×
Register Here to Apply for Jobs or Post Jobs. X

Vice President, Product Security

Job in Virginia, St. Louis County, Minnesota, 55792, USA
Listing for: Qualys
Full Time position
Listed on 2026-09-13
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 260000 - 340000 USD Yearly USD 260000.00 340000.00 YEAR
Job Description & How to Apply Below

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Qualifications Leadership & Executive Management
  • 12+ years of progressive experience in cybersecurity, application security, product security, cloud security, or security architecture, including 7+ years in senior leadership roles managing globally distributed security, engineering, and architecture teams.
  • Proven experience building, scaling, and leading high-performing Product Security organizations supporting large-scale SaaS, cloud-native, and enterprise software platforms.
  • Demonstrated success leading directors, senior managers, architects, and security engineering teams across multiple geographies and product portfolios.
  • Experience owning multi-million-dollar security budgets, strategic planning processes, headcount forecasting, vendor relationships, and security program execution.
  • Strong executive presence with the ability to communicate technical risk, business impact, and security strategy to Boards of Directors, Executive Leadership Teams, auditors, regulators, and customer executives.
  • Proven ability to influence security and product roadmaps across Engineering, Product Management, Cloud Operations, Legal, Compliance, Customer Success, Sales Engineering, and Corporate Security organizations.
  • Experience participating in M&A due diligence, product security assessments, and post-acquisition security integration activities is highly desirable.
Product Security & Secure Engineering
  • Deep expertise in product security, application security, cloud security, Dev Sec Ops , software supply chain security, and secure software development lifecycle (SSDLC) practices.
  • Demonstrated experience implementing and scaling:
  • Security-by-design principles
  • Threat modeling frameworks
  • Secure coding standards
  • Vulnerability management programs
  • Red teaming exercises
  • Bug bounty and responsible disclosure programs
  • Software supply chain security controls
  • SBOM management
  • Secure CI/CD pipelines
  • Container and Kubernetes security
  • Extensive knowledge of modern authentication and identity architectures including:
  • Zero Trust
  • OAuth2
  • OpenID Connect
  • SAML
  • PKI
  • Hardware-backed cryptography
  • Secrets management
  • PAM solutions
  • Deep understanding of modern security frameworks including:
  • NIST Cybersecurity Framework
  • NIST SP 800-53
  • NIST SP 800-171
  • NIST SP 800-218 (SSDF)
  • CIS Controls
  • OWASP Top 10
  • OWASP ASVS
  • SOC 2
  • ISO 27001
Federal Compliance & Government Security Experience FedRAMP
  • 10+ years of experience supporting U.S. federal cybersecurity programs and regulatory frameworks.
  • Proven experience leading, achieving, and sustaining multiple FedRAMP Moderate and FedRAMP High Authorizations to Operate (ATO) for cloud-native SaaS products.
  • Extensive experience working directly with:
  • Federal Agencies
  • Joint Authorization Board (JAB) stakeholders
  • Third Party Assessment Organizations (3

    PAOs)
  • Authorizing Officials
  • Government security assessors
  • Deep knowledge of:
  • NIST SP 800-53 Rev. 5
  • FedRAMP Continuous Monitoring
  • POA&M management
  • Significant Change Requests
  • Annual Assessments
  • Vulnerability remediation requirements
  • Configuration management controls
  • Demonstrated ownership of security strategy and product architecture supporting regulated government cloud environments.
CMMC & DoD Cloud Requirements
  • Hands-on experience implementing and managing environments aligned to:
  • CMMC Level 2 requirements
  • NIST SP 800-171
  • DFARS
  • DFARS
  • DFARS
  • DFARS
  • Experience designing and securing solutions deployed within Department of Defense environments requiring Impact Level (IL) authorization.
  • Demonstrated knowledge and practical experience supporting:
  • DoD Impact Level 4 (IL4)
  • DoD Impact Level 5 (IL5)
  • DoD Impact Level 6 (IL6)
  • Experience working with government customers handling Controlled Unclassified Information (CUI), National Security Systems (NSS), and classified or highly regulated workloads.
  • Familiarity with DISA STIGs, SRGs, DoD Cloud Computing Security Requirements Guide (CC SRG), and associated authorization processes.
NIAP & Common Criteria
  • Experience leading or supporting NIAP Common Criteria certification efforts for enterprise software, networking products, endpoint security solutions, or cybersecurity technologies.
  • Strong understanding of:
  • Common Criteria Evaluation and Validation Scheme (CCEVS)
  • Protection Profiles
  • Security Targets
  • Evaluation Assurance Levels (EAL)
  • NIAP product certification lifecycle
  • Experience working with accredited testing laboratories and certification authorities to achieve and maintain product certifications.
Multi-Cloud…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary