Lead Product Security

🏒 Jobgether · all 1672 jobs
πŸ“ Remote Canada
πŸ“… Posted Sep 26, 2026 Β· via Lever
Apply on original site β†—

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Lead Product Security based in Canada.

This is a senior technical leadership role responsible for embedding security throughout the product development lifecycle.
You will shape secure architecture, design reviews, threat modeling, and secure-by-default standards across product engineering.
The role combines hands-on security expertise with developer enablement, mentoring, and organizational security maturity.
You will work across application security tooling, secure code review, product supply chain security, and vulnerability response.
A key focus is scaling security capabilities through Security Champions, training, reusable guidance, and measurable improvement programs.
You will collaborate closely with engineering, security operations, PSIRT, and other stakeholders on high-impact security initiatives.
The position offers broad autonomy and the opportunity to influence how secure software is designed, built, assessed, and maintained.

Accountabilities:
- Lead security architecture and design reviews across core product lines, providing actionable guidance before implementation begins.

- Contribute to and scale threat modeling practices by coaching engineers to conduct their own models and reviewing results.

- Define security requirements, design gates, product security baselines, and standards that establish a practical definition of secure-by-default.

- Build and measure secure development lifecycle practices across SCA, SAST, DAST, secret scanning, dependency management, and build pipeline integrity.

- Conduct deep secure code reviews in high-risk areas such as authentication, authorization, cryptography, secrets management, and input validation.

- Strengthen product supply chain and release security, including SBOM generation and the integrity of build and distribution artifacts.

- Develop and expand the Security Champions program through recruitment, training, enablement content, office hours, and outcome tracking.

- Mentor engineers and security professionals on secure design, threat modeling, and secure code review to scale security expertise across teams.

- Coordinate penetration tests and third-party security assessments, triaging findings and driving remediation through completion.

- Partner with PSIRT on product vulnerability triage, remediation, and coordinated response, using root-cause insights to improve engineering and SDLC controls.

- Assess product security maturity using frameworks such as BSIMM or SAMM and drive a prioritized improvement roadmap.

- Support secure-by-design regulatory requirements, including the EU Cyber Resilience Act, through technical evidence and process improvements.

- Provide subject matter expertise for customer security questionnaires, audits, RFPs, and security escalations, while building reusable, vetted response documentation.

- Support incident response involving product code, build systems, or product infrastructure with product-specific security expertise and remediation guidance.

- Lead discrete technical workstreams, track milestones, and contribute to application security tooling evaluations and proof-of-concepts.

Requirements

- Bachelor’s degree in Computer Science, Information Security, Information Technology, or equivalent practical experience.

- 8+ years of experience in product security, application security, or software security engineering, with strong hands-on experience in secure design reviews, threat modeling, and secure code review.

- Experience building or operating a Security Champions program, developer security training initiative, or comparable security enablement program.

- Strong knowledge of application security tooling, including SCA, SAST, DAST, and secret scanning, along with an understanding of their detection capabilities and limitations.

- Practical secure coding and code review experience in at

Flights + hotels

This role requires you to be in Canada. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels β†’

← All remote jobs

Get new remote jobs like this by email
Daily email, only when there's something new. One click to stop.

Get remote it jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you