SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 176,000 - 242,000 / annual
Bugcrowd is seeking a Product Security Engineering Manager to lead strategy and execution of application security, platform security, and FedRAMP programs. You will manage and mentor a geographically distributed team of security engineers while driving secure-by-default system design and embedding security throughout the engineering organization.
Key responsibilities include:
• Lead, grow, and empower a high-performing team of product security engineers, fostering a culture of engineering excellence, psychological safety, and continuous learning.
• Own and evolve the secure development lifecycle (SDLC), driving "shift-left" initiatives across architecture reviews, threat modeling, SAST/DAST, continuous end-to-end testing, and advanced fuzzing.
• Design and launch a Security Foundations program focused on secure-by-default engineering. The goal is to systematically eradicate entire classes of vulnerabilities through paved roads and developer guardrails, not just find bugs.
• Own the security roadmap and day-to-day operations of the FedRAMP program.
• Drive sustained improvement and manage complex projects spanning multiple teams and business units.
• Build strong partnerships with software engineering, DevOps, product management, and operations teams.
Required qualifications:
• 7+ years of cybersecurity experience, with focus on Product Security, Application Security, or Platform Security.
• 2+ years directly managing and mentoring security engineers.
• Deep, hands-on experience integrating security into modern CI/CD pipelines, with proficiency in threat modeling, architecture reviews, automated testing (SAST, DAST, SCA, Fuzzing), and SDLC program management.
• Fluency in one or more modern programming languages (Python, Go, Ruby, Java) for code reviews, script automation, and security tooling.
• Strong understanding of cloud-native architectures (AWS, GCP, Azure), containerization (Kubernetes, Docker), Linux, and Infrastructure as Code (Terraform).
• Practical experience supporting compliance requirements such as FedRAMP (preferred), PCI, SOC2, ISO27001, NIST 800-53.
Bonus experience includes managing bug bounty programs, building secure-by-default internal libraries, and working in fast-paced, high-growth security or SaaS companies.