Vice President, Product Security
Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Qualifications
Leadership & Executive Management
- 12+ years of progressive experience in cybersecurity, application security, product security, cloud security, or security architecture, including 7+ years in senior leadership roles managing globally distributed security, engineering, and architecture teams.
- Proven experience building, scaling, and leading high-performing Product Security organizations supporting large-scale SaaS, cloud-native, and enterprise software platforms.
- Demonstrated success leading directors, senior managers, architects, and security engineering teams across multiple geographies and product portfolios.
- Experience owning multi-million-dollar security budgets, strategic planning processes, headcount forecasting, vendor relationships, and security program execution.
- Strong executive presence with the ability to communicate technical risk, business impact, and security strategy to Boards of Directors, Executive Leadership Teams, auditors, regulators, and customer executives.
- Proven ability to influence security and product roadmaps across Engineering, Product Management, Cloud Operations, Legal, Compliance, Customer Success, Sales Engineering, and Corporate Security organizations.
- Experience participating in M&A due diligence, product security assessments, and post-acquisition security integration activities is highly desirable.
Product Security & Secure Engineering
- Deep expertise in product security, application security, cloud security, DevSecOps, software supply chain security, and secure software development lifecycle (SSDLC) practices.
- Demonstrated experience implementing and scaling:
- Security-by-design principles
- Threat modeling frameworks
- Secure coding standards
- Vulnerability management programs
- Red teaming exercises
- Bug bounty and responsible disclosure programs
- Software supply chain security controls
- SBOM management
- Secure CI/CD pipelines
- Container and Kubernetes security
- Extensive knowledge of modern authentication and identity architectures including:
- Zero Trust
- OAuth2
- OpenID Connect
- SAML
- PKI
- Hardware-backed cryptography
- Secrets management
- PAM solutions
- Deep understanding of modern security frameworks including:
- NIST Cybersecurity Framework
- NIST SP 800-53
- NIST SP 800-171
- NIST SP 800-218 (SSDF)
- CIS Controls
- OWASP Top 10
- OWASP ASVS
- SOC 2
- ISO 27001
Federal Compliance & Government Security Experience
FedRAMP
- 10+ years of experience supporting U.S. federal cybersecurity programs and regulatory frameworks.
- Proven experience leading, achieving, and sustaining multiple FedRAMP Moderate and FedRAMP High Authorizations to Operate (ATO) for cloud-native SaaS products.
- Extensive experience working directly with:
- Federal Agencies
- Joint Authorization Board (JAB) stakeholders
- Third Party Assessment Organizations (3PAOs)
- Authorizing Officials
- Government security assessors
- Deep knowledge of:
- NIST SP 800-53 Rev. 5
- FedRAMP Continuous Monitoring
- POA&M management
- Significant Change Requests
- Annual Assessments
- Vulnerability remediation requirements
- Configuration management controls
- Demonstrated ownership of security strategy and product architecture supporting regulated government cloud environments.
CMMC & DoD Cloud Requirements
- Hands-on experience implementing and managing environments aligned to:
- CMMC Level 2 requirements
- NIST SP 800-171
- DFARS 252.204-7012
- DFARS 252.204-7019
- DFARS 252.204-7020
- DFARS 252.204-7021
- Experience designing and securing solutions deployed within Department of Defense environments requiring Impact Level (IL) authorization.
- Demonstrated knowledge and practical experience supporting:
- DoD Impact Level 4 (IL4)
- DoD Impact Level 5 (IL5)
- DoD Impact Level 6 (IL6)
- Experience working with government customers handling Controlled Unclassified Information (CUI), National Security Systems (NSS), and classified or highly regulated workloads.
- Familiarity with DISA STIGs, SRGs, DoD Cloud Computing Security Requirements Guide (CC SRG), and associated authorization processes.
NIAP & Common Criteria
- Experience leading or supporting NIAP Common Criteria certification efforts for enterprise software, networking products, endpoint security solutions, or cybersecurity technologies.
- Strong understanding of:
- Common Criteria Evaluation and Validation Scheme (CCEVS)
- Protection Profiles
- Security Targets
- Evaluation Assurance Levels (EAL)
- NIAP product certification lifecycle
- Experience working with accredited testing laboratories and certification authorities to achieve and maintain product certifications.
Multi-Cloud Security & Hyperscaler Expertise
- 15+ years of experience designing and securing cloud-native SaaS platforms operating at enterprise scale.
- Demonstrated architecture and operational expertise across multiple hyperscale cloud service providers including:
Amazon Web Services (AWS)
- Experience securing AWS environments leveraging:
- Organizations
- IAM
- KMS
- CloudTrail
- GuardDuty
- Security Hub
- Control Tower
- ECS/EKS
- Native compliance controls
Microsoft Azure
- Experience securing Azure environments utilizing:
- Entra ID
- Azure Policy
- Defender for Cloud
- Key Vault
- Azure Monitor
- Microsoft Sentinel
- AKS
- Landing Zone architectures
Google Cloud Platform (GCP)
- Experience designing secure GCP architectures leveraging:
- Cloud IAM
- Security Command Center
- Cloud KMS
- Anthos
- Chronicle
- Organization Policies
- GKE security controls
Oracle Cloud Infrastructure (OCI)
- Experience securing OCI environments including:
- OCI IAM
- OCI Vault
- Cloud Guard
- Security Zones
- OCI Logging
- OCI Container Engine for Kubernetes (OKE)
- Experience developing governance models and security architectures across multi-cloud and hybrid-cloud environments.
- Demonstrated track record implementing consistent security controls, monitoring, identity governance, and compliance frameworks across AWS, Azure, GCP, and OCI.
Preferred Qualifications
- CISSP, CCSP, GIAC, SABSA, or equivalent advanced security certifications.
- Prior experience serving as:
- VP Product Security
- Head of Product Security
- Chief Product Security Officer
- Distinguished Security Architect
- Senior Security Executive within a cybersecurity or cloud technology company.
- Experience working in publicly traded technology organizations and interacting with Audit Committees and Board-level Cybersecurity Committees.
- Experience supporting enterprise cybersecurity products, vulnerability management platforms, endpoint security solutions, cloud security tools, SIEMs, or security operations technologies.
Qualys is an Equal Opportunity Employer, please see our EEO policy.

