Product Security Engineering Manager
Job description
About the role
You will set strategy and lead execution of application security, platform security, and federal (FedRAMP) programs for Bugcrowd. You will grow and mentor a geographically distributed team of security engineers, fostering a culture of engineering excellence, psychological safety, and continuous learning. You will drive shift-left initiatives across architecture reviews, threat modeling, SAST/DAST, continuous end-to-end testing, and advanced fuzzing to embed security early and often. You will design and launch a Security Foundations program focused on secure-by-default engineering to systematically eradicate entire classes of vulnerabilities. You will own the security roadmap and day-to-day operations of the FedRAMP program, ensuring alignment with customer and regulatory demands. You will partner closely with software engineering, DevOps, and product management teams to integrate security into delivery workflows. If you are passionate about building secure-by-default systems and empowering a team to proactively manage risk, we want to meet you.
Key facts
What you'll do
Lead, grow, and empower a high-performing team of product security engineers across distributed locations, fostering a culture of engineering excellence, psychological safety, and continuous learning.
Drive the secure development lifecycle by owning and evolving processes around architecture reviews, threat modeling, SAST, DAST, continuous end-to-end testing, and advanced fuzzing to shift security left.
Design and launch a Security Foundations program focused on secure-by-default engineering, creating paved roads and developer guardrails to eradicate entire classes of vulnerabilities.
Own the security roadmap and day-to-day operations of the FedRAMP program, ensuring controls are implemented, maintained, and continuously improved.
Collaborate with software engineering and DevOps teams to integrate security tools and practices into CI/CD pipelines and infrastructure as code workflows.
Implement and scale automated security testing strategies, including SAST, DAST, SCA, and fuzzing, to detect vulnerabilities before production.
Build and maintain strong partnerships with product management, operations, and compliance teams to align security initiatives with business objectives.
Guide technical decision-making and hands-on implementation for complex security challenges while mentoring engineers on best practices.
Drive measurable improvements in security posture, compliance readiness, and development velocity through data-informed program management.
Champion secure coding standards, threat modeling practices, and continuous learning to elevate the organization's security culture.
Promote transparency and communication across engineering and security teams to ensure risks are surfaced and addressed proactively.
Continuously evaluate emerging threats, tooling, and frameworks to evolve the security program and maintain a robust defense.
Requirements
Demonstrate 7+ years of experience in cybersecurity, with a focus on Product Security, Application Security, or Platform Security as a core professional background.
Bring 2+ years of direct experience managing and mentoring a team of security engineers, leading through hands-on technical guidance and career development.
Showcase demonstrable experience driving sustained improvement and managing complex projects that span multiple teams and business units to successful completion.
Exhibit excellent communication skills with a proven ability to build strong partnerships with software engineering, DevOps, product management, and operations teams.
Possess deep, hands-on experience integrating security into modern CI/CD pipelines, including threat modeling, architecture reviews, SAST, DAST, SCA, and automated testing strategies.
Show fluency in at least one or more modern programming languages such as Python, Go, Ruby, or Java to facilitate code reviews, script automation, and security tooling implementation.
Maintain a strong understanding of cloud-native architectures including AWS, GCP, or Azure, containerization with Kubernetes and Docker, Linux administration, and Infrastructure as Code using Terraform.
Have practical experience supporting compliance requirements such as FedRAMP, PCI, SOC 2, ISO 27001, or NIST 800-53, with a preference for FedRAMP expertise.
Demonstrate a commitment to ethical security practices, regulatory compliance, and the responsible disclosure and remediation of vulnerabilities.
Show the ability to work effectively in a remote-first environment, coordinating across time zones while maintaining collaboration and productivity.
Bring a strong sense of ownership for security outcomes, with the initiative to identify risks early and drive remediation efforts to closure.
Demonstrate resilience and adaptability in responding to evolving threats, balancing strategic planning with tactical execution.
Nice to have
Previous experience managing, triaging, or actively participating in Bug Bounty programs to understand attacker mindsets and vulnerability trends.
A background in building "paved roads" or secure-by-default frameworks that enable developers to deliver securely by default.
Experience with data and AI-powered security platforms that leverage collective intelligence and threat-informed program management.
Familiarity with security knowledge platforms that unify crowdsourced insights, threat intelligence, and program telemetry.
Background working with distributed engineering teams and fostering collaboration across global security and product organizations.
Practical notes
This is a remote role based in the United States.
Full-time employment is expected with standard business-hour availability for coordination.
Travel is not required for this role.
No visa sponsorship is currently available for this position.
Please apply only if you meet the outlined eligibility criteria and can commit to the responsibilities and expectations described.