Director, Product Security
Job description
About the role
This position defines and directs a product security program across the Everpure portfolio. The role partners with engineering, IT, and risk leadership to embed secure-by-design practices into the development lifecycle. The hire owns the strategy, execution, and maturation of product security initiatives aligned with business objectives. They balance proactive defense with corporate business agility to sustain customer trust in the Everpure Platform. The position ensures security considerations are integrated from initial concept through production deployment. This role drives the adoption of security standards and best practices across product teams. The hire acts as the authoritative voice for product security within the organization.
Key facts
What you'll do
Establish and evolve the end-to-end product security program for the Everpure Platform and its connected products.
Architect and implement security controls, processes, and tooling tailored to the specific needs of product development teams.
Translate complex technical threats into clear risk-mitigation strategies that resonate with executive leadership and influence strategic decisions.
Own multi-vendor tooling budgets, optimizing security tool portfolios for measurable value, operational efficiency, and business alignment.
Champion secure-by-design principles by collaborating with engineering leaders to embed security practices into architecture reviews and delivery pipelines.
Drive the adoption of modern CI/CD platform security tools, application security testing, and infrastructure security measures across the product portfolio.
Develop and maintain a comprehensive understanding of the threat landscape as it applies to product ecosystems, ensuring defenses evolve accordingly.
Build and lead a high-performing product security engineering team, providing clear career paths, mentorship, and structured development.
Establish metrics and reporting mechanisms to track findings, measure program effectiveness, and demonstrate reduction in organizational risk.
Foster cross-functional collaboration with IT, risk, and engineering teams to create a cohesive security culture grounded in trust and shared responsibility.
Leverage mastery of infrastructure, APIs, public cloud providers, container services, and application security to guide architectural decisions.
Communicate security posture and risk to diverse stakeholders, ensuring transparency and alignment on security objectives and outcomes.
Optimize security workflows to increase coverage and accelerate secure delivery without compromising business agility.
Serve as the primary liaison between product teams and enterprise security functions, ensuring consistent policy implementation.
Requirements
Bachelor's degree or equivalent experience is required for this role.
Candidates must possess advanced cybersecurity leadership experience managing high-performing security engineering teams.
Demonstrated mastery of infrastructure security is mandatory, covering application security, APIs, public cloud providers, container services, and modern CI/CD platform security tools.
The ability to influence without direct authority and navigate complex organizational dynamics is essential.
Experience translating complex technical threats into executive-level risk-mitigation strategies is required.
Proven capability to own, optimize, and govern multi-vendor tooling budgets for measurable business value is necessary.
Strong written and verbal communication skills are required to bridge technical execution with corporate business goals.
Candidates must be able to engage stakeholders at all levels to build collaboration and alignment around security initiatives.
The role requires the capacity to operate effectively in a fast-paced, multi-team environment with competing priorities.
Security engineers must leverage modern CI/CD platform security tools, application security practices, and public cloud security configurations.
A commitment to secure-by-design principles and continuous improvement of security processes is mandatory.
The candidate must be comfortable managing end-to-end responsibilities from strategy through execution and measurement.
Adaptability to constant change in the threat landscape and regulatory requirements is a non-negotiable requirement.
Nice to have
Experience in regulated industries or with compliance frameworks is preferred.
Background in IoT, embedded systems, or hardware security is a plus.
Familiarity with DevSecOps maturity models and security automation frameworks is preferred.
Practical notes
Roles are eligible for incentive pay and equity.
Typical interview steps
Security interviews usually include a technical assessment, a threat modeling exercise, and behavioral rounds. Candidates may be asked to review a code sample for vulnerabilities or design a secure system. Practical knowledge and clear risk communication are the core skills. Interviewers often ask how you triage and communicate risk. Showing calm judgment under pressure matters as much as technical depth.