Vice President, Product Security

qualys

Virginia (MN)

On-site

USD 240,000 - 320,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Qualys is seeking an experienced security leader to drive product security and secure engineering across globally distributed teams. You will influence roadmaps, translate complex risk to executive stakeholders, and manage large security budgets for a SaaS/cloud-native portfolio.

The ideal candidate has senior leadership experience in secure software, cloud security, and regulatory programs such as FedRAMP/DoD, with a proven track record of collaboration across engineering, product, and legal

Qualifications

  • Senior-level experience in cybersecurity leadership across security, engineering, and architecture teams.
  • Proven ability to build and scale product security in large SaaS/cloud-native environments.
  • Experience communicating risk and security strategy to boards and executives.
  • Ability to influence roadmaps across engineering, product, cloud ops, legal, and compliance.

Responsibilities

  • Lead globally distributed Product Security and Secure Engineering teams.
  • Own multi-year security strategy, budgets, headcount planning, and vendor relationships.
  • Oversee FedRAMP/DoD and government security program execution and audits.

Skills

Security leadership
Product security
Cloud security
Executive communication
Cross-functional collaboration

Job description

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Qualifications
Leadership & Executive Management
  • 1 2 + years of progressive experience in cybersecurity, application security, product security, cloud security, or security architecture, including 7 + years in senior leadership roles managing globally distributed security, engineering, and architecture teams.
  • Proven experience building, scaling, and leading high-performing Product Security organizations supporting large-scale SaaS, cloud-native, and enterprise software platforms.
  • Demonstrated success leading directors, senior managers, architects, and security engineering teams across multiple geographies and product portfolios.
  • Experience owning multi-million-dollar security budgets, strategic planning processes, headcount forecasting, vendor relationships, and security program execution.
  • Strong executive presence with the ability to communicate technical risk, business impact, and security strategy to Boards of Directors, Executive Leadership Teams, auditors, regulators, and customer executives.
  • Proven ability to influence security and product roadmaps across Engineering, Product Management, Cloud Operations, Legal, Compliance, Customer Success, Sales Engineering, and Corporate Security organizations.
  • Experience participating in M&A due diligence, product security assessments, and post-acquisition security integration activities is highly desirable.
Product Security & Secure Engineering

Deep expertise in product security, application security, cloud security, DevSecOps , software supply chain security, and secure software development lifecycle (SSDLC) practices.

  • Security-by-design principles
  • Threat modeling frameworks
  • Secure coding standards
  • Vulnerability management programs
  • Red teaming exercises
  • Bug bounty and responsible disclosure programs
  • Software supply chain security controls
  • SBOM management
  • Secure CI/CD pipelines
  • Container and Kubernetes security

Extensive knowledge of modern authentication and identity architectures including:

  • Zero Trust
  • OAuth2
  • OpenID Connect
  • SAML
  • PKI
  • Hardware-backed cryptography
  • Secrets management
  • PAM solutions

Deep understanding of modern security frameworks including:

  • NIST Cybersecurity Framework
  • NIST SP 800-53
  • NIST SP 800-171
  • NIST SP 800-218 (SSDF)
  • CIS Controls
  • OWASP Top 10
  • OWASP ASVS
  • SOC 2
  • ISO 27001
Federal Compliance & Government Security Experience
  • FedRAMP

10+ years of experience supporting U.S. federal cybersecurity programs and regulatory frameworks.

Proven experience leading, achieving, and sustaining multiple FedRAMP Moderate and FedRAMP High Authorizations to Operate (ATO) for cloud-native SaaS products.

Extensive experience working directly with:

  • Federal Agencies
  • Joint Authorization Board (JAB) stakeholders
  • Third Party Assessment Organizations (3PAOs)
  • Authorizing Officials
  • Government security assessors

Deep knowledge of:

  • NIST SP 800-53 Rev. 5
  • FedRAMP Continuous Monitoring
  • POA&M management
  • Significant Change Requests
  • Annual Assessments
  • Vulnerability remediation requirements
  • Configuration management controls

Demonstrated ownership of security strategy and product architecture supporting regulated government cloud environments.

CMMC & DoD Cloud Requirements

Hands-on experience implementing and managing environments aligned to:

  • CMMC Level 2 requirements
  • NIST SP 800-171
  • DFARS 252.204-7012
  • DFARS 252.204-7019
  • DFARS 252.204-7020
  • DFARS 252.204-7021

Experience designing and securing solutions deployed within Department of Defense environments requiring Impact Level (IL) authorization.

Demonstrated knowledge and practical experience supporting:

  • DoD Impact Level 4 (IL4)
  • DoD Impact Level 5 (IL5)
  • DoD Impact Level 6 (IL6)

Experience working with government customers handling Controlled Unclassified Information (CUI), National Security Systems (NSS), and classified or highly regulated workloads.

Familiarity with DISA STIGs, SRGs, DoD Cloud Computing Security Requirements Guide (CC SRG), and associated authorization processes.

NIAP & Common Criteria

Experience leading or supporting NIAP Common Criteria certification efforts for enterprise software, networking products, endpoint security solutions, or cybersecurity technologies.

Strong understanding of:

  • Common Criteria Evaluation and Validation Scheme (CCEVS)
  • Protection Profiles
  • Security Targets
  • Evaluation Assurance Levels (EAL)
  • NIAP product certification lifecycle

Experience working with accredited testing laboratories and certification authorities to achieve and maintain product certifications.

Multi-Cloud Security & Hyperscaler Expertise

15+ years of experience designing and securing cloud-native SaaS platforms operating at enterprise scale.

Demonstrated architecture and operational expertise across multiple hyperscale cloud service providers including:

  • Amazon Web Services (AWS)
  • Ex
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Vice President, Product Security
Vice President, Product Security

Socket.dev • Virginia (MN)

Hybrid
USD 210,000 - 320,000
Vice President, Product Security
Vice President, Product Security

Qualys • Virginia (MN)

On-site
USD 260,000 - 340,000
Cloud Subject Matter Expert / Cloud Security Architect
Cloud Subject Matter Expert / Cloud Security Architect

Intellect Solutions LLC • Rockville (MD), Northern (KY)

Hybrid
USD 150,000 - 210,000
Security clearance assistance
Cyber Product Owner
Cyber Product Owner

Jobtailor • Town of Texas (WI)

On-site
USD 120,000 - 180,000
Cyber Cloud Security Engineer
Cyber Cloud Security Engineer

Pierce • New York (NY)

On-site
USD 140,000 - 190,000
Cybersecurity Engineer - Cloud, Ops (human)
Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics • Germany (OH)

On-site
USD 120,000 - 160,000
Security Software Engineer
Security Software Engineer

Eccalon, LLC • Hanover (MD)

On-site
USD 120,000 - 190,000
Security Software Engineer On-site
Security Software Engineer On-site

Eccalon, LLC • Detroit (MI)

On-site
USD 110,000 - 145,000
Cloud Security Engineer
Cloud Security Engineer

apex-technology-inc • Los Angeles (CA)

On-site
USD 180,000 - 240,000
Cloud Security Engineer, AWS GovCloud
Cloud Security Engineer, AWS GovCloud

apex-technology-inc • Los Angeles (CA)

On-site
USD 140,000 - 190,000