Phoenix (AZ)

On-site
USD 130,000 - 190,000
Product Security Engineer
Product Security Engineer

Stellar IT Solutions LLC • Sunnyvale (CA)

On-site
USD 140,000 - 200,000
Senior Director, Product and Platform Security
Senior Director, Product and Platform Security

Ladders • United States

Remote
USD 275,000 - 440,000
Flexible work arrangements
Comprehensive benefits package
AI tools access
+1
Product Security Engineer
Product Security Engineer

GoMining • Georgia

On-site
USD 120,000 - 180,000
Professional growth
Remote or hybrid format
Vacation and holidays
+3
Product Security Engineer
Product Security Engineer

GoMining • Town of Poland (NY)

On-site
USD 120,000 - 190,000
Professional growth support
Flexible hours
Vacation and holidays
Senior Product Security Engineer
Senior Product Security Engineer

Gofractional • Northern (KY)

On-site
USD 83,000 - 165,000
Medical coverage
Dental coverage
Vision coverage
+7