Vice President, Product Security

Posted Yesterday
Be an Early Applicant
3 Locations
Remote
Expert/Leader
Information Technology • Security • Cybersecurity
The Role
Leads the global Product Security organization and security strategy for large-scale SaaS and cloud platforms. Oversees secure engineering, application and cloud security, DevSecOps, vulnerability management, threat modeling, supply chain security, compliance, and multi-cloud architecture. Owns security budgets, roadmaps, executive communications, FedRAMP and DoD authorizations, CMMC alignment, NIAP Common Criteria certifications, and government security programs across AWS, Azure, GCP, and OCI.
Summary Generated by Built In

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!

Qualifications 

Leadership & Executive Management 

  • 12+ years of progressive experience in cybersecurity, application security, product security, cloud security, or security architecture, including 7+ years in senior leadership roles managing globally distributed security, engineering, and architecture teams. 

  • Proven experience building, scaling, and leading high-performing Product Security organizations supporting large-scale SaaS, cloud-native, and enterprise software platforms. 

  • Demonstrated success leading directors, senior managers, architects, and security engineering teams across multiple geographies and product portfolios. 

  • Experience owning multi-million-dollar security budgets, strategic planning processes, headcount forecasting, vendor relationships, and security program execution. 

  • Strong executive presence with the ability to communicate technical risk, business impact, and security strategy to Boards of Directors, Executive Leadership Teams, auditors, regulators, and customer executives. 

  • Proven ability to influence security and product roadmaps across Engineering, Product Management, Cloud Operations, Legal, Compliance, Customer Success, Sales Engineering, and Corporate Security organizations. 

  • Experience participating in M&A due diligence, product security assessments, and post-acquisition security integration activities is highly desirable. 

Product Security & Secure Engineering 

  • Deep expertise in product security, application security, cloud security, DevSecOps, software supply chain security, and secure software development lifecycle (SSDLC) practices. 

  • Demonstrated experience implementing and scaling: 

  • Security-by-design principles 

  • Threat modeling frameworks 

  • Secure coding standards 

  • Vulnerability management programs 

  • Red teaming exercises 

  • Bug bounty and responsible disclosure programs 

  • Software supply chain security controls 

  • SBOM management 

  • Secure CI/CD pipelines 

  • Container and Kubernetes security 

  • Extensive knowledge of modern authentication and identity architectures including: 

  • Zero Trust 

  • OAuth2 

  • OpenID Connect 

  • SAML 

  • PKI 

  • Hardware-backed cryptography 

  • Secrets management 

  • PAM solutions 

  • Deep understanding of modern security frameworks including: 

  • NIST Cybersecurity Framework 

  • NIST SP 800-53 

  • NIST SP 800-171 

  • NIST SP 800-218 (SSDF) 

  • CIS Controls 

  • OWASP Top 10 

  • OWASP ASVS 

  • SOC 2 

  • ISO 27001 

 

Federal Compliance & Government Security Experience 

FedRAMP 

  • 10+ years of experience supporting U.S. federal cybersecurity programs and regulatory frameworks. 

  • Proven experience leading, achieving, and sustaining multiple FedRAMP Moderate and FedRAMP High Authorizations to Operate (ATO) for cloud-native SaaS products. 

  • Extensive experience working directly with: 

  • Federal Agencies 

  • Joint Authorization Board (JAB) stakeholders 

  • Third Party Assessment Organizations (3PAOs) 

  • Authorizing Officials 

  • Government security assessors 

  • Deep knowledge of: 

  • NIST SP 800-53 Rev. 5 

  • FedRAMP Continuous Monitoring 

  • POA&M management 

  • Significant Change Requests 

  • Annual Assessments 

  • Vulnerability remediation requirements 

  • Configuration management controls 

  • Demonstrated ownership of security strategy and product architecture supporting regulated government cloud environments. 

CMMC & DoD Cloud Requirements 

  • Hands-on experience implementing and managing environments aligned to: 

  • CMMC Level 2 requirements 

  • NIST SP 800-171 

  • DFARS 252.204-7012 

  • DFARS 252.204-7019 

  • DFARS 252.204-7020 

  • DFARS 252.204-7021 

  • Experience designing and securing solutions deployed within Department of Defense environments requiring Impact Level (IL) authorization. 

  • Demonstrated knowledge and practical experience supporting: 

  • DoD Impact Level 4 (IL4) 

  • DoD Impact Level 5 (IL5) 

  • DoD Impact Level 6 (IL6) 

  • Experience working with government customers handling Controlled Unclassified Information (CUI), National Security Systems (NSS), and classified or highly regulated workloads. 

  • Familiarity with DISA STIGs, SRGs, DoD Cloud Computing Security Requirements Guide (CC SRG), and associated authorization processes. 

NIAP & Common Criteria 

  • Experience leading or supporting NIAP Common Criteria certification efforts for enterprise software, networking products, endpoint security solutions, or cybersecurity technologies. 

  • Strong understanding of: 

  • Common Criteria Evaluation and Validation Scheme (CCEVS) 

  • Protection Profiles 

  • Security Targets 

  • Evaluation Assurance Levels (EAL) 

  • NIAP product certification lifecycle 

  • Experience working with accredited testing laboratories and certification authorities to achieve and maintain product certifications. 

 

Multi-Cloud Security & Hyperscaler Expertise 

  • 15+ years of experience designing and securing cloud-native SaaS platforms operating at enterprise scale. 

  • Demonstrated architecture and operational expertise across multiple hyperscale cloud service providers including: 

Amazon Web Services (AWS) 

  • Experience securing AWS environments leveraging 

  • Organizations 

  • IAM 

  • KMS 

  • CloudTrail 

  • GuardDuty 

  • Security Hub 

  • Control Tower 

  • ECS/EKS 

  • Native compliance controls 

Microsoft Azure 

  • Experience securing Azure environments utilizing 

  • Entra ID 

  • Azure Policy 

  • Defender for Cloud 

  • Key Vault 

  • Azure Monitor 

  • Microsoft Sentinel 

  • AKS 

  • Landing Zone architectures 

Google Cloud Platform (GCP) 

  • Experience designing secure GCP architectures leveraging 

  • Cloud IAM 

  • Security Command Center 

  • Cloud KMS 

  • Anthos 

  • Chronicle 

  • Organization Policies 

  • GKE security controls 

Oracle Cloud Infrastructure (OCI) 

  • Experience securing OCI environments including: 

  • OCI IAM 

  • OCI Vault 

  • Cloud Guard 

  • Security Zones 

  • OCI Logging 

  • OCI Container Engine for Kubernetes (OKE) 

  • Experience developing governance models and security architectures across multi-cloud and hybrid-cloud environments. 

  • Demonstrated track record implementing consistent security controls, monitoring, identity governance, and compliance frameworks across AWS, Azure, GCP, and OCI. 

 

Preferred Qualifications 

  • CISSP, CCSP, GIAC, SABSA, or equivalent advanced security certifications. 

  • Prior experience serving as: 

  • VP Product Security 

  • Head of Product Security 

  • Chief Product Security Officer 

  • Distinguished Security Architect 

  • Senior Security Executive within a cybersecurity or cloud technology company. 

  • Experience working in publicly traded technology organizations and interacting with Audit Committees and Board-level Cybersecurity Committees. 

  • Experience supporting enterprise cybersecurity products, vulnerability management platforms, endpoint security solutions, cloud security tools, SIEMs, or security operations technologies. 

Qualys is an Equal Opportunity Employer, please see our EEO policy.

Skills Required

  • 12+ years of progressive experience in cybersecurity, application security, product security, cloud security, or security architecture
  • 7+ years in senior leadership roles managing globally distributed security, engineering, and architecture teams
  • Experience building, scaling, and leading Product Security organizations for large-scale SaaS, cloud-native, and enterprise software platforms
  • Experience leading directors, senior managers, architects, and security engineering teams across multiple geographies and product portfolios
  • Experience owning multi-million-dollar security budgets, strategic planning, headcount forecasting, vendor relationships, and security program execution
  • Executive communication experience with boards, executive leadership teams, auditors, regulators, and customer executives
  • Experience influencing security and product roadmaps across engineering, product, cloud operations, legal, compliance, customer success, sales engineering, and corporate security
  • Experience implementing product security, application security, cloud security, DevSecOps, software supply chain security, and SSDLC practices
  • Experience with security-by-design, threat modeling, secure coding, vulnerability management, red teaming, bug bounty, responsible disclosure, SBOMs, secure CI/CD, container security, and Kubernetes security
  • Knowledge of modern authentication and identity architectures, including Zero Trust, OAuth2, OpenID Connect, SAML, PKI, hardware-backed cryptography, secrets management, and PAM
  • Knowledge of NIST, CIS Controls, OWASP, SOC 2, and ISO 27001 security frameworks
  • 10+ years supporting U.S. federal cybersecurity programs and regulatory frameworks
  • Experience leading multiple FedRAMP Moderate and FedRAMP High Authorizations to Operate for cloud-native SaaS products
  • Experience working with federal agencies, JAB stakeholders, 3PAOs, authorizing officials, and government security assessors
  • Experience with FedRAMP continuous monitoring, POA&M management, significant change requests, annual assessments, vulnerability remediation, and configuration management controls
  • Experience implementing CMMC Level 2, NIST SP 800-171, DFARS requirements, and DoD Impact Level authorization environments
  • Experience supporting DoD Impact Levels 4, 5, and 6 and workloads involving CUI, NSS, classified, or highly regulated data
  • Knowledge of DISA STIGs, SRGs, DoD Cloud Computing Security Requirements Guide, and authorization processes
  • Experience leading or supporting NIAP Common Criteria certification for enterprise software, networking, endpoint security, or cybersecurity products
  • Understanding of CCEVS, Protection Profiles, Security Targets, EALs, and the NIAP certification lifecycle
  • 15+ years designing and securing cloud-native SaaS platforms at enterprise scale
  • Architecture and operational expertise across AWS, Azure, GCP, and OCI
  • Experience developing governance models and security architectures across multi-cloud and hybrid-cloud environments
  • CISSP, CCSP, GIAC, SABSA, or equivalent advanced security certification
  • Prior experience as VP Product Security, Head of Product Security, Chief Product Security Officer, Distinguished Security Architect, or senior security executive
  • Experience in publicly traded technology organizations and interaction with audit committees or board-level cybersecurity committees
  • Experience supporting enterprise cybersecurity products, vulnerability management platforms, endpoint security solutions, cloud security tools, SIEMs, or security operations technologies

Qualys Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Qualys and has not been reviewed or approved by Qualys.

  • Affordable Benefits Benefits costs are widely viewed as low for employees and dependents, with healthcare often described as almost fully paid for. Feedback suggests this affordability helps offset perceptions of lower base pay in some roles.
  • Healthcare Strength Healthcare offerings are broad, including multiple medical plan options, dental and vision coverage, mental health support, and disability insurance. Benefits are described as “pretty amazing” or “great,” reinforcing perceived quality and coverage depth.
  • Equity Value & Accessibility Equity participation is accessible through company stock plans and an employee stock purchase plan. Compensation packages commonly include equity alongside salary and bonus, which some consider a meaningful part of total rewards.

Qualys Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Foster City, CA
2,736 Employees
Year Founded: 1999

What We Do

Qualys, Inc. (NASDAQ: QLYS) is a pioneer and leading provider of disruptive cloud-based security, compliance and IT solutions with more than 10,000 subscription customers worldwide, including a majority of the Forbes Global 100 and Fortune 100. Qualys helps organizations streamline and automate their security and compliance solutions onto a single platform for greater agility, better business outcomes, and substantial cost savings. The Qualys Cloud Platform leverages a single agent to continuously deliver critical security intelligence while enabling enterprises to automate the full spectrum of vulnerability detection, compliance, and protection for IT systems, workloads and web applications across on premises, endpoints, servers, public and private clouds, containers, and mobile devices. Founded in 1999 as one of the first SaaS security companies, Qualys has strategic partnerships and seamlessly integrates its vulnerability management capabilities into security offerings from cloud service providers, including Amazon Web Services, the Google Cloud Platform and Microsoft Azure, along with a number of leading managed service providers and global consulting organizations. For more information, please visit http://www.qualys.com

Similar Jobs

Applied Systems Logo Applied Systems

Lead Product Manager

Artificial Intelligence • Cloud • Payments • Software • Business Intelligence • Generative AI • Automation
Remote or Hybrid
2 Locations
3116 Employees
135K-210K Annually

PwC Logo PwC

Consultant

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
64 Locations
370000 Employees
99K-232K Annually

PwC Logo PwC

CTIO -Activation & Customer Success - Experienced Associate

Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
Remote or Hybrid
62 Locations
370000 Employees
51K-140K Annually

Similar Companies Hiring

Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account