Vice President, Product Security

QualysApplyPublished 2 days agoFirst seen 1 days ago
Apply

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Qualifications

Leadership & Executive Management

  • 12+ years of progressive experience in cybersecurity, application security, product security, cloud security, or security architecture, including 7+ years in senior leadership roles managing globally distributed security, engineering, and architecture teams. 
  • Proven experience building, scaling, and leading high-performing Product Security organizations supporting large-scale SaaS, cloud-native, and enterprise software platforms. 
  • Demonstrated success leading directors, senior managers, architects, and security engineering teams across multiple geographies and product portfolios. 
  • Experience owning multi-million-dollar security budgets, strategic planning processes, headcount forecasting, vendor relationships, and security program execution. 
  • Strong executive presence with the ability to communicate technical risk, business impact, and security strategy to Boards of Directors, Executive Leadership Teams, auditors, regulators, and customer executives. 
  • Proven ability to influence security and product roadmaps across Engineering, Product Management, Cloud Operations, Legal, Compliance, Customer Success, Sales Engineering, and Corporate Security organizations. 
  • Experience participating in M&A due diligence, product security assessments, and post-acquisition security integration activities is highly desirable. 

Product Security & Secure Engineering

  • Deep expertise in product security, application security, cloud security, DevSecOps, software supply chain security, and secure software development lifecycle (SSDLC) practices. 
  • Demonstrated experience implementing and scaling: 
  • Security-by-design principles 
  • Threat modeling frameworks 
  • Secure coding standards 
  • Vulnerability management programs 
  • Red teaming exercises 
  • Bug bounty and responsible disclosure programs 
  • Software supply chain security controls 
  • SBOM management 
  • Secure CI/CD pipelines 
  • Container and Kubernetes security 
  • Extensive knowledge of modern authentication and identity architectures including: 
  • Zero Trust 
  • OAuth2 
  • OpenID Connect 
  • SAML 
  • PKI 
  • Hardware-backed cryptography 
  • Secrets management 
  • PAM solutions 
  • Deep understanding of modern security frameworks including: 
  • NIST Cybersecurity Framework 
  • NIST SP 800-53 
  • NIST SP 800-171 
  • NIST SP 800-218 (SSDF) 
  • CIS Controls 
  • OWASP Top 10 
  • OWASP ASVS 
  • SOC 2 
  • ISO 27001 

Federal Compliance & Government Security Experience

FedRAMP

  • 10+ years of experience supporting U.S. federal cybersecurity programs and regulatory frameworks. 
  • Proven experience leading, achieving, and sustaining multiple FedRAMP Moderate and FedRAMP High Authorizations to Operate (ATO) for cloud-native SaaS products. 
  • Extensive experience working directly with: 
  • Federal Agencies 
  • Joint Authorization Board (JAB) stakeholders 
  • Third Party Assessment Organizations (3PAOs) 
  • Authorizing Officials 
  • Government security assessors 
  • Deep knowledge of: 
  • NIST SP 800-53 Rev. 5 
  • FedRAMP Continuous Monitoring 
  • POA&M management 
  • Significant Change Requests 
  • Annual Assessments 
  • Vulnerability remediation requirements 
  • Configuration management controls 
  • Demonstrated ownership of security strategy and product architecture supporting regulated government cloud environments. 

CMMC & DoD Cloud Requirements

  • Hands-on experience implementing and managing environments aligned to: 
  • CMMC Level 2 requirements 
  • NIST SP 800-171 
  • DFARS 252.204-7012 
  • DFARS 252.204-7019 
  • DFARS 252.204-7020 
  • DFARS 252.204-7021 
  • Experience designing and securing solutions deployed within Department of Defense environments requiring Impact Level (IL) authorization. 
  • Demonstrated knowledge and practical experience supporting: 
  • DoD Impact Level 4 (IL4) 
  • DoD Impact Level 5 (IL5) 
  • DoD Impact Level 6 (IL6) 
  • Experience working with government customers handling Controlled Unclassified Information (CUI), National Security Systems (NSS), and classified or highly regulated workloads. 
  • Familiarity with DISA STIGs, SRGs, DoD Cloud Computing Security Requirements Guide (CC SRG), and associated authorization processes. 

NIAP & Common Criteria

  • Experience leading or supporting NIAP Common Criteria certification efforts for enterprise software, networking products, endpoint security solutions, or cybersecurity technologies. 
  • Strong understanding of: 
  • Common Criteria Evaluation and Validation Scheme (CCEVS) 
  • Protection Profiles 
  • Security Targets 
  • Evaluation Assurance Levels (EAL) 
  • NIAP product certification lifecycle 
  • Experience working with accredited testing laboratories and certification authorities to achieve and maintain product certifications. 

Multi-Cloud Security & Hyperscaler Expertise

  • 15+ years of experience designing and securing cloud-native SaaS platforms operating at enterprise scale. 
  • Demonstrated architecture and operational expertise across multiple hyperscale cloud service providers including: 

Amazon Web Services (AWS)

  • Experience securing AWS environments leveraging:  
  • Organizations 
  • IAM 
  • KMS 
  • CloudTrail 
  • GuardDuty 
  • Security Hub 
  • Control Tower 
  • ECS/EKS 
  • Native compliance controls 

Microsoft Azure

  • Experience securing Azure environments utilizing:  
  • Entra ID 
  • Azure Policy 
  • Defender for Cloud 
  • Key Vault 
  • Azure Monitor 
  • Microsoft Sentinel 
  • AKS 
  • Landing Zone architectures 

Google Cloud Platform (GCP)

  • Experience designing secure GCP architectures leveraging:  
  • Cloud IAM 
  • Security Command Center 
  • Cloud KMS 
  • Anthos 
  • Chronicle 
  • Organization Policies 
  • GKE security controls 

Oracle Cloud Infrastructure (OCI)

  • Experience securing OCI environments including: 
  • OCI IAM 
  • OCI Vault 
  • Cloud Guard 
  • Security Zones 
  • OCI Logging 
  • OCI Container Engine for Kubernetes (OKE) 
  • Experience developing governance models and security architectures across multi-cloud and hybrid-cloud environments. 
  • Demonstrated track record implementing consistent security controls, monitoring, identity governance, and compliance frameworks across AWS, Azure, GCP, and OCI. 

Preferred Qualifications

  • CISSP, CCSP, GIAC, SABSA, or equivalent advanced security certifications. 
  • Prior experience serving as: 
  • VP Product Security 
  • Head of Product Security 
  • Chief Product Security Officer 
  • Distinguished Security Architect 
  • Senior Security Executive within a cybersecurity or cloud technology company. 
  • Experience working in publicly traded technology organizations and interacting with Audit Committees and Board-level Cybersecurity Committees. 
  • Experience supporting enterprise cybersecurity products, vulnerability management platforms, endpoint security solutions, cloud security tools, SIEMs, or security operations technologies. 

Qualys is an Equal Opportunity Employer, please see our EEO policy.