Director, Product Security; Remote
Hilo, Hawaii County, Hawaii, 96720, USA
Listed on 2026-06-05
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing
Join to apply for the Director, Product Security (Remote) role at Jobright.ai
2 days ago Be among the first 25 applicants
Join to apply for the Director, Product Security (Remote) role at Jobright.ai
Get AI-powered advice on this job and more exclusive features.
Jobright is an AI-powered career platform that helps job seekers discover the top opportunities in the US. We are NOT a staffing agency. Jobright does not hire directly for these positions. We connect you with verified openings from employers you can trust.
Job Summary:
Unqork empowers enterprises to accelerate growth by building AI-powered applications. The Director of Product Security will lead the charge in securing Unqork's technology stack, championing cloud and application security best practices, and ensuring security is integrated into the development lifecycle.
Responsibilities:
• You will lead the charge in securing Unqork's technology stack.
• You will champion cloud and application security best practices and drive their adoption across Unqork's engineering organization.
• You'll leverage your deep technical expertise to oversee the identification and remediation of security vulnerabilities.
• In this role, you will lead the review process for all feature and bug fix requests, ensuring security is a foundational element of our development lifecycle.
• You will be responsible for scoping and approving all security-related enhancements and bug fixes, ensuring they meet our rigorous standards.
• As a mentor, you'll coach and empower team members to deliver high-quality, secure solutions and align with our core engineering practices.
• You will define the strategic roadmap for Unqork's product security program (cloud and application security), aligning with business goals and risk tolerance.
• You'll mature our secure software development lifecycle (SDLC) by integrating security controls and tooling into our CI/CD pipelines and governing the security release process.
• You will drive the Secure Software Development Lifecycle (SSDLC), embedding security from design to deployment.
• This includes conducting threat modeling and architectural security reviews for all applications, managing and maturing our SAST, DAST, and SCA tooling, and spearheading vulnerability remediation efforts.
• You'll act as a subject matter expert, guiding development teams on secure coding practices and fostering a strong security culture across the organization.
• You will ensure adherence to regulatory requirements and industry best practices by defining and enforcing security policies and standards.
• This involves managing our monthly FedRAMP continuous monitoring, maintaining cloud security policies in Lacework, and reviewing security notifications from AWS, GCP, and Azure.
• You will ensure our security controls and configurations are consistently applied and effective across our various cloud environments (e.g., AWS, Azure, GCP).
• Define, implement, and enforce product security policies, standards, and guidelines, ensuring adherence to regulatory requirements and industry best practices.
• You will partner with leadership in Security, Product, Engineering, and Legal to embed security ownership, drive architectural decisions, and manage risk.
• This includes creating secure design requirements and conducting security testing for new platform features and infrastructure changes.
• Lead the product security aspects of incident response, guiding root cause analysis, driving remediation efforts, and implementing preventative measures.
• You will provide hands-on technical guidance and mentorship to an application security engineer, cloud security engineer, and security analyst fostering their growth and ensuring their work aligns with organizational goals.
Qualifications:
Required:
• 10+ years of progressive experience in information security, with at least 3-5 years in a leadership role managing product or application security teams.
• Deep understanding of modern web application architectures (e.g., microservices, event-driven), cloud technologies (AWS, Azure, GCP), and secure coding principles.
• Extensive experience with application security testing methodologies (SAST,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).