Manager, Product Security
Job description
Financial, Inc.
About the role
This position leads a team focused on cloud, application, and AI security within the Product Security organization. You will guide the protection of cloud infrastructure and applications while establishing frameworks for the safe integration of AI technologies across company systems. In this capacity, you will own the strategic oversight of security initiatives that touch every layer of our product stack. You will translate complex risk findings into actionable plans that enable rapid innovation without compromising integrity. The role requires you to act as both a technical expert and a collaborative leader who can navigate ambiguity with confidence. You will be responsible for ensuring that security is embedded into the fabric of our product development lifecycle. Ultimately, your work will safeguard our members and our systems while enabling the company to scale securely in a dynamic market.
Key facts
What you'll do
- Manage the security posture for cloud infrastructure, application systems, and AI-enabled product features.
- Influence platform team roadmaps and align security priorities across departments.
- Collaborate with engineering and product groups to integrate security into development workflows and system designs.
- Lead and mentor a team of security engineers to ensure high technical standards and impact.
- Develop strategies for securing cloud-native architectures at scale.
- Create security guardrails for internal and third-party AI integrations to prevent data leakage, prompt injection, and model misuse.
- Implement automated controls for identity, access, encryption, vulnerability management, and secure SDLC.
- Direct response efforts for security incidents involving cloud, application, or AI risks.
- Establish metrics and reporting mechanisms to measure the effectiveness of security controls and program maturity.
- Partner with legal, compliance, and privacy teams to ensure adherence to regulatory requirements and industry standards.
- Conduct threat modeling and risk assessments for new products, features, and architectural changes.
- Drive the adoption of security best practices through documentation, training, and cross-functional enablement sessions.
- Evaluate emerging security technologies and integrate them into the security stack where appropriate.
- Act as the primary point of contact for security-related inquiries from executive leadership and cross-functional stakeholders.
Requirements
- 5+ years of experience in security engineering, specifically in cloud and application security.
- 2+ years of experience in a management or leadership role for security engineers.
- Proficiency with AWS and GCP, Infrastructure as Code (IaC), and modern infrastructure patterns.
- Experience with SAST, DAST, SCA, WAF, and CNAPP tooling.
- Background in securing applications that process sensitive or regulated data.
- Experience securing AI/ML systems or a proven ability to work in emerging, ambiguous security domains.
- Ability to communicate security risks in terms of business impact.
- Experience working in fast-paced, product-focused environments.
- Demonstrated ability to work independently and collaboratively in a distributed team structure.
- Strong written and verbal communication skills to articulate security concepts to both technical and non-technical audiences.
- Commitment to following established security policies, procedures, and governance frameworks.
- Willingness to stay current with evolving threats, attack vectors, and security research.
- Understanding of secure software development lifecycle practices and how to apply them in iterative release environments.
- Readiness to uphold the highest standards of integrity, transparency, and accountability in all security-related activities.
Skills & tools
- Cloud platforms: AWS, GCP
- Security tooling: SAST, DAST, SCA, WAF, CNAPP
- Infrastructure: Infrastructure as Code (IaC)
- AI/ML security principles
Practical notes
- In-office policy: Four days per week in the office, Fridays remote.
- Benefits include health, financial, and wellbeing plans, annual wellness stipend, and parental leave (up to 22 weeks for birthing parents, 12 weeks for non-birthing parents).
- Additional perks include backup care, subsidized commuter benefits, and a generous vacation policy.
- Chime is an Equal Opportunity Employer and considers qualified applicants with criminal histories in accordance with the San Francisco Fair Chance Ordinance.