Product Security Lead
Quick Summary
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Product Security Lead based in Canada.
This role leads the Product Security function and reports directly to the Chief Information Security Officer.
You will define the security strategy, roadmap, and operating model while embedding security throughout the product and engineering lifecycle.
The position combines hands-on technical leadership with strategic influence across application security, cloud platforms, connected devices, and product engineering.
You will help teams adopt secure-by-design practices through threat modeling, architectural reviews, secure coding, and automated security controls.
The role also plays an important part in customer and commercial engagements by translating security maturity into support for enterprise opportunities.
You will work across Security, Engineering, Product, Sales, GRC, Cloud Operations, and other teams to manage product risk and strengthen resilience.
This is a high-impact leadership opportunity in a remote environment focused on secure innovation and connected infrastructure.
- Define, build, and lead the vision, roadmap, and operating model for the Product Security function.
- Serve as a trusted security advisor to the CISO, Product leadership, Engineering leadership, and other senior stakeholders.
- Embed security-by-design principles throughout the Secure Software Development Lifecycle (SSDLC).
- Lead threat modeling, secure design reviews, architectural risk assessments, and other proactive product security activities.
- Partner with Engineering teams to implement secure coding practices and security gates within CI/CD pipelines.
- Influence cloud and platform architecture to strengthen resilience, network segmentation, least-privilege access, and defense-in-depth controls.
- Lead product-level risk identification and manage the vulnerability lifecycle across application code, APIs, cloud services, and embedded components.
- Oversee penetration testing activities, vulnerability remediation, and risk tracking to ensure issues are addressed effectively.
- Partner with GRC, Sales, and Revenue Operations teams on RFPs, RFIs, customer security reviews, and enterprise engagements.
- Act as a technical authority in customer-facing security discussions and communicate security capabilities in a commercially relevant way.
- Translate regulatory, contractual, and audit requirements into practical and scalable product security controls.
- Apply relevant requirements from frameworks and standards including ISO 27001, SOC 2, NIST, and Tx-RAMP.
- Collaborate with Security Operations and Cloud Operations to establish product telemetry and logging requirements.
- Help ensure secure-by-default deployment patterns and effective integration with incident response processes.
- Continuously improve product security practices, tooling, processes, and operating models as threats and business requirements evolve.
Requirements
~2 min read- Extensive technical experience in application security, product security, secure engineering, or cloud security.
- Experience working in SaaS, critical infrastructure, connected technology, or similarly complex environments is highly valuable.
- Strong hands-on experience with Secure Software Development Lifecycle practices, including threat modeling, SAST/DAST, secure design, and automated security controls.
- Proven ability to integrate security gates and controls into modern CI/CD pipelines.
- Strong understanding of security frameworks and control mapping, including ISO 27001, SOC 2, NIST CSF, and NIST 800-53.
- Working knowledge of NIST SP 800-82 and security considerations for OT/ICS or connected infrastructure.
- Demonstrated experience securing connected devices, IoT, or OT-adjacent systems.
- Strong expertise in cloud-native architectures, with AWS experience preferred.
- Experience securing APIs, microservices, cloud services, and distributed platforms.
- Practical knowledge of vulnerability management, penetration testing, security assessments, and product risk management.
- Strong experience with the OWASP security tool suite and the CISA Cyber Security Evaluation Tool (CSET).
- Ability to influence senior Engineering and Product stakeholders without relying on direct reporting authority.
- Excellent communication skills, with the ability to translate complex technical risks for executives, auditors, customers, and non-technical stakeholders.
- Strong analytical and critical-thinking abilities, with sound judgment when managing complex or high-impact security decisions.
- Ability to operate effectively in ambiguous, fast-moving environments while maintaining strong ownership and attention to detail.
- Strong cross-functional collaboration skills and the ability to build consensus across technical and business teams.
What We Offer
~2 min readLocation & Eligibility
Listing Details
- Posted
- September 23, 2026
- First seen
- September 27, 2026
- Last seen
- September 28, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 46%
- Scored at
- September 28, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.