Principal Product Security Program Leader

Advanced Micro Devices, IncSan Jose, CA
Hybrid

About The Position

AMD is seeking an experienced Product Security Leader to serve as the primary point of accountability for product security across the Adaptive & Embedded Computing (AECG) business unit. This role owns end-to-end coordination of vulnerability response, secure development lifecycle (SDL) governance, and regulatory compliance for AMD's Adaptive and Embedded Computing product lines. The successful candidate will partner closely with AMD's Product Security Office (PSO), Corporate Legal and business-unit security subject matter experts across hardware, firmware, and software tooling teams. This is a high-visibility role that is critical to meeting AMD's security commitments to its customers, including the EU Cyber Resilience Act (CRA), GDPR, and contractual security obligations with hyperscale and OEM partners.

Requirements

  • Expert level of product security, PSIRT, or Security Design Lifecycle leadership experience in semiconductor, EDA software, embedded systems, or a comparable industry; FPGA / adaptive computing experience is a strong plus.
  • Demonstrated leadership with a PSIRT or product coordinated vulnerability disclosure (CVD) program, including triage, CVSS scoring, CVE assignment, security bulletin/advisory authoring, and coordinated disclosure with hyperscalers, OEMs, and independent security researchers.
  • Working expertise with SAST tooling (e.g., Coverity, CodeQL), SCA/SBOM tooling (e.g., Black Duck, SPDX, CycloneDX), threat modeling methodologies, and secure SDLC frameworks (eg, ISO/SAE 21434, NIST SSDF).
  • Demonstrated familiarity with the EU Cyber Resilience Act (CRA), GDPR, and adjacent global cybersecurity regulations, with the ability to translate regulatory text into engineering requirements.
  • Track record partnering with Legal, Corporate Communications, and Compliance teams on regulated disclosures and customer-facing security assessments.
  • Strong executive communication skills: able to produce concise status reporting, brief senior leadership, and translate technical findings into business and customer impact.

Nice To Haves

  • Experience with FPGA design tool flows (e.g., Vivado, Vitis, Vitis HLS) and embedded software stacks (e.g., PetaLinux, Yocto, Xen).
  • Familiarity with information security management standards such as ISO/IEC 27001, in addition to product-security-specific frameworks.
  • Active participation in industry security groups such as the FIRST PSIRT SIG, OpenSSF working groups, OCP Security, or PSIRT Services Framework contributors.
  • Familiarity with bug bounty platform operations, including researcher engagement and reputation management.
  • Experience contributing to or interpreting regulator guidance (e.g., ENISA, national cybersecurity agencies) and participation in relevant standards bodies (e.g., TCG, IETF, IEEE).
  • Relevant industry certifications a plus: CISSP, CISM, CSSLP, or equivalent.

Responsibilities

  • Own product security governance for the business unit — primary interface with AMD's Product Security Office on vulnerability management, SDL health, and remediation progress.
  • Coordinate response across embedded security experts spanning silicon, firmware, and software tooling to triage and resolve vulnerability reports from researchers, internal teams, and customers.
  • Maintain and evolve the security threat model for AMD's adaptive-computing design tools.
  • Partner with Legal and Compliance to align the business unit with the EU Cyber Resilience Act, GDPR, and related regulatory requirements, including SBOM and vulnerability disclosure obligations.
  • Facilitate customer-facing security assessments and due-diligence requests.
  • Serve as incident lead for high-severity vulnerabilities and active exploit reports, driving timely resolution and coordinated disclosure with partners and customers.
  • Brief business-unit and executive leadership on security posture, material incidents, and program health.

Benefits

  • AMD benefits at a glance.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service