Product Security Manager

symplr

United States

On-site

USD 120,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

symplr is seeking a Product Security Manager to drive security across enterprise software products from development through deployment and maintenance. You will define security requirements, perform threat modeling, and lead vulnerability management with cross‑functional teams to embed security in CI/CD pipelines.

The role emphasizes incident response readiness and ongoing security improvements. Ideal candidates have 4–5+ years of security experience, CISSP/CSSLP/CISM/CCSP are a plus, and strong

Qualifications

  • University degree in Information Security, Computer Science, Computer Engineering, Information Technology (or equivalent).
  • 4–5 years of relevant corporate information security industry experience.
  • Certifications such as CISSP, CSSLP, CISM, CCSP are a plus.
  • Knowledge of cybersecurity frameworks and regulatory requirements (HIPAA, NIST, ISO/IEC 27001).
  • Experience with threat modeling, risk assessment, and security lifecycle management.

Responsibilities

  • Define and enforce security requirements for software products and features throughout the lifecycle.
  • Perform threat modeling, privacy impact assessments, SAST/DAST, and third‑party penetration testing.
  • Identify, assess, and prioritize product security risks and vulnerabilities.
  • Collaborate across teams to embed security tooling in CI/CD and shift‑left security.
  • Lead WAF deployments and adoption initiatives for commercial products.
  • Track security performance, incidents, and continuous improvements.

Skills

Cloud security
Threat modeling
Vulnerability management
OWASP
SAST/DAST
Penetration testing
Python scripting
CI/CD security
Web technologies

Education

Bachelor's degree in Info Security
CISSP
CSSLP
CISM
CCSP

Tools

Burp Suite
GitHub Advanced Security
Qualys
Tenable
Barracuda WAF
AWS
Azure

Job description

Overview

The Product Security Manager is an individual with solid hands‑on technical understanding of enterprise security solutions, cloud infrastructure and services platforms (AWS & Azure), latest security regulations, security best practices and security threats. In this individual contributor role, you will support various security initiatives in support of commercial software products from development through deployment and ongoing maintenance. You’ll work with cross‑functional teams to protect our products and users from emerging security threats throughout the security development lifecycle. The person assists the security team in improving the security measures, maintaining and enforcing security policies, and ensuring compliance.

Duties & Responsibilities
  • Define and enforce security requirements for software products, features, and components. Ensure security considerations are included in the product roadmap and development plans
  • Design, perform, and maintain security analysis on commercial products throughout the product lifecycle including controls assessments, threat modeling, privacy impact assessments, SAST, DAST, and third‑party application penetration testing
  • Identify, assess, and prioritize product security risks
  • Collaborate with cross‑functional teams to perform vulnerability management of identified risks and implement strategies for mitigating identified risks
  • Work cross‑functionally to ensure that security tooling is embedded in the product CI/CD pipelines to adopt shift left security
  • Collaborate with the product, engineering, and other stakeholders to lead WAF deployments and adoption initiatives as it relates to commercial product
  • Track and report on product security performance, including effectiveness of security measures, incidents, and ongoing security improvements
  • Participate in incident response activities as they relate to application security
Skills Required
  • Technical proficiency with software engineering methodologies such as peer reviews and continuous integration.
  • Technical experience in OWASP web application and web services security vulnerabilities including cross‑site scripting, cross‑site request forgery, SQL injection, DoS attacks, XML/SOAP, and API attacks.
  • Experience with technical threat assessments and threat modeling of software applications and hardware devices using tools such as Microsoft Threat Modeling tool
  • Experience with technical vulnerability discovery using tools such as Burpsuite, GitHub Advanced Security, Qualys, and Tenable
  • Experience with industry standards and compliance standards such as NIST, HIPAA, and OWASP
  • Experience with penetration testing tools and methodologies
  • Experience with vulnerability management
  • Experience with scripting languages such as PowerShell, Python, or Perl
  • Solid understanding of web applications, web servers, application firewalls, and protocols with respect to web application development, deployment, and operation
  • Knowledge of web technologies and concepts
  • Understanding of AWS and Azure cloud technologies
  • Understanding of Web Application Firewalls including Barracuda, AWS, and Cloudflare
  • Understanding of TCP/IP, web protocols and networking concepts
  • Understanding of PKI Technology
  • Understanding of incident response processes
Required Education, Experience, Skills and Abilities
  • University degree in Information Security, Computer Science, Computer Engineering, Information Technology (or equivalent of education and work experience)
  • Minimum of 4‑5 years of relevant corporate information security industry experience
  • Healthcare technology industry experience is a bonus
  • One or more of the following certifications: CISSP, CSSLP, CISM, CCSP
  • Knowledge of cybersecurity frameworks and relevant regulatory requirements
  • Proven technical experience in Threat Modeling, Risk Assessment, and Security Lifecycle Management
  • Technical understanding of systems, applications, and databases
  • Technical expertise in cloud infrastructure and services platforms (AWS and Azure preferred)
  • Excellent communication skills at all organizational levels
  • Strong project management and time management skills
  • High level of personal integrity and ability to professionally handle confidential matters
  • Capable of acting calmly and managing incidents under high pressure and stress
  • Capable of multitasking in a fast paced, multifaceted environment
  • Ability to work well with customers, peers, and management
  • Proficient with the Microsoft Office Suite, Visio, and SharePoint
Preferred Education, Experience, Skills and Abilities
  • Bachelor’s degree in Information Security, Computer Science, Computer Engineering, Information Technology (or equivalent of education and work experience)
  • 5‑7 years of relevant corporate information security industry experience
  • AWS Cloud Security and/or Microsoft Azure Security certifications are a plus
  • Familiarity with DevOps toolchain (e.g. Terraform, Jenkins)
  • Familiarity with cloud security, including but not limited to CSPM, CASB, DLP, IAM, and vulnerability management
  • Familiarity with technical skills in enterprise security and networking protocols
  • Demonstrated experience and knowledge of relevant regulatory and security framework requirements, such as The U.S. Health Insurance Portability and Accountability Act (HIPAA) and NIST 800 and ISO/IEC 27001/27002
  • Previous working experience in healthcare technology environments

Min Salary: USD $120,000.00/Yr.

Max Salary: USD $140,000.00/Yr.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Security Engineer Senior
Product Security Engineer Senior

Jobgether • United States

On-site
USD 140,000 - 190,000
Medical benefits
Retirement savings program
Professional development
Senior Information Protection Advisor – Product Security, DevSecOps
Senior Information Protection Advisor – Product Security, DevSecOps

Jobtailor • Connecticut

On-site
USD 120,000 - 180,000
VP Security Guardian, Product Security
VP Security Guardian, Product Security

Jobtailor • Massachusetts

On-site
USD 140,000 - 190,000
Product Manager - Security Engineering
Product Manager - Security Engineering

customsoftwaresystems • Washington

Hybrid
USD 140,000 - 190,000
Health insurance
Health Savings Account (HSA)
Dental
+6
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Product Manager - Endpoint Management & Security
Product Manager - Endpoint Management & Security

United States Digital Space LLC • United States

Hybrid
USD 150,000 - 200,000
Medical insurance
Dental insurance
Vision insurance
+3
Senior Information Security Engineer
Senior Information Security Engineer

Jobtailor • Sandy (UT)

On-site
USD 110,000 - 170,000
Senior IT Security Manager I
Senior IT Security Manager I

GoFormz • San Diego (CA)

On-site
USD 150,000 - 190,000