About The Position

We are hiring a Sr. Manager, Security Product Management - Governance & Controls to transform our security governance function into a scalable, productized capability. This role replaces document-centric compliance with security requirements and controls built directly into engineering and business workflows. As the product owner for security control framework, this role owns the user experience of security - ensuring policies, standards and controls are designed for adoption, automated by default and measured through real-time data. This role is also accountable for periodic security maturity assessments, using control telemetry to continuously improve security posture. You will partner closely with Product & Engineering, GRC Engineering, Security, Compliance, and business teams to ensure security requirements are designed into systems and delivery pipelines early, enabling teams to move fast while building securely by default. This position is a people manager role reporting to the Senior Director of Security Governance, Risk Management, and Compliance (GRC).

Requirements

  • 8+ years in technical product management, platform security, or security engineering, with a track record of shipping internal platforms
  • 5+ years of people management experience, including hiring and developing hybrid product and engineering teams
  • Bachelor’s Degree in Computer Science, Engineering, Management Information Systems, or a related technical field
  • Proven ability to transform manual or document-driven processes into scalable, automated technical products
  • Expereince with security frameworks (NIST CSF, ISO 27001, SOC 2) and adapting them to high-velocity engineering environments
  • Experience with modern software delivery (CI/CD, GitOps, Infrastructure-as-Code)
  • Experience using telemetry, APIs, SQL, or visualization tools to measure adoption and maturity

Nice To Haves

  • Exceptional ability to prioritize based on risk-reduction ROI, and influence audiences from executive leadership to engineers
  • Background in security engineering, SRE, or platform engineering
  • Data-driven mindset
  • Experience building or owning internal developer platforms at scale
  • Hands-on experience with policy-as-code / control-as-code and automated enforcement
  • Proven track record of simplifying or retiring low-value security controls in fast-moving environments

Responsibilities

  • Build and lead a high-performing team that replaces document-centric security governance with scalable, productized control capabilities
  • Define and drive a multi-year product vision and roadmap for security governance focused on adoption and measurable risk reduction
  • Define and clearly communicate product goals and requirements, working cross-functionally with Security, GRC Product Management, and Engineering to deliver solutions
  • Establish the architecture blueprint that transforms security governance into a scalable product platform
  • Own the end-to-end lifecycle of security policies, standards, and controls as versioned, releasable product assets
  • Translate security, compliance, and risk requirements into developer-friendly product features embedded in engineering workflows (CI/CD, infrastructure provisioning, service onboarding)
  • Run continuous Voice of the Customer research to identify friction and drive feature improvements
  • Analyze cost, risk, and engineering tradeoffs, facilitating discussions to reach alignment and clear decisions
  • Define critical success metrics, implement tracking mechanisms, and measure feature impact post-launch using telemetry and data insights
  • Drive iterative delivery and continuous improvement through data-informed prioritization
  • Lead internal product marketing and advocacy of security governance capabilities
  • Partner with GRC Engineering and Security Program Management to ensure features ship on time and align with security priorities
  • Own risk-based prioritization and deprecation decisions, including when to simplify, delay, or retire security controls
  • Provide executive-level visibility into governance maturity using real-time data, not point-in-time assessments

Benefits

  • Bonus: Sales personnel are eligible for variable incentive pay dependent on their achievement of pre-established sales goals. Non-Sales roles are eligible for a company bonus plan, which is calculated as a percentage of eligible wages and dependent on company performance.
  • Stock: This role is eligible to receive Restricted Stock Units (RSUs).
  • Paid Time Off: earned time off, as well as paid company holidays based on region
  • Paid Parental Leave: take up to six months off with your child after birth, adoption or foster care placement
  • Full Health Benefits Plans: options for 100% employer paid and minimum employee contribution health plans from day one of employment
  • Retirement Plans: select retirement and pension programs with potential for employer contributions
  • Learning and Development: options for coaching, online courses and education reimbursements
  • Compassionate Care Leave: paid time off following the loss of a loved one and other life-changing events
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service