Senior Product Security Manager
Lead a newly established product red team conducting adversary emulation against synthetic customer environments. Build operational standards, guide offensive security campaigns, and influence product security, detection, and remediation priorities.
תחומי אחריות
- Own product red team objectives, engagement selection, campaign proposals, rules of engagement, and findings documentation
- Design engagement frameworks, testing policies, operational procedures, and technical and operational success metrics
- Build and lead an offensive operations team covering adversary emulation, exploit development, persistence, supply chain security, and AI attack vectors
- Plan and execute realistic attack paths involving initial access, persistence, lateral movement, data staging, and living-off-the-land techniques
- Develop proof-of-concept exploits and command-and-control channels to demonstrate vulnerability chains and detection gaps
- Validate security controls, detection capabilities, logging, and remediation effectiveness across kill-chain phases
- Partner with product engineering, detection engineering, purple teams, and product security leadership on testing and remediation
- Advise senior executives on emerging threats, product security gaps, security architecture, and risk-based recommendations
דרישות
- 12+ years of offensive security experience, including at least 5 years leading offensive operations teams
- Experience leading covert offensive cyber operations in intelligence, military, contracted, or equivalent private-sector environments
- Expertise in threat actor emulation, MITRE ATT&CK, exploit development, persistence, detection evasion, command and control, and kill-chain analysis
- Experience establishing operational doctrine, rules of engagement, security procedures, and high-risk engagement approvals
- Ability to operate under ambiguity, manage regulatory and legal constraints, mentor senior operators, and brief executives
- Knowledge of product security, SDLC integration, CI/CD pipelines, SaaS threat models, and multi-tenant architectures
יתרון
- Experience leading red teams against software products or SaaS platforms
- Experience with AI attack vectors, software supply chain security, or SDLC tooling security
- Published security research or presentations at major security conferences
- Experience testing AWS, Azure, or GCP infrastructure and containerized environments
- Familiarity with enterprise customer deployments and security control expectations