Jobgether
Accountabilities:: Define, build, and lead the vision, roadmap, and operating model for the Product Security function. Serve as a trusted security advisor to the CISO, Product leadership, Engineering leadership, and other senior stakeholders. Embed security-by-design principles throughout the Secure Software Development Lifecycle (SSDLC). Lead threat modeling, secure design reviews, architectural risk assessments, and other proactive product security activities. Partner with Engineering teams to implement secure coding practices and security gates within CI/CD pipelines. Influence cloud and platform architecture to strengthen resilience, network segmentation, least-privilege access, and defense-in-depth controls. Lead product-level risk identification and manage the vulnerability lifecycle across application code, APIs, cloud services, and embedded components. Oversee penetration testing activities, vulnerability remediation, and risk tracking to ensure issues are addressed effectively. Partner with GRC, Sales, and Revenue Operations teams on RFPs, RFIs, customer security reviews, and enterprise engagements. Act as a technical authority in customer-facing security discussions and communicate security capabilities in a commercially relevant way. Translate regulatory, contractual, and audit requirements into practical and scalable product security controls. Apply relevant requirements from frameworks and standards including ISO 27001, SOC 2, NIST, and Tx-RAMP. Collaborate with Security Operations and Cloud Operations to establish product telemetry and logging requirements. Help ensure secure-by-default deployment patterns and effective integration with incident response processes. Continuously improve product security practices, tooling, processes, and operating models as threats and business requirements evolve. Requirements Extensive technical experience in application security, product security, secure engineering, or cloud security. Experience working in SaaS, critical infrastructure, connected technology, or similarly complex environments is highly valuable. Strong hands-on experience with Secure Software Development Lifecycle practices, including threat modeling, SAST/DAST, secure design, and automated security controls. Proven ability to integrate security gates and controls into modern CI/CD pipelines. Strong understanding of security frameworks and control mapping, including ISO 27001, SOC 2, NIST CSF, and NIST 800-53. Working knowledge of NIST SP 800-82 and security considerations for OT/ICS or connected infrastructure. Demonstrated experience securing connected devices, IoT, or OT-adjacent systems. Strong expertise in cloud-native architectures, with AWS experience preferred. Experience securing APIs, microservices, cloud services, and distributed platforms. Practical knowledge of vulnerability management, penetration testing, security assessments, and product risk management. Strong experience with the OWASP security tool suite and the CISA Cyber Security Evaluation Tool (CSET). Ability to influence senior Engineering and Product stakeholders without relying on direct reporting authority. Excellent communication skills, with the ability to translate complex technical risks for executives, auditors, customers, and non-technical stakeholders. Strong analytical and critical-thinking abilities, with sound judgment when managing complex or high-impact security decisions. Ability to operate effectively in ambiguous, fast-moving environments while maintaining strong ownership and attention to detail. Strong cross-functional collaboration skills and the ability to build consensus across technical and business teams. Benefits Base salary of CA$163,000–CA$198,000, depending on skills, experience, market conditions, and primary work location. Equity opportunities. Discretionary bonus and variable incentive opportunities. Comprehensive health benefits from day one. 24/7 virtual healthcare access. Dedicated wellness programs and resources. RRSP/401K matching plan to support long-term financial planning. Flexible vacation policy. Mio-Days designed to provide additional time to recharge. Flexible work options within a remote environment. Internet subsidy and remote work allowance. Enhanced leave programs for new parents. Opportunity to lead and shape a strategic Product Security function. High-impact collaboration with Security, Engineering, Product, Cloud Operations, Sales, and GRC teams. Opportunity to work on security challenges involving cloud platforms, connected devices, IoT, and critical infrastructure. Inclusive and diverse working environment. Accessibility accommodations available throughout the hiring process where required. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1