Technical Product Manager - Authorization Tooling - CTO Office
Our team:
We are the CTO Security Service Infrastructure group. We solve complex systems problems, enabling our engineers to quickly ship new products, and prototype the next generation of infrastructure security technologies. Whether we’re designing our next generation security controls, or threat modeling our distributed systems, our goal is to define the future of how we secure Bloomberg’s infrastructure. That’s where you come in.
As a product owner in the CTO’s office, you’ll be trusted to understand the intersections between Bloomberg’s global technology footprint, unique software stack and security requirements, provide guidance for usable infrastructure security, ensure that logical security controls are manageable at our scale, and much more. Your leadership skills will influence the roadmap for future security technologies, while working alongside motivated engineers across the company to keep Bloomberg at the forefront. Our team works across many areas of security architecture, and you will have the opportunity to focus on the projects you are passionate about and bring your expertise to help reach our team’s goals.
In this role, you will serve as the technical product owner for Bloomberg’s home-grown authorization tooling; the platforms and services that govern what people and systems are permitted to do once authenticated. You will partner closely with engineering to keep these tools state of the art, continually assess whether an in-house approach remains the best fit or whether the landscape has shifted, and work with internal stakeholders to anticipate emerging authorization needs before they become blockers. You will own prioritization of development efforts, lead the creation of roadmaps, metrics, and OKRs, and contribute to the overall strategy and vision for how authorization is designed, delivered, and governed across the firm. This is a technical role: you will need to understand how systems interact, how different technologies and access models differ, and what those differences mean for the underlying authorization tooling
We'll expect you to:
- Partner with engineering counterparts to keep our home-grown authorization tooling state of the art, evolving it in step with changing platforms, technologies, and security requirements
- Continually assess whether an in-house approach remains the right one, evaluating build, buy, and re-use trade-offs against the organization’s needs and the state of the industry
- Work with internal stakeholders across engineering, product, and business teams to anticipate future authorization needs and shape the tooling to meet them
- Own prioritization of development efforts, balancing security, usability, scalability, and delivery timelines
- Lead the creation of roadmaps, metrics, and OKRs that make progress and impact measurable and transparent
- Define and track metrics that measure the health, performance, and current state of the authorization tooling, so decisions about where to invest, modernize, or retire are grounded in evidence
- Contribute to the overall strategy and vision for authorization across the firm, and translate that direction into concrete implementation priorities
- Establish a comprehensive understanding of current authorization workflows, dependencies, pain points, and future-state opportunities
- Produce clear requirements, architecture direction, and implementation guidance for authorization-related initiatives, including RFCs and design rationale
- Ensure appropriate auditing, reporting, and observability exist for authorization workflows and related controls
- Assess risks and identify opportunities to strengthen authorization models and controls across the organization
- Collaborate with vendors, consultants, and industry peers to exchange knowledge and stay informed about the latest advancements in authorization and access management technologies
You’ll need to have:
- 7+ years of experience building, maintaining and managing security aspects of large-scale, distributed infrastructure and applications
- Strong experience with authorization and access control technologies with an emphasis on security, integration and automation
- Sufficient technical depth to understand how systems interact, how different technologies and access models differ and what those differences mean for the underlying authorization tooling.
- A track record of building collaborative relationships with stakeholders across many functions, with a focus on correctness, scalability, and usability of distributed infrastructure. A long history of leading through influence and establishing consensus for execution
- Ability to collect and document detailed product requirements including RFCs, design rationale and decision making
- The experience of knowing when to build, buy or re-use
- Deep knowledge of authorization and access control concepts and standards and how they are adopted in large enterprises
- Demonstrated polished written and oral communication skills, in a variety of circumstances (from presenting to audiences through to 1:1 communication), ability to present complex topics to senior leadership
We'd love to see:
- Ability to build proof-of-concept solutions and prototype approaches, and to partner with engineering teams to drive adoption
- Experience and knowledge of handling regulatory requirements such as GDPR, DORA, and HIPAA
- Experience integrating with and securing a combination of in-house developed and third-party solutions
Salary Range = 240,000 - 330,000 USD Annual + Benefits + Bonus
The referenced salary range is based on the Company's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level.We offer one of the most comprehensive and generous benefits plans available and offer a range of total rewards that may include merit increases, incentive compensation (exempt roles only), paid holidays, paid time off, medical, dental, vision, short and long term disability benefits, 401(k) +match, life insurance, and various wellness programs, among others. The Company does not provide benefits directly to contingent workers/contractors and interns.
Discover what makes Bloomberg unique - watch our podcast series for an inside look at our culture, values, and the people behind our success.
