Product Security Principal
Listed on 2026-07-22
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Position Title
Product Security Principal
LocationNew York, NY 10018
Job SummaryServes as the embedded security subject matter expert and thought lead for assigned product lines within the product operating model framework. Partners with the Technology Line of Business Lead, Business Architect, and Business Unit Risk Manager (BURM) to cultivate a security-first culture, ensuring products are secure from design through deployment. This position is accountable for application-specific security controls, threat modeling, security architecture reviews, secure code practices, and security testing coordination.
Responsible for identifying and managing security risks, translating regulatory and policy requirements into actionable control designs, and serving as the clear point of escalation for IT Risk and Cyber domains within the product. Acts with urgency to monitor Key Risk Indicators, manage emerging security issues, and drive real risk reduction outcomes across the product’s technology supply chain.
- Cultivates security culture across product, technology, and business teams by embedding threat modeling, security architecture reviews, and secure code practices, ensuring products adopt security controls and are secure from design through deployment.
- Owns application-specific security requirements, threat modeling, security architecture design, authentication/authorization design, and data classification/handling standards in partnership with Tech Leads and Business Architects.
- Leads security testing, vulnerability assessments, penetration testing coordination, and security validation activities, tracking security defect remediation and ensuring compliance with secure coding standards.
- Prepares and delivers Technology Review Board security artifacts including Initial Design Review security assessments, Production Release Review security validation, and security incident response plans.
- Proactively monitors Key Risk Indicators, manages emerging security issues with urgency, identifies root causes and themes, and provides timely recommendations for resolution to the BURM and leadership.
- Partners with Third Party Oversight teams to ensure effective technology risk management of vendors, with focus on Cloud computing, SaaS tools, and emerging technologies engaged by technology partners.
- Collaborates on business‑as‑usual audit and regulatory engagements, translating firm‑wide policy and regulatory requirements into control designs for Software Engineers and SRE teams.
- Serves as the product’s security thought leader, sharing best practices between product and cybersecurity teams, and acting as the clear point of escalation and subject matter expert for IT Risk and Cyber domains.
- Performs special projects, and additional duties and responsibilities as required.
- Where applicable and when performing the responsibilities of the job, employees are accountable to maintain regulatory compliance and adhere to internal policies, standards, and controls.
- Education level preferred:
High School / High School Equivalency (GED, HiSET, TASC) / Foreign Equivalent - Minimum experience required: 8+ Years in information security, cybersecurity, or technology risk management with strong security and technical skills in a regulated organization
- Experience operating in a 3 Lines of Defense (3
LoD) model with demonstrated ability to translate policy and regulatory requirements into control designs for engineers and architects - Proven ability to communicate effectively and authoritatively with technical and non‑technical stakeholders, explaining complex security concepts in simple terms
- Education level preferred:
Undergraduate Degree (4 years or equivalent) - Technical understanding of Public Cloud computing (Azure/AWS), including cloud hardening, data protection controls, resiliency, and access management. Experience with APIs/microservices, IAM, Secrets Management, Dev Sec Ops , and SSDLC preferred.
- Financial services and banking experience preferred; experience in industries with similar risk tolerance acceptable. CISSP, CISM, or equivalent security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).