Jobs

Senior Manager, Product Security

Strength in Trust  

At OneTrust, we exist to unlock every company's potential to thrive by doing what's good for people and planet. Using cutting-edge technology and a real-world approach to privacy, GRC, ethics, and ESG, we’ve created a no-nonsense platform to help supercharge the global push for Trust Intelligence. 

The Challenge

We are seeking an experienced Senior Manager to join our growing product security team. In this role, you will be responsible for overseeing the company's application security program, including penetration testing, vulnerability management, and secure coding practices. The Senior Manager will work closely with cross-functional teams, including IT, Development, and Operations, to ensure that the company's applications and systems are protected from security threats and vulnerabilities. The successful candidate will have a deep understanding of container security and experience implementing security measures in a continuous integration and continuous deployment (CICD) environment. This is a critical role responsible for ensuring the security and integrity of our company's applications and systems. 

Your Mission

  • Develop and maintain the company's application security program, including policies, procedures, and standards. 
  • Conduct penetration testing and vulnerability assessments to identify security gaps and areas for improvement. 
  • Provide guidance to development teams on secure coding practices and review code for potential security vulnerabilities. 
  • Collaborate with cross-functional teams to ensure that security is integrated into the application development process.
  • Monitor and track security vulnerabilities and work with development teams to remediate identified issues.
  • Maintain relationships with external security vendors, consultants, and other stakeholders to stay current with emerging security threats and technologies.
  • Develop and deliver security training and awareness programs to increase security awareness across the organization.
  • Manage a team of application security professionals and provide coaching and guidance as needed.
  • Develop security standards and guidelines to ensure the secure design and development of applications.
  • Stay up to date with emerging security threats and technologies and advise on appropriate mitigation strategies. 
  • Evaluate and implement security controls for CICD pipelines.
  • Conduct security assessments of applications and infrastructure.
  • Develop and maintain security documentation, including standards and procedures.
  • Collaborate with development teams to integrate security into the software development life cycle.
  • Lead the design and implementation of secure container-based infrastructure.
  • Stay current on industry best practices and emerging threats in container security.
  • Provide specialized assistance to internal incidents team to effectively respond to application related security incidents.
  • Mentor members of the security team. 

You Are

The Senior Manager of Application Security, Penetration Testing, and Vulnerability Management plays a critical role in ensuring the security of the company's applications and systems. The ideal candidate will have a strong technical background in application security, with experience in penetration testing, vulnerability management, and secure coding practices. The candidate must be able to work collaboratively with cross-functional teams and provide expert guidance on security-related issues. If you are a highly skilled and motivated individual with a passion for application security, we encourage you to apply for this exciting opportunity. 

Your Experience Includes

  • Bachelor's degree in Computer Science, Information Systems, or related field 
  • 7+ years of experience in application security, penetration testing, vulnerability management, or related field 
  • Strong understanding of application security principles, technologies, and best practices 
  • Experience with security testing tools, such as Burp Suite, Metasploit, and Nessus 
  • Knowledge of software development lifecycle (SDLC) methodologies and agile development practices
  • Industry certifications, such as CISSP, CISM, or CEH, are preferred but not required
  • Experience working with security tools such as Burp Suite, Nessus, and Qualys.
  • Strong understanding of containerization technologies such as Docker, Kubernetes.
  • Knowledge of programming languages such as Java, Python.
  • Experience with CICD tools such as Jenkins, Azure DevOps and CircleCI.
  • Knowledge of security concepts such as network security, access controls, encryption, and vulnerability management.
  • Strong understanding of web application security concepts, OWASP Top 10, and security standards such as PCI-DSS and ISO 27001.
  • Working knowledge of Web Application Firewall (WAF).

Our Commitment to You

When you join OneTrust you are stepping onto a launching pad — the countdown has begun. The destination? A career without boundaries working alongside a diverse and inclusive crew who is passionate about doing meaningful work. As a pioneer, your voice and expertise will help chart the direction of an entirely new industry — Trust. Our commitment to putting people first starts with you. Your growth is part of the mission. Our goal is to give you the power to embark on the next phase of your uniquely, unique career.

OneTrust provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

For California, Colorado, Connecticut, Nevada, New York, Rhode Island, and Washington-based candidates: the annual base pay range for this role is listed below. Within this range, individual pay is determined by several factors, including location, job-related skills, work experience, and relevant education and/or training. This role may also be eligible for discretionary bonuses, equity, and/or commissions, as well as benefits.

Salary Range$124,150—$165,550 USD

Resources  

Check out the following to learn more about OneTrust and its people: 

  • OneTrust Careers on YouTube
  • Your Ultimate Guide to Careers at OneTrust
  • @LifeatOneTrust on Instagram

Cyber Security Jobs by Category

Cyber Security Salaries