About The Position

The Security Product Lead – Product Security & AI Security is responsible for defining the strategic direction, roadmap, and measurable outcomes for securing the organization's product lifecycle and emerging AI/ML initiatives. This role sits within the Security Strategy & Delivery team and partners closely with the Product Security, Engineering, and Data Science/AI functional leaders and operational teams. This position ensures that Product Security and AI Security capabilities are treated as internal security products—aligned to enterprise risk priorities, supported by a clear roadmap, measured through defined KPIs, and delivered through structured program governance. The role requires strong cross-functional collaboration, strategic thinking, and the ability to influence without direct authority. By proactively embedding security controls into the product development lifecycle (SDLC) and addressing unique risks associated with AI/ML systems, this role directly supports the organization's overarching goal of protecting member trust, safeguarding corporate assets, and ensuring the continued stability and growth of the business.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, or related discipline.
  • 7+ years of experience in cybersecurity, risk management, or technology strategy roles.
  • Demonstrated experience in Product Security (AppSec), DevSecOps, or AI/ML Security domains.
  • Demonstrated experience building and managing strategic roadmaps tied to measurable outcomes.
  • Experience providing strategic security due diligence and executing cyber security integration for M&A activities.
  • Strong understanding of secure development practices, vulnerability management, and common software security frameworks.
  • Understanding of AI/ML concepts and associated security risks, including data provenance, model integrity, and adversarial machine learning.
  • Strong product mindset with ability to translate strategy into execution.
  • Experience working in matrixed organizations with cross-functional stakeholders.
  • Strong analytical, communication, and executive presentation skills.

Responsibilities

  • Strategy & Roadmap Stewardship Develop and maintain a multi-year strategy and roadmap for Product Security and AI Security capabilities.
  • Align roadmap priorities with enterprise risk objectives, regulatory requirements (e.g., data privacy, AI governance), and evolving attack surface.
  • Identify capability gaps (e.g., secure coding practices, AI model integrity) and define strategic investment opportunities.
  • Translate strategic objectives into structured, sequenced initiatives.
  • Lead Security Due Diligence: Own the end-to-end security assessment process for M&A targets, including technical architecture reviews, vulnerability assessments, security program maturity evaluations, and risk quantification
  • Develop M&A Security Strategy: Define and continuously improve Meta’s M&A security playbook, methodologies, and standards to enable rapid, consistent, and thorough security evaluations
  • Drive Integration Planning: Partner with target companies and internal teams to design secure integration roadmaps that balance speed-to-value with security requirements
  • Manage M&A security assessments and integration roadmaps to design secure integration roadmaps, balancing speed and security
  • Define the value proposition and service model for Product Security and AI Security capabilities, including security requirements for all new product features.
  • Establish clear capability maturity targets (e.g., DevSecOps integration level, AI risk mitigation completeness) and continuous improvement plans.
  • Maintain and prioritize a strategic backlog aligned to measurable risk reduction outcomes (e.g., reduction in critical vulnerabilities, secure-by-design adoption).
  • Ensure capabilities are treated as ongoing products with lifecycle ownership, not one-time projects.
  • Translate business priorities, AI adoption strategy, and risk signals into a prioritized portfolio
  • Partner with engineering and product teams to reduce friction and improve predictability
  • Mature Secure SDLC practices and embed automation into CI/CD pipelines
  • Define and track outcome-based metrics (risk reduction, adoption, efficiency)
  • Own the portfolio view of Product Security & AI Security initiatives within the broader security strategy.
  • Structure and manage strategic programs required to deliver roadmap objectives (e.g., implementing an AI Red Team program, rolling out a new static analysis tool).
  • Define milestones, delivery plans, and success metrics for major initiatives.
  • Track progress against portfolio commitments and escalate risks proactively.
  • Manage cross-functional dependencies across Engineering, Product Management, Data Science, Legal, and other stakeholders.
  • Support quarterly and annual planning cycles, including investment
  • Ensure predictable execution through structured governance and reporting cadence.
  • Partner closely with the Product Security and AI/ML functional leaders and teams to align on priorities and execution sequencing.
  • Collaborate with Engineering, Product Management, Legal, Risk, and Compliance stakeholders.
  • Facilitate stakeholder alignment, trade-off decisions (e.g., security vs. speed), and expectation management.
  • Influence without direct authority to drive secure design principles and manage cross-functional projects to ensure delivery
  • Monitor industry trends in software supply chain attacks, emerging vulnerabilities (e.g., OWASP Top 10), and AI-specific threats (e.g., model poisoning, prompt injection).
  • Identify opportunities for automation, analytics enhancement, and process optimization within DevSecOps pipelines.
  • Incorporate lessons learned from penetration tests, bug bounty programs, and security audits into roadmap evolution.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service