Product Security Lead

1 Month ago • 8 Years + • Product

Job Summary

Job Description

Smarsh is seeking a Product Security Lead to embed security into the software development lifecycle. This role involves conducting threat modeling, security design reviews, and vulnerability management. The lead will also perform secure code reviews, architectural security assessments, and enhance security automation in CI/CD pipelines. Responsibilities include facilitating penetration testing, building security awareness through a Security Champion program, and supporting incident response readiness. The position also requires ensuring alignment with regulatory requirements like SOC 2 and ISO 27001, and supporting audit activities.
Must have:
  • 8+ years in Product Security/AppSec.
  • Expertise in secure SDLC, coding practices, OWASP Top 10.
  • Proficiency in modern programming languages (Python, Java, JS, Go, C#).
  • Experience with cloud-native security (AWS, Azure, GCP).
  • Familiarity with CI/CD security automation.
  • Strong understanding of IAM and API security.
  • Excellent communication and collaboration skills.
Good to have:
  • OSCP, GIAC, CISSP, or CSSLP certifications.
  • Experience in SaaS environments.
  • Knowledge of machine learning security.
  • Familiarity with attack surface management.

Job Details

Who are we?

Smarsh empowers its customers to manage risk and unleash intelligence in their digital communications. Our growing community of over 6500 organizations in regulated industries counts on Smarsh every day to help them spot compliance, legal or reputational risks in 80+ communication channels before those risks become regulatory fines or headlines.  Relentless innovation has fueled our journey to consistent leadership recognition from analysts like Gartner and Forrester, and our sustained, aggressive growth has landed Smarsh in the annual Inc. 5000 list of fastest-growing American companies since 2008.

Key Responsibilities

    • Secure SDLC Integration: Embed security within the software development lifecycle, ensuring security is considered at every phase—from design to deployment.
    • Threat Modeling & Security Design Reviews: Conduct structured threat modeling and security assessments for new features, architectures, and services.
    • Vulnerability Management & Remediation: Work closely with engineering teams to identify and remediate vulnerabilities from SAST, DAST, SCA, container security, and cloud security scans.
    • Code & Architecture Review: Conduct secure code reviews and architectural security assessments to identify risks early in the development process.
    • Automation & Tooling: Enhance security automation capabilities by integrating security testing tools into CI/CD pipelines.
    • Penetration Testing & Red Teaming: Facilitate internal and external penetration testing activities, helping to triage and remediate findings.
    • Security Champion Enablement: Collaborate with engineering teams to build security awareness and develop a network of Security Champions.
    • Incident & Response Readiness: Support Smarsh SOC and security incident response, including root cause analysis and post-mortem reviews for your product(s).
    • Security Compliance & Governance: Ensure alignment with regulatory requirements (SOC 2, ISO 27001, etc.) and support audit activities

Qualifications & Experience

    • 8 + years of experience in Product Security, Application Security, or a related security engineering role.
    • Deep expertise in secure software development, secure coding practices, and OWASP Top 10 / CWE 25.
    • Strong technical proficiency in modern programming languages (e.g., Python, Java, JavaScript, Go, or C#).
    • Experience with cloud-native security (AWS, Azure, GCP) and securing containerized environments (Docker, Kubernetes).
    • Proficiency in security testing tools such as Burp Suite, Endor, Semgrep, etc.
    • Strong background in network security, including firewalls, IDS/IPS, VPNs, and secure network design.
    • Hands-on experience with CI/CD security automation (GitHub Actions, Jenkins, GitLab CI, etc.).
    • Familiarity with infrastructure-as-code security (Terraform, CloudFormation) and cloud security posture management.
    • Strong understanding of identity & access management (OAuth, OIDC, SAML, JWT) and API security.
    • Knowledge of industry frameworks like NIST, ISO 27001, and SOC 2. 
    • Experience driving developer enablement and security training initiatives.
    • Excellent communication and collaboration skills to engage with engineering, product, and leadership teams.

Preferred Qualifications

    • Security certifications such as OSCP, GIAC (GWEB, GWAPT, GCSA), CISSP, or CSSLP.
    • Experience working in SaaS, multi-tenant cloud environments.
    • Knowledge of machine learning security (AI/ML model risks, LLM security best practices).
    • Familiarity with attack surface management and threat intelligence.

About our culture

Smarsh hires lifelong learners with a passion for innovating with purpose, humility and humor. Collaboration is at the heart of everything we do. We work closely with the most popular communications platforms and the world’s leading cloud infrastructure platforms. We use the latest in AI/ML technology to help our customers break new ground at scale. We are a global organization that values diversity, and we believe that providing opportunities for everyone to be their authentic self is key to our success. Smarsh leadership, culture, and commitment to developing our people have all garnered Comparably.com Best Places to Work Awards. Come join us and find out what the best work of your career looks like.

Similar Jobs

The Globel Talent Co - Senior Data & Marketing Analyst

The Globel Talent Co

Johannesburg, Gauteng, South Africa (Remote)
6 Months ago
klass - Chief Revenue Officer

klass

United States (Remote)
2 Months ago
Abridge - Deal Desk Manager

Abridge

Chicago, Illinois, United States (Remote)
1 Month ago
NCR Voyix - Software Engineer IV - C#.Net

NCR Voyix

Chennai, Tamil Nadu, India (On-Site)
2 Months ago
Sierra - Senior Commercial Counsel - UK

Sierra

London, England, United Kingdom (On-Site)
3 Weeks ago
Ansys - Product Sales Executive - Digital Engineering Systems

Ansys

Canonsburg, Pennsylvania, United States (On-Site)
3 Months ago
Wolters Kluwer - Product Owner (m/w/d) - Payroll software

Wolters Kluwer

Ludwigsburg, Baden-Württemberg, Germany (Hybrid)
2 Months ago
CyberArk - Senior Product Owner (Discovery & Context)

CyberArk

Israel (Hybrid)
3 Weeks ago
Progress - Senior Director, Product Marketing - ShareFile + MOVEIt

Progress

United States (Remote)
3 Weeks ago
4theplayer - REMOTE Junior Technical Writer / Product Executive

4theplayer

(Remote)
3 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

gitlab - Senior Manager, Assigned Support Engineering

gitlab

(Remote)
1 Month ago
Mercury - Staff Product Designer - Accounting

Mercury

San Francisco, California, United States (Remote)
1 Month ago
Unity - Senior Partner Relations Manager

Unity

Tokyo, Japan (On-Site)
4 Months ago
Varonis  - MDDR Manager

Varonis

Morrisville, North Carolina, United States (Hybrid)
2 Months ago
Vertx Inc. - Manager - Marketing Data Strategy and Governance

Vertx Inc.

United States (Remote)
1 Month ago
Tide - Product Design Manager

Tide

Romania (Hybrid)
1 Month ago
EMA - Deployment Engineer

EMA

Bengaluru, Karnataka, India (Hybrid)
7 Months ago
ElevenLabs - Account Executive - Germany

ElevenLabs

Germany (Remote)
5 Months ago
Zuora - Sr Solution Delivery Manager

Zuora

United States (Remote)
3 Months ago
Nasdaq - Commercial Management – Sr. Analyst

Nasdaq

Mumbai, Maharashtra, India (On-Site)
1 Year ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

Ajmera Infotech - React Developer

Ajmera Infotech

Bengaluru, Karnataka, India (On-Site)
2 Months ago
Wolters Kluwer - Sr. Telephony Engineer (Genesys Cloud, MS Teams, Audiocodes, SIP Trunk Routing, Scripting)

Wolters Kluwer

Pune, Maharashtra, India (Hybrid)
1 Month ago
cyara - Senior Software Engineer - Backend Telephony

cyara

Hyderabad, Telangana, India (Hybrid)
1 Year ago
Capgemini - SAP CAR Consultant

Capgemini

Tiruchirappalli, Tamil Nadu, India (On-Site)
1 Month ago
Nagarro - Staff Engineer, ERP

Nagarro

India (Remote)
10 Months ago
PhonePe - Senior Server Administrator (Azure Administrator)

PhonePe

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Nagarro - Senior Engineer, Sharepoint

Nagarro

India (Remote)
10 Months ago
Nice - Director, Product Management

Nice

Pune, Maharashtra, India (Hybrid)
1 Month ago
ISS Stoxx - Index Specialist – ESG/Sustainability – Research & Development

ISS Stoxx

Mumbai, Maharashtra, India (On-Site)
2 Months ago
Simple Viral Games - Quality Analyst/ QA Engineer

Simple Viral Games

Bengaluru, Karnataka, India (On-Site)
1 Year ago

Get notifed when new similar jobs are uploaded

Product Jobs

SciPlay - Director of Product

SciPlay

Tel Aviv-Yafo, Tel Aviv District, Israel (On-Site)
1 Month ago
tonies studios - Director of Product Marketing

tonies studios

United States (On-Site)
1 Month ago
Sega (UK) - Product Planning Associate

Sega (UK)

London, England, United Kingdom (On-Site)
3 Months ago
illumio - Director, Product Security

illumio

Sunnyvale, California, United States (On-Site)
1 Month ago
Rippling - Product Lead, Employee Experience

Rippling

New York, United States (On-Site)
3 Months ago
eBay - Sr. TPM - Search, SEO & Product

eBay

Portland, Oregon, United States (Remote)
3 Weeks ago
Scopely - Senior Director, Product - Garden Joy

Scopely

Culver City, California, United States (Hybrid)
8 Months ago
nubank - Product Operations II, Growth

nubank

Mexico City, Mexico (On-Site)
1 Month ago
Trueplay - Product Owner

Trueplay

(Remote)
3 Months ago
Nintendo - CONTRACT - Product Specialist (Portuguese)

Nintendo

Redmond, Washington, United States (Hybrid)
8 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Bengaluru, Karnataka, India (Hybrid)

Heredia, Costa Rica (Remote)

United Kingdom (Remote)

Bengaluru, Karnataka, India (Hybrid)

Atlanta, Georgia, United States (Remote)

Atlanta, Georgia, United States (Hybrid)

Bengaluru, Karnataka, India (Hybrid)

Heredia, Costa Rica (Hybrid)

Boca Raton, Florida, United States (Remote)

Portland, Oregon, United States (Hybrid)

View All Jobs

Get notified when new jobs are added by smarsh

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug