Product Security Governance Principal

Fifth Third Bank•Cincinnati, OH
•$96,500 - $207,500•Remote

About The Position

Fifth Third Bank is seeking a Product Security Governance Principal to lead and mature Product Security governance for internally developed customer-facing software, APIs, SDKs, integrations, and related services. This role involves defining product scope, engagement criteria, review expectations, decision authorities, escalation paths, and evidence standards. The Principal will develop and maintain standards, procedures, playbooks, templates, decision records, risk records, and supporting guidance. They will facilitate risk-based decisions involving security requirements, control applicability, exceptions, compensating controls, and accountability, while aligning Product Security practices with enterprise architecture, application security, vulnerability management, risk, compliance, audit, and engineering processes. Additionally, the role requires leading a scalable customer assurance model, coordinating security summaries and whitepapers, evaluating customer-facing security statements, and partnering with various teams to support customer, deal, regulatory, and audit needs. The Principal will also lead Product Security coordination for SOC 2 and related readiness activities, support system scoping, and evaluate control design and evidence requirements. A key aspect of the role is defining consistent expectations for product readiness assessments and product-level security evidence, assessing evidence for completeness and relevance, and developing consolidated views of product security risk. The position involves leading governance forums, identifying improvements, providing concise updates to stakeholders, contributing to Product Security strategy, and promoting shared accountability for secure products.

Requirements

  • Seven or more years of progressively responsible experience in Product Security, security governance, cybersecurity assurance, IT risk, security compliance, technology audit, security architecture, or a related discipline.
  • Demonstrated success leading security governance, assurance, readiness, control evaluation, gap analysis, or evidence-review practices in a complex organization.
  • Proven ability to independently evaluate technical and nontechnical evidence, identify material concerns, exercise sound judgment, and recommend defensible decisions.
  • Substantial experience translating security and compliance requirements into practical expectations for product and engineering teams.
  • Demonstrated ability to influence senior stakeholders, facilitate constructive challenge, resolve ambiguity, and drive accountable outcomes across Product, Engineering, Information Security, Risk, Compliance, Audit, Legal, and business teams.
  • Strong understanding of administrative, technical, and operational security controls and how they work together throughout the product lifecycle.
  • Experience maintaining governance artifacts such as standards, procedures, control matrices, evidence inventories, decision records, risk records, and action plans.
  • Strong executive, business, audit, and technical communication skills.
  • Bachelor’s degree in cybersecurity, information technology, information systems, business, accounting, or a related field, or an equivalent combination of education and relevant experience.

Nice To Haves

  • Experience building or maturing a Product Security program in financial services, another regulated industry, or a complex enterprise.
  • Experience supporting SOC 2 readiness, including system scoping, Trust Services Criteria, evidence coordination, gap assessment, and action tracking.
  • Experience with customer-facing software, APIs, SDKs, SaaS platforms, cloud-native services, or distributed products.
  • Familiarity with ISO/IEC 27001, NIST CSF, PCI DSS, cloud shared-responsibility models, and modern software-development practices.
  • Experience developing customer assurance materials, product security summaries, security whitepapers, or similar artifacts.
  • Experience with governance, risk, compliance, workflow, evidence-management, or reporting platforms.
  • Relevant credentials such as CISSP, CISA, CISM, CRISC, CCSP, or ISO 27001 Lead Implementer or Auditor.

Responsibilities

  • Lead and mature Product Security governance for internally developed customer-facing software, APIs, SDKs, integrations, and related services.
  • Define product scope, engagement criteria, review expectations, decision authorities, escalation paths, and evidence standards.
  • Develop and maintain standards, procedures, playbooks, templates, decision records, risk records, and supporting guidance.
  • Facilitate risk-based decisions involving security requirements, control applicability, exceptions, compensating controls, and accountability.
  • Align Product Security practices with established enterprise architecture, application security, vulnerability management, risk, compliance, audit, and engineering processes.
  • Lead a scalable customer assurance model for applicable products and services.
  • Coordinate accurate, reviewable security summaries, whitepapers, assessment responses, and supporting evidence.
  • Evaluate customer-facing security statements for appropriate scope, context, qualifications, and evidence.
  • Partner with Product, Engineering, Risk, Compliance, Legal, Audit, and customer-facing teams to support customer, deal, regulatory, and audit needs.
  • Establish traceability between assurance statements, controls, evidence sources, and accountable owners while increasing consistency and response efficiency.
  • Lead Product Security coordination for applicable SOC 2 and related readiness activities within established enterprise compliance and audit processes.
  • Support system scoping, business-requirement validation, readiness evaluations, gap assessments, evidence coordination, and assessment-provider engagement.
  • Partner with control owners to evaluate control design, evidence requirements, operating effectiveness, and improvement opportunities.
  • Maintain readiness plans, evidence inventories, dependencies, decisions, and accountable action tracking.
  • Translate assessment observations into sustainable improvements while preserving appropriate separation from independent audit or attestation responsibilities.
  • Define consistent expectations for product readiness assessments and product-level security evidence.
  • Evaluate evidence from established activities such as threat modeling, penetration testing, security scanning, software supply chain practices, secure development, incident management, and remediation.
  • Assess evidence for completeness, relevance, recency, traceability, and applicability, including the context and limitations of technical tools.
  • Develop consolidated views of product security risk, control adoption, coverage, and assurance readiness.
  • Establish meaningful indicators and reporting that demonstrate Product Security adoption, maturity, decisions, and accountable actions.
  • Lead governance forums, readiness reviews, working sessions, and decision meetings.
  • Identify recurring themes and recommend scalable improvements to controls, evidence, processes, and stakeholder guidance.
  • Provide concise updates and practical recommendations to technical teams, business stakeholders, and senior leaders.
  • Contribute to Product Security strategy, planning, prioritization, and roadmap development.
  • Promote shared accountability for secure and trusted customer-facing products.

Benefits

  • Comprehensive benefits
  • Differentiated compensation offerings
  • Incentive compensation plan
  • Extensive benefits programs designed to support the individual needs of our employees and their families, encompassing physical, financial, emotional and social well-being.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service