Product Security Director

Crunchyroll, LLCLos Angeles, CA
$249,000 - $305,000Hybrid

About The Position

Crunchyroll is growing and evolving, creating both new opportunities and new challenges as it protects millions of anime fans worldwide. We are looking for a security leader who wants to shape how engineering builds and operates securely at scale--while still shipping quickly and with high quality. In this Principal-level, hands-on Security Director role, you will report to the SVP of Engineering. You will connect strategy to execution by turning security goals into secure-by-default systems and practices that teams actually use. You will partner with engineering leaders and senior ICs to reduce friction, define priorities, and drive consistent follow-through, protecting our fans and our platform without sacrificing delivery velocity. Success will be through influence and enablement. You will also periodically build proof of concept solutions that make it easier for teams to adopt the right security patterns, such as reference implementations and tooling integrations. This position is based in Los Angeles, California. We work a hybrid schedule and are in-office three days a week: Tuesday, Wednesday, and Thursday.

Requirements

  • Principal-level technical leadership with a proven track record of leading cross-team security initiatives through influence, clarity, and shipping real systems—not just policies.
  • Strong application security fundamentals such as: authn/authz, session security, secure API design, data protection, threat modeling, and secure SDLC practices.
  • Practical risk manager, with the ability to prioritize, measure tradeoffs, and create guardrails that teams actually adopt.
  • Cloud & platform security experience such as: IAM concepts, secrets management, key management, service-to-service auth patterns, and logging/detection fundamentals.
  • DevSecOps and automation mindset and experience integrating security checks into CI/CD with minimal developer friction.
  • Depth in vulnerability management, knowing how to triage, develop remediation strategies, verify fixes, all while partnering with teams to close the loop quickly.
  • Excellent communication skills including concise, executive-ready writing and strong technical coaching abilities for engineers.

Nice To Haves

  • Experience with streaming/media security and DRM ecosystems and output protection concepts.
  • Experience with mobile and device ecosystems (iOS/Android/TV devices), including secure storage patterns and platform attestation.
  • Familiarity with reverse engineering tools and client hardening/anti-tamper approaches.
  • Exposure to privacy/security compliance partnerships (GRC) and working with legal/product on policy requirements.

Responsibilities

  • Drive adoption of required controls across engineering by establishing clear engineering playbooks, paved paths, and secure-by-default platform capabilities that can be consistently adopted across services, regardless of engineering domain.
  • Ensure threat modeling and security architecture considerations are built into how engineering designs and ships using approved patterns and reference architectures as the default starting point.
  • Drive early escalation and propose alternatives (sequencing, compensating controls, platform changes) when requirements are infeasible or disproportionately costly, so we maintain momentum without accepting unmanaged risk.
  • Identify cross-domain architectural risks and drive resolution across teams, bringing the right stakeholders together and escalating when tradeoffs require executive judgment.
  • Run the operating rhythm across engineering for vulnerability intake, triage, ownership assignment, remediation planning, verification, and escalation. Ensure timely fixes and eliminate repeat issue classes through platform/tooling improvements.
  • Partner with engineering teams to integrate enterprise security tooling into CI/CD and production environments, and ensure engineering can reliably produce evidence of compliance in a low-friction, automated way.
  • Improve security incident preparedness in engineering (runbooks, exercises, detection hooks) and ensure post-incident actions translate into durable engineering improvements.
  • Serve as the primary engineering counterpart to Global Security, translating enterprise policies, controls, tooling, and compliance requirements into adoptable engineering practices and roadmaps, and feeding back where standards need better patterns, automation, or sequencing to scale.

Benefits

  • Great compensation package including salary plus performance bonus earning potential, paid annually.
  • Flexible time off policies allowing you to take the time you need to be your whole self.
  • Generous medical, dental, vision, STD, LTD, and life insurance
  • Health Saving Account HSA program
  • Health care and dependent care FSA
  • 401(k) plan, with employer match
  • Employer paid commuter benefit
  • Support program for new parents
  • Pet insurance
  • Some of our offices are pet friendly!
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service