SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
CodeRabbit is hiring a Senior Product Manager to own the security product—an AI-driven scanner that detects vulnerabilities across codebases and surfaces findings in pull request reviews. The role combines LLM-based vulnerability hunting with static analysis, secrets detection, infrastructure-as-code checks, and supply-chain analysis.
You will own the security product end-to-end: defining roadmap priorities across SAST, secrets detection, IaC, and dependency analysis; designing how findings are presented, triaged, and resolved; and establishing the precision and recall bar that customers trust. You'll treat every false positive as a trust problem, not a tuning detail, and turn detection-quality evidence into product decisions and customer-facing proof.
You'll also own the AppSec and CISO buyer persona alongside developers, partner with Sales on enterprise evaluations and competitive positioning, and shape pricing and packaging with Growth and Finance. Daily collaboration with engineers building the agentic scanning pipeline ensures detection priorities reflect both customer needs and market reality.
This is a high-ownership individual contributor role. The company is well-funded ($143M Series C, $1.5B valuation) and processes over 2 million code reviews weekly across 17,000+ customers and 150,000 open-source projects.
Required: 5–8 years in security (product management at a security vendor, or hands-on security work such as application security, penetration testing, vulnerability research, or detection engineering). You must have product management experience with deeply technical B2B SaaS or developer tools products, practical knowledge of real vulnerability classes and exploitation, familiarity with the security tooling landscape (SAST, DAST, secrets scanning, IaC, SCA), technical fluency to read code and engage engineers, strong writing and communication skills, comfort with ambiguity, and low-ego, high-ownership mindset.
Nice-to-have: hands-on security practitioner background (CVEs, bug bounties, CTFs, pentest findings), experience shipping LLM or agentic products, direct vendor-side experience in code security, or power-user knowledge of Git platforms.