Security Product Lead – Product & AI Security
Listed on 2026-04-28
-
IT/Tech
Cybersecurity, AI Engineer, Product Designer, Data Science Manager
Role Overview
The Security Product Lead – Product Security & AI Security is responsible for defining the strategic direction, roadmap, and measurable outcomes for securing the organization's product lifecycle and emerging AI/ML initiatives. This role sits within the Security Strategy & Delivery team and partners closely with the Product Security, Engineering, and Data Science/AI functional leaders and operational teams. This position ensures that Product Security and AI Security capabilities are treated as internal security products—aligned to enterprise risk priorities, supported by a clear roadmap, measured through defined KPIs, and delivered through structured program governance.
The role requires strong cross‑functional collaboration, strategic thinking, and the ability to influence without direct authority. By proactively embedding security controls into the product development lifecycle (SDLC) and addressing unique risks associated with AI/ML systems, this role directly supports the organization's overarching goal of protecting member trust, safeguarding corporate assets, and ensuring the continued stability and growth of the business.
- Develop and maintain a multi-year strategy and roadmap for Product Security and AI Security capabilities.
- Align roadmap priorities with enterprise risk objectives, regulatory requirements (e.g., data privacy, AI governance), and evolving attack surface.
- Identify capability gaps (e.g., secure coding practices, AI model integrity) and define strategic investment opportunities.
- Translate strategic objectives into structured, sequenced initiatives.
- Lead Security Due Diligence:
Own the end‑to‑end security assessment process for M&A targets, including technical architecture reviews, vulnerability assessments, security program maturity evaluations, and risk quantification. - Develop M&A Security Strategy:
Define and continuously improve SoFi's M&A security playbook, methodologies, and standards to enable rapid, consistent, and thorough security evaluations. - Drive Integration Planning:
Partner with target companies and internal teams to design secure integration roadmaps that balance speed‑to‑value with security requirements. - Manage M&A security assessments and integration roadmaps to design secure integration roadmaps, balancing speed and security.
- Define the value proposition and service model for Product Security and AI Security capabilities, including security requirements for all new product features.
- Establish clear capability maturity targets (e.g., Dev Sec Ops integration level, AI risk mitigation completeness) and continuous improvement plans.
- Maintain and prioritize a strategic backlog aligned to measurable risk reduction outcomes (e.g., reduction in critical vulnerabilities, secure‑by‑design adoption).
- Ensure capabilities are treated as ongoing products with lifecycle ownership, not one‑time projects.
- Translate business priorities, AI adoption strategy, and risk signals into a prioritized portfolio.
- Partner with engineering and product teams to reduce friction and improve predictability.
- Mature Secure SDLC practices and embed automation into CI/CD pipelines.
- Define and track outcome‑based metrics (risk reduction, adoption, efficiency).
- Own the portfolio view of Product Security & AI Security initiatives within the broader security strategy.
- Structure and manage strategic programs required to deliver roadmap objectives (e.g., implementing an AI Red Team program, rolling out a new static analysis tool).
- Define milestones, delivery plans, and success metrics for major initiatives.
- Track progress against portfolio commitments and escalates risks proactively.
- Manage cross‑functional dependencies across Engineering, Product Management, Data Science, Legal, and other stakeholders.
- Support quarterly and annual planning cycles, including investment.
- Ensure predictable execution through structured governance and reporting cadence.
- Partner closely with the Product Security and AI/ML functional leaders and teams to align on priorities and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).