Product Security Leader (Seaport/Boston Onsite)

Posted 13 Days Ago
Be an Early Applicant
Boston, MA, USA
Hybrid
175K-210K Annually
Senior level
Software • Industrial • Automation • Manufacturing
The Role
Build and lead Velotic’s product security program, including secure SDLC practices, security tooling, threat modeling, vulnerability management, security automation, and developer security training. Lead architecture reviews, penetration testing, incident response, compliance activities, customer security assessments, and security champions initiatives. Partner with engineering, product, infrastructure, IT, support, customers, system integrators, and MSSP providers while reporting security metrics and risks to executive leadership.
Summary Generated by Built In
Company Description

WHO WE ARE

Velotic is a newly formed independent software company with a pure-play focus on industrial operations. We unite two category-defining portfolios -- ThingWorx and Kepware (formerly part of PTC) and Proficy (formerly part of GE Vernova) -- to transform industrial manufacturing, at scale. With $350M in annual revenue, a global footprint across a range of industries, a legacy customer base, and our intelligent data connectivity systems and AI solutions, we are one of the world's largest independent software companies focused on industrial operations -- here to power the future of manufacturing.

OUR MISSION 

Enabling the world's industrial producers to do the right things right—across every shift, every plant, every day. We help manufacturers prosper by equipping them with software-defined, data-driven production systems that elevate quality, accelerate cycle times, improve resilience, and enable sustainable profit growth.

Product Security Leader

Velotic is seeking a dynamic and technically driven Product Security Leader to establish and lead the product security function for our newly formed organization. This is a unique greenfield opportunity to build a world-class product security program from the ground up while navigating the complexity of integrating two carved-out companies in the industrial software space. The Product Security Leader will be a hands-on builder and leader who will be responsible for interfacing software development engineers who will be embedding security throughout the software development lifecycle (SDLC), establishing secure development practices, and ensuring with product managers that Velotic's products are built with security as a foundational principle. This role also requires close coordination with technical support, customer success, IT and infrastructure teams, and external partners including System Integrators and MSSP providers.

Job Description

Role Description:

The Product Security Leader at Velotic will play a pivotal role in building security into the DNA of our products during a unique and complex organizational formation. As Velotic brings together engineering teams from two carved-out companies, each with their own development practices, tech stacks, and security maturity levels, this role requires exceptional technical depth, strong relationship-building skills, and the ability to navigate ambiguity while driving toward a unified vision.

This is a true greenfield opportunity where you will define what "good" looks like for product security at Velotic. You'll establish the secure SDLC framework, select and implement security tooling, build a security champions network, and create the processes that will scale with the company's growth. The challenge and opportunity lie in harmonizing security practices across two different engineering cultures while maintaining development velocity and building something better than either organization had before.

The successful candidate will work at the intersection of security, engineering, and product management. You'll need to be technical enough to earn the respect of senior engineers, strategic enough to influence product roadmaps, and pragmatic enough to balance security ideals with business realities. This role requires coordination with external partners—System Integrators who are helping stand up development infrastructure and MSSP providers who deliver security monitoring services—requiring strong vendor management skills alongside technical expertise.

Day-to-day, you'll lead threat modeling sessions, review security architectures, triage vulnerabilities, guide remediation efforts, implement security automation, and work hands-on with development teams to embed security throughout the development process. You'll also be responsible for managing security assessments from customers, responding to security questionnaires, coordinating penetration tests, and ensuring Velotic's products meet compliance requirements for key certifications like SOC 2 and ISO 27001.

A key aspect of this role is building security in a developer-friendly way. You'll need to shift security left without slowing teams down, automate security checks within CI/CD pipelines, provide clear and actionable security guidance, and celebrate security wins to build momentum. You'll establish metrics that demonstrate both security improvements and the business value of the product security program.

This role reports to the Chief Product Officer and collaborates closely with the CISO, VP/Directors of Engineering, Product Management leaders, Infrastructure/Cloud teams, and external security partners. You'll regularly present product security metrics, risk assessments, and program updates to executive leadership, particularly around critical vulnerabilities, security incidents, and program maturity progress.

The ideal candidate for this role is someone who thrives at the intersection of security and engineering, loves building programs from scratch, and is energized by the challenge of bringing together different organizations with a shared security vision. You should be comfortable with ambiguity, excellent at influencing without authority, and passionate about making security an enabler of innovation rather than a blocker. If you want to leave a lasting mark by building a world-class product security program during a critical formative period, this is the opportunity for you.

This position offers significant autonomy, direct impact on product strategy, close collaboration with executive leadership and private equity stakeholders, and the satisfaction of building something meaningful from the ground up in a well-funded, growth-oriented environment.

Qualifications

Qualifications:

  • Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, or related technical field; Master's preferred
  • 8+ years of experience in application security, product security, or secure software development, with at least 3 years in a leadership role
  • Proven experience building or scaling product security programs in SaaS, B2B software, B2C software, or product-focused technology companies
  • Preferred experience leading product security through organizational transitions such as carve-outs, mergers, acquisitions, or multi-entity integrations 
  • Deep technical expertise in application security, including secure coding practices, security architecture, threat modeling, and vulnerability management
  • Strong knowledge of common vulnerabilities and attack patterns (OWASP Top 10, SANS Top 25, etc.) and modern application security testing methodologies
  • Experience with application security testing tools and methodologies including SAST, DAST, IAST, SCA, container security scanning, and penetration testing
  • Hands-on experience with modern development practices including CI/CD pipelines, DevSecOps, cloud-native architecture, microservices, APIs, and infrastructure-as-code
  • Strong understanding of cloud security across major platforms (AWS, Azure, GCP) and containerization technologies (Docker, Kubernetes)
  • Experience with security automation, security tooling integration, and shifting security left in the development process
  • Knowledge of secure software development frameworks (NIST SSDF, OWASP SAMM, BSIMM, ISO/IEC 27034) and ability to implement them in practical, developer-friendly ways
  • Maintains a deep understanding of the compliance requirements relevant to software products (SOC 2, ISO 27001, PCI DSS, GDPR, CCPA, etc.)
  • Proven ability to work effectively with engineering teams, influence without direct authority, and build security champions programs
  • Strong communication skills with ability to translate technical security concepts for both technical and non-technical audiences
  • Relevant certifications such as CSSLP, CEH, OSCP, GWAPT, AWS/Azure/GCP Security certifications, or similar credentials preferred
  • Experience harmonizing security tools, processes, and practices across a large development organization with different tech stacks and maturity levels
  • Proven ability to balance, prioritize and roadmap security initiatives with business velocity and developer capacity

Responsibilities:

Program strategy and operating model:

  • Build and lead Velotic's product security program from the ground up, establishing security practices, tools, processes, and culture across engineering teams
  • Build and maintain a security champions program to embed security expertise within engineering teams and foster a culture of security ownership
  • Develop and deliver security training tailored to developers, covering secure coding practices, common vulnerabilities, and security tooling

Secure SDLC and engineering enablement:

  • Develop and implement a unified secure SDLC framework that harmonizes security practices across both carved-out entities while respecting existing development workflows and gradually elevating security maturity
  • Oversee the selection, implementation, and management of application security testing tools (SAST, DAST, SCA, container scanning, etc.) across multiple development environments and tech stacks
  • Work with infrastructure and cloud teams to ensure secure deployment practices, container security, Kubernetes security, and cloud security best practices
  • Lead software supply chain security initiatives, including open-source security management, dependency scanning, and software bill of materials (SBOM) generation

Security testing and vulnerability management:

  • Coordinate product security initiatives across internal engineering teams, System Integrators, and MSSP providers to ensure consistent security controls and effective vulnerability management
  • Establish and lead threat modeling practices for new features, products, and architectural changes, working closely with engineering and product teams
  • Manage vulnerability disclosure programs, coordinate security issue triage and remediation, and establish SLAs for vulnerability resolution based on risk
  • Establish incident response procedures for product security vulnerabilities, coordinating with engineering teams on remediation and customer communication
  • Partner with product management to incorporate security requirements into product roadmaps and ensure security enhances rather than impedes product innovation

Governance, compliance, and customer assurance:

  • Define and implement security requirements for all stages of the software development lifecycle, from design through deployment and maintenance
  • Ensure compliance for products with regulatory and certification requirements (SOC 2, ISO 27001, etc.)

Leadership and influencing:

  • Lead security architecture reviews for new products, features, and infrastructure changes, providing actionable guidance to engineering teams
  • Lead security testing initiatives including penetration testing coordination, bug bounty program management, and red team exercises
  • Establish metrics and KPIs to measure product security posture, track vulnerability trends, and demonstrate program effectiveness to leadership
  • Manage third-party security assessments of Velotic's products, including customer security reviews, vendor questionnaires, and independent audits
  • Serve as the primary product security liaison with SI partners implementing development infrastructure and MSSP providers delivering security monitoring services
  • Build and manage the product security budget, including tooling investments, third-party testing services, and team resources
  • Stay current with emerging threats, vulnerabilities, and security technologies relevant to the product software industry

Additional Information

All your information will be kept confidential according to EEO guidelines.

Skills Required

  • Bachelor’s degree in Computer Science, Cybersecurity, Software Engineering, or a related technical field
  • 8+ years of experience in application security, product security, or secure software development
  • At least 3 years of experience in a leadership role
  • Experience building or scaling product security programs in a SaaS, B2B software, B2C software, or product-focused technology company
  • Deep expertise in application security, secure coding, security architecture, threat modeling, and vulnerability management
  • Knowledge of OWASP Top 10, SANS Top 25, and modern application security testing methodologies
  • Experience with SAST, DAST, IAST, SCA, container security scanning, and penetration testing
  • Hands-on experience with CI/CD pipelines, DevSecOps, cloud-native architecture, microservices, APIs, and infrastructure-as-code
  • Strong understanding of AWS, Azure, GCP, Docker, and Kubernetes security
  • Experience with security automation, tooling integration, and shifting security left
  • Knowledge of NIST SSDF, OWASP SAMM, BSIMM, and ISO/IEC 27034
  • Understanding of SOC 2, ISO 27001, PCI DSS, GDPR, and CCPA compliance requirements
  • Ability to influence engineering teams without direct authority and build security champions programs
  • Strong communication skills for technical and non-technical audiences
  • Master’s degree in a related field
  • Experience leading product security through carve-outs, mergers, acquisitions, or multi-entity integrations
  • CSSLP, CEH, OSCP, GWAPT, AWS, Azure, or GCP security certification, or similar credential
  • Experience harmonizing security tools, processes, and practices across development organizations with different technology stacks and maturity levels
  • Ability to balance, prioritize, and roadmap security initiatives against business velocity and developer capacity
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
4,000 Employees
Year Founded: 2005

What We Do

Cielo Projects (operating as Velotic™) is a leading independent industrial software company providing data‑driven solutions that improve manufacturing efficiency, productivity, and operational insight. Serving customers across manufacturing, oil & gas, utilities, and infrastructure, the company leverages a portfolio anchored by Proficy, Kepware, and ThingWorx to support global industrial operators, with a primary focus on AI‑enabled manufacturing and industrial software.

Similar Jobs

SOPHiA GENETICS Logo SOPHiA GENETICS

Senior Program Leader (IVD/CDx) (Relocation to Switzerland)

Artificial Intelligence • Big Data • Healthtech • Software • Biotech
Remote or Hybrid
4 Locations
450 Employees

CrowdStrike Logo CrowdStrike

Product Marketing Manager

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
170K-260K Annually

CrowdStrike Logo CrowdStrike

Program Manager

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
120K-180K Annually

PwC Logo PwC

Strategy& Deals Tech Strategy AI & Tech Value Creation Director

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Hybrid
12 Locations
370000 Employees
155K-410K Annually

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account