Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Qualifications
Leadership & Executive Management
- 12+ years of progressive experience in cybersecurity, application security, product security, cloud security, or security architecture, including7+ years in senior leadership roles managing globally distributed security, engineering, and architecture teams.
- Proven experience building, scaling, and leading high-performing Product Security organizations supporting large-scale SaaS, cloud-native, and enterprise software platforms.
- Demonstrated success leading directors, senior managers, architects, and security engineering teams across multiple geographies and product portfolios.
- Experience owning multi-million-dollar security budgets, strategic planning processes, headcount forecasting, vendor relationships, and security program execution.
- Strong executive presence with the ability to communicate technical risk, business impact, and security strategy to Boards of Directors, Executive Leadership Teams, auditors, regulators, and customer executives.
- Proven ability to influence security and product roadmaps across Engineering, Product Management, Cloud Operations, Legal, Compliance, Customer Success, Sales Engineering, and Corporate Security organizations.
- Experience participating in M&A due diligence, product security assessments, and post-acquisition security integration activities is highly desirable.
Product Security & Secure Engineering
- Deep expertise in product security, application security, cloud security, DevSecOps, software supply chain security, and secure software development lifecycle (SSDLC) practices.
- Demonstrated experience implementing and scaling: Security-by-design principles
- Threat modeling frameworks
- Secure coding standards
- Vulnerability management programs
- Red teaming exercises
- Bug bounty and responsible disclosure programs
- Software supply chain security controls
- SBOM management
- Secure CI/CD pipelines
- Container and Kubernetes security
- Extensive knowledge of modern authentication and identity architectures including: Zero Trust, OAuth2, OpenID Connect, SAML, PKI, Hardware-backed cryptography, Secrets management, PAM solutions
- Deep understanding of modern security frameworks including: NIST Cybersecurity Framework, NIST SP 800-53, NIST SP 800-171, NIST SP 800-218 (SSDF), CIS Controls, OWASP Top 10, OWASP ASVS
- SOC 2
- ISO 2701
Federal Compliance & Government Security Experience
- FEDRAMP
- 10+ years of experience supporting U.S. federal cybersecurity programs and regulatory frameworks.
- Proven experience leading, achieving, and sustaining multiple FedRAMP Moderate and FedRAMP High Authorizations to Operate (ATO) for cloud-native SaaS products.
- Extensive experience working directly with: Federal Agencies, Joint Authorization Board (JAB) stakeholders, Third Party Assessment Organizations (3PAOs), Authorizing Officials, Government security assessors.
- Deep knowledge of: NIST SP 800-53 Rev. 5, FedRAMP Continuous Monitoring, POA&M management, Significant Change Requests, Annual Assessments, Vulnerability remediation requirements.
Configuration management controls
- Configuration management controls.
- Demonstrated ownership of security strategy and product architecture supporting regulated government cloud environments.
CMMC & DoD Cloud Requirements
- Hands-on experience implementing and managing environments aligned to: CMMC Level 2 requirements, NIST SP 800-171, DFARS 252.204-7012, DFARS 252.204-7019, DFARS 252.204-7020, DFARS 252.204-7021
- Experience designing and securing solutions deployed within Department of Defense environments requiring Impact Level (IL) authorization.
- Demonstrated knowledge and practical experience supporting: DoD Impact Level 4 (IL4), DoD Impact Level 5 (IL5), DoD Impact Level 6 (IL6).
- Experience working with government customers handling Controlled Unclassified Information (CUI), National Security Systems (NSS), and classified or highly regulated workloads.
- Familiarity with DISA STIGs, SRGs, DoD Cloud Computing Security Requirements Guide (CC SRG), and associated authorization processes.
NIAP & Common Criteria
- Experience leading or supporting NIAP Common Criteria certification efforts for enterprise software, networking products, endpoint security solutions, or cybersecurity technologies.
- Strong understanding of: Common Criteria Evaluation and Validation Scheme (CCEVS), Protection Profiles, Security Targets, Evaluation Assurance Levels (EAL), NIAP product certification lifecycle.
- Experience working with accredited testing laboratories and certification authorities to achieve and maintain product certifications.
Multi-Cloud Security & Hyperscaler Expertise
- 15+ years of experience designing and securing cloud-native SaaS platforms operating at enterprise scale.
- Demonstrated architecture and operational expertise across multiple hyperscale cloud service providers including:
Amazon Web Services (AWS)
- Experience securing AWS environments leveraging: Organizations, IAM, KMS, CloudTrail, GuardDuty, Security Hub, Control Tower, ECS/EKS.
Microsoft Azure
- Experience securing Azure environments utilizing: Entra ID, Azure Policy, Defender for Cloud, Key Vault, Azure Monitor, Microsoft Sentinel, AKS, Landing Zone architectures.
Google Cloud Platform (GCP)
- Experience designing secure GCP architectures leveraging: Cloud IAM, Security Command Center, Cloud KMS, Anthos, Chronicle, Organization Policies, GKE security controls.
Oracle Cloud Infrastructure (OCI)
- Experience securing OCI environments including: OCI IAM, OCI Vault, Cloud Guard, Security Zones, OCI Logging, OCI Container Engine for Kubernetes (OKE).
Experience developing governance models and security architectures across multi-cloud and hybrid-cloud environments.
- Demonstrated track record implementing consistent security controls, monitoring, identity governance, and compliance frameworks across AWS, Azure, GCP, and OCI.
Preferred Qualifications
- CISSP, CCSP, GIAC, SABSA, or equivalent advanced security certifications.
- Prior experience serving as: VP Product Security, Head of Product Security, Chief Product Security Officer, Distinguished Security Architect, Senior Security Executive within a cybersecurity or cloud technology company.
- Experience working in publicly traded technology organizations and interacting with Audit Committees and Board-level Cybersecurity Committees.
- Experience supporting enterprise cybersecurity products, vulnerability management platforms, endpoint security solutions, cloud security tools, SIEMs, or security operations technologies.
Qualys is an Equal Opportunity Employer, please see our EEO policy.