Director of Product Security Engineering

Remote

Applications have closed

ExtraHop Networks

ExtraHop provides cloud-native cybersecurity solutions to help enterprises detect and respond to advanced threats—before they compromise your business.

View company page

We are ExtraHop. We're on a mission to provide security teams with the intelligence they need to confront and stop advanced threats like supply chain attacks, zero day exploits, and ransomware attacks. Cyber attackers still have the advantage. We’re taking it back with creativity, intellectual curiosity, and a sense of humor. Are you ready to help us reclaim the upper hand?

We are ExtraHop. We’re on a mission to provide security teams with the intelligence they need to confront and stop advanced threats like supply chain attacks, zero day exploits, and ransomware attacks. Attackers still have the advantage. We’re taking it back with creativity, intellectual curiosity, and a sense of humor. Are you ready to help us reclaim the upper hand?

Do you like securing complex networks? Want to be a part of a collaborative team that builds solutions that protect some of the biggest networks in the world? ExtraHop is seeking a Director of Product Security Engineering experienced with driving product security, regulatory compliance, and working collaboratively with other R&D teams to continuously improve product security.

We are looking for a hands-on technical leader that is passionate about building world-class products securely. You will own and drive our security roadmap in alignment with R&D and business initiatives. You will work collaboratively across R&D to cultivate a culture of security awareness, advocate for security, mentor others, and influence leadership.

Duties & Responsibilities

  • Lead product security strategy and collaborate with the Engineering staff through all the phases of the Secure Development Lifecycle. Responsibilities include security architecture & design, threat modeling, secure code reviews, process improvements, security testing & automation, and exploit mitigation.
  • Lead product security incident and vulnerability response.
  • Educate customers and build trust in the security of the product
  • Lead product security operations, including monitoring, alerting, investigation, response, developing playbooks and workflows, and reporting on product security issues.
  • Oversee compliance, certifications, audits, and pentests
  • Manage a bug bounty program
  • Develop and deliver security training and awareness programs
  • Stay up-to-date on the latest security threats and vulnerabilities
  • Represent the company at security conferences and events
  • Build and maintain relationships with security vendors and partners

Required Skills & Experience

  • Extensive experience in multiple security domains including product security engineering, security operations, infrastructure security, incident response, and compliance. Strong preference for product security experience.
  • Experience with software development
  • Strong leader and coach with management experience.
  • Experience with managing  a diverse subset of security roles and skills.
  • You communicate security concepts effectively, both to management and individual contributors with a diverse set of backgrounds
  • You have strong prioritization skills, both in prioritizing security team efforts as well as helping other teams understand prioritization of performing security remediation and mitigation work.
  • Self-motivated and self-directed, well-organized and able to position controls in anticipation of threats
  • B.S. in Computer Science related, or equivalent experience

Desired Skills & Experience

  • Experience with product security for an enterprise software product
  • Experience with product security for cloud services including SaaS products
  • Experience with product security for firmware
  • Experience with compliance programs such as SOC2, HIPAA, or FedRAMP
  • Experience with building trust with customers around product security
  • Experience with incident and vulnerability response
  • Experience with security monitoring of cloud services or SaaS products
  • Software development experience in C, C++, Python, or Go

All R&D Employees will be required to attend 2 mandatory in-person events every year of approx. 4 days duration.

$194,000- $263,600 + benefits+ options




ABOUT EXTRAHOP 

Cyberattackers have the advantage. ExtraHop is on a mission to help you take it back with security that can’t be undermined, outsmarted, or compromised. Our dynamic cyber defense platform, Reveal(x) 360, helps organizations detect and respond to advanced threats––before they compromise business operations. We apply cloud-scale AI to petabytes of traffic per day, performing line-rate decryption and behavioral analysis across all infrastructure, workloads, and data-in-flight. With complete visibility from ExtraHop, enterprises can detect malicious behavior, hunt advanced threats, and forensically investigate any incident with confidence.

ExtraHop is recognized by leading organizations for both its innovation in the market and its commitment to building a world-class team. In 2020, we’ve already been named a “Best Place to Work” by Inc., Computerworld, BuiltIn Seattle and Seattle Business Magazine, and we’ve been named to Wealthfront’s Career-Launching Companies list for the last four years. Forbes named ExtraHop to its 2020 AI 50 List, as well as the list of “20 Best Cybersecurity Startups to Watch.” In 2019 and 2020, JMP Securities put ExtraHop on its Elite 80 List as one of the most strategically positioned private companies in the cybersecurity industry. SC Media has named ExtraHop an Industry Innovator for enterprise network detection and response for the past two years.

Benefits/perks listed below may vary depending on the nature of your employment with ExtraHop and the country where you work.

  • Health, dental, and vision benefits
  • Honor System PTO and 9 Holidays (US only) + 3 Days of Paid Volunteer Time 
  • Non-Commissioned positions are eligible to participate in annual discretionary bonus plan
  • FSA and Dependent Care Accounts + EAP where applicable
  • Educational Reimbursement 
  • 401k with employer match or Pension where applicable
  • Pet Insurance (US only)
  • Parental Leave (US Only)
  • Hybrid and Remote Work Model

*Candidates should note that the Company may modify reporting relationships, job titles and compensation, including commissions and benefits, from time to time at its sole discretion, as it deems necessary, with or without prior notice.

We are intentional about our culture, diversity, and inclusion, and we welcome everyone to come ready to participate in contributing to this truly unique environment. At ExtraHop, we believe that the best products, services, and companies are built by strong teams that include a diversity of backgrounds, perspectives, ideas, and experiences. We are committed to supporting and enabling growth and opportunity for every employee at every level. This is the foundation of our success. 

We are equally committed to equal employment opportunity, and it is foundational to how we recruit and hire our talented team. Employment is determined based upon capabilities and qualifications without discrimination on the basis of race, creed, color, religion, sex, gender identification and expression, marital status, military status or status as an honorably discharge/veteran, pregnancy (including potential pregnancy, pregnancy-related conditions, and childbearing), sexual orientation, age (40 and over), national origin, ancestry, citizenship or immigration status, physical, mental, or sensory disability , HIV/AIDS or hepatitis C status, genetic information, status as an actual or perceived victim of domestic violence, sexual assault, or stalking, or any other protected class as established by law.

Our people are our most important competitive advantage, leading the charge against nation-states, cyber criminals, and insider threats.

Ready to join us?   #Extrahop #Security #NDR #informationsecurity #cybersecurity #cloudsecurity #infosec #LI-Remote 

Tags: Audits Automation C Cloud Compliance Computer Science Cyber defense Exploit Exploits FedRAMP HIPAA Incident response Monitoring Product security Python R&D SaaS Security strategy SOC 2 Strategy Vulnerabilities

Perks/benefits: 401(k) matching Career development Competitive pay Conferences Health care Insurance Parental leave Salary bonus Team events

Regions: Remote/Anywhere North America
Country: United States
Job stats:  30  8  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.