×
Register Here to Apply for Jobs or Post Jobs. X

Product Security Governance Principal

Job in San Francisco, San Francisco County, California, 94199, USA
Listing for: Fifth Third Bank
Full Time position
Listed on 2026-10-09
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 140000 - 170000 USD Yearly USD 140000.00 170000.00 YEAR
Job Description & How to Apply Below

Make banking a Fifth Third better®

We connect great people to great opportunities. Are you ready to take the next step? Discover a career in banking at Fifth Third Bank.

Core Competencies
  • Governance leadership and sound risk judgment
  • Evidence-based assurance and control evaluation
  • Customer trust, readiness, and compliance coordination
  • Clear executive, audit, business, and technical communication
  • Cross-functional influence and constructive challenge
  • Independent execution, accountability, and follow-through
  • Scalable process design and continuous improvement
Key Responsibilities Product Security Governance

Lead and mature Product Security governance for internally developed customer-facing software, APIs, SDKs, integrations, and related services.

Define product scope, engagement criteria, review expectations, decision authorities, escalation paths, and evidence standards.

Develop and maintain standards, procedures, playbooks, templates, decision records, risk records, and supporting guidance.

Facilitate risk-based decisions involving security requirements, control applicability, exceptions, compensating controls, and accountability.

Align Product Security practices with established enterprise architecture, application security, vulnerability management, risk, compliance, audit, and engineering processes.

Customer Assurance

Lead a scalable customer assurance model for applicable products and services.

Coordinate accurate, reviewable security summaries, whitepapers, assessment responses, and supporting evidence.

Evaluate customer-facing security statements for appropriate scope, context, qualifications, and evidence.

Partner with Product, Engineering, Risk, Compliance, Legal, Audit, and customer-facing teams to support customer, deal, regulatory, and audit needs.

Establish traceability between assurance statements, controls, evidence sources, and accountable owners while increasing consistency and response efficiency.

SOC 2 and Readiness Coordination

Lead Product Security coordination for applicable SOC 2 and related readiness activities within established enterprise compliance and audit processes.

Support system scoping, business-requirement validation, readiness evaluations, gap assessments, evidence coordination, and assessment-provider engagement.

Partner with control owners to evaluate control design, evidence requirements, operating effectiveness, and improvement opportunities.

Maintain readiness plans, evidence inventories, dependencies, decisions, and accountable action tracking.

Translate assessment observations into sustainable improvements while preserving appropriate separation from independent audit or attestation responsibilities.

Product Risk and Evidence

Define consistent expectations for product readiness assessments and product-level security evidence.

Evaluate evidence from established activities such as threat modeling, penetration testing, security scanning, software supply chain practices, secure development, incident management, and remediation.

Assess evidence for completeness, relevance, recency, traceability, and applicability, including the context and limitations of technical tools.

Develop consolidated views of product security risk, control adoption, coverage, and assurance readiness.

Establish meaningful indicators and reporting that demonstrate Product Security adoption, maturity, decisions, and accountable actions.

Program Operations and Continuous Improvement

Lead governance forums, readiness reviews, working sessions, and decision meetings.

Identify recurring themes and recommend scalable improvements to controls, evidence, processes, and stakeholder guidance.

Provide concise updates and practical recommendations to technical teams, business stakeholders, and senior leaders.

Contribute to Product Security strategy, planning, prioritization, and roadmap development.

Promote shared accountability for secure and trusted customer-facing products.

Required Qualifications
  • Seven or more years of progressively responsible experience in Product Security, security governance, cybersecurity assurance, IT risk, security compliance, technology audit, security architecture, or a related discipline.
  • Demonstrated success leading security governance, assurance, readiness, control evaluation, gap analysis, or evidence-review practices in a complex organization.
  • Proven ability to independently evaluate technical and nontechnical evidence, identify material concerns, exercise sound judgment, and recommend defensible decisions.
  • Substantial…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary