Manager, Product Security Engineering
Generate a McCoy IQ challenge in 30 seconds.
See how candidates think and approach the work this role demands, before the phone screen. We'll build a video challenge from this posting, and you can edit or share it before it goes live.
Key details
Job Description
<div class="content-intro"><p><span class="TextRun SCXW107525881 BCX8" lang="EN-US" data-contrast="none"><span class="NormalTextRun SCXW107525881 BCX8">At Dragos, the mission is personal. The systems we protect deliver the water you drink, power your home, and keep the hospitals your community depends on running. Those critical infrastructure systems that power our civilization around the world are under attack every day by adversaries. When those systems fail, people are&nbsp;</span><span class="NormalTextRun SCXW107525881 BCX8">immediately</span><span class="NormalTextRun SCXW107525881 BCX8">&nbsp;at risk.&nbsp;</span><span class="NormalTextRun SCXW107525881 BCX8">We are the global leader in&nbsp;</span><span class="NormalTextRun SCXW107525881 BCX8">xOT</span><span class="NormalTextRun SCXW107525881 BCX8">&nbsp;cybersecurity, combining technology, threat intelligence, and expert services. The people here chose this work because they understand&nbsp;</span><span class="NormalTextRun SCXW107525881 BCX8">what is</span><span class="NormalTextRun SCXW107525881 BCX8">&nbsp;at stake</span><span class="NormalTextRun SCXW107525881 BCX8">. Here, you will find a remote-first mission-driven team across North America, Europe, the Middle East, and APAC built on authenticity, transparency, and trust. If safeguarding the systems that protect your family, friends, and community is the kind of work that matters to you, you are in the right place.</span></span><span class="EOP Selected SCXW107525881 BCX8" data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;201341983&quot;:0,&quot;335551550&quot;:1,&quot;335551620&quot;:1,&quot;335559685&quot;:0,&quot;335559737&quot;:0,&quot;335559738&quot;:120,&quot;335559739&quot;:160,&quot;335559740&quot;:360}">&nbsp;</span></p></div><p><strong><span data-contrast="auto">About the Role</span></strong><span data-contrast="auto">:</span><span data-ccp-props="{}"> <br></span>We are seeking a Manager, Product Security Engineering to lead our product security team, which includes the Principal Product Security Engineer, Staff Product Security Engineer, and other product security engineers, while remaining hands-on as a practicing security engineer yourself. This is a working-manager role: roughly half your time will be spent leading, mentoring, and growing your team, and half will be spent as an individual contributor driving certification, accreditation, and hardening efforts such as DISA STIGs, SOC 2, ISO 27001, and other compliance programs our customers and prospects depend on. Your ICs will carry the bulk of day-to-day vulnerability hunting and patching in Dragos products — including finding novel (0-day) issues, not just outdated dependencies — so you can focus on certifications, delivery, and team growth. You'll give the Principal Product Security Engineer latitude to drive technical strategy and PSIRT leadership, while you own people management, career growth, delivery, and cross-functional coordination with Compliance, Legal, and Sales Engineering for the team as a whole.</p>
<p><strong><span data-contrast="auto">Responsibilities</span></strong><span data-contrast="auto">:</span><span data-ccp-props="{}">&nbsp;</span></p>
<ul>
<li>Manage, mentor, and grow the product security engineering team, including the Principal Product Security Engineer and Staff Product Security Engineer, covering hiring, career development, and performance management</li>
<li>Personally own and drive certification and accreditation initiatives, including DISA STIG hardening and authorization packages, SOC 2, ISO 27001, and other frameworks required by customers or regulators</li>
<li>Give the Principal Product Security Engineer room to own technical strategy and PSIRT leadership, while you translate that strategy into an executable roadmap and hold the team accountable to it</li>
<li>Remain hands-on: contribute directly to vulnerability remediation, SAST/DAST tooling, security assessments, or PSIRT response alongside the team, while trusting your ICs to own the majority of day-to-day vulnerability hunting and patching</li>
<li>Prioritize and track the team's vulnerability hunting and patching work — including 0-days found in Dragos products, not just dependency CVEs — to keep it aligned with certification deadlines and customer commitments</li>
<li>Coordinate with Compliance, Legal, and Sales Engineering to respond to customer security questionnaires, audits, and certification renewals</li>
<li>Track and report on the team's certification posture, audit readiness, and vulnerability remediation SLAs to Engineering leadership</li>
<li>Establish and maintain evidence collection processes so certifications and accreditations can be renewed and audited efficiently</li>
<li>Foster a strong technical community by developing close relationships amongst Engineering Managers</li>
</ul>
<p><strong><span data-contrast="auto">Qualifications</span></strong><span data-contrast="auto">:</span><span data-ccp-props="{}">&nbsp;</span></p>
<ul>
<li>5+ years of direct cybersecurity or product security experience</li>
<li>1-2+ years of experience managing or leading a team of security engineers, or demonstrated team-lead/player-coach experience</li>
<li>Direct, hands-on experience obtaining or maintaining compliance certifications (SOC 2 Type II, ISO 27001, FedRAMP, or similar) and/or DISA STIG hardening and authorization processes</li>
<li>Comfortable operating as a working manager, splitting time between people leadership and individual technical contribution</li>
<li>Experience with SAST/DAST implementation and integrating security tooling into CI/CD pipelines</li>
<li>Experience with security in cloud (AWS/Azure/GCP), on-premise, and virtualized environments</li>
<li>Excellent communication and cross-functional collaboration skills; comfortable representing product security to Compliance, Legal, Sales, and customers</li>
<li>Management experience with Agile and working in cross-functional Product Teams</li>
<li>Knowledge of ICS/OT security is a plus</li>
</ul>
<p><strong><span data-contrast="auto">Compensation</span></strong><span data-contrast="auto">:</span><span data-ccp-props="{}">&nbsp;</span></p>
<ul>
<li data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1"><span data-contrast="none">Salary: $220,000</span></li>
<li data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1">Competitive Equity Package</li>
<li data-leveltext="" data-font="Symbol" data-listid="3" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559683&quot;:0,&quot;335559684&quot;:-2,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;hybridMultilevel&quot;}" data-aria-posinset="1" data-aria-level="1">Comprehensive Benefits Plan<span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:0,&quot;335559739&quot;:0}">&nbsp;</span></li>
</ul>
<p><span data-ccp-props="{}">&nbsp;</span></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p><span data-ccp-props="{}"><span data-contrast="none">#LI-NH1 #LI-REMOTE</span><span data-ccp-props="{&quot;134233117&quot;:false,&quot;134233118&quot;:false,&quot;335551550&quot;:0,&quot;335551620&quot;:0,&quot;335557856&quot;:16777215,&quot;335559738&quot;:240,&quot;335559739&quot;:240}">&nbsp;</span></span></p>
<p>&nbsp;</p><div class="content-conclusion"><p>Dragos is an Equal Opportunity Employer and considers applicants for employment without regard to race, color, religion, sex, orientation, national origin, age, disability, genetics, or any other basis forbidden under federal, state, or local laws. All new hires must pass a background check as a condition of employment.</p></div>
Audit details(provenance, verification trail, raw fields)
Core fields
dragos:5368582008Provenance
dragosVerification trail
This posting hasn't been probed by our closure verifier yet. Stream C runs on a rolling schedule against postings approaching the close-decision threshold.
See how we measure for definitions, or our corrections log for known issues. Found something wrong? Flag a correction.
