SlipstreamJobsFresh Startup & VC-Backed Jobs

Product Security Engineering Manager

Bugcrowd - Remote - Remote - posted 2026-04-09

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 176,000 - 242,000 / annual

Bugcrowd is seeking a Product Security Engineering Manager to lead strategy and execution of application security, platform security, and FedRAMP programs. You will manage and mentor a geographically distributed team of security engineers while driving secure-by-default system design and embedding security throughout the engineering organization. Key responsibilities include: • Lead, grow, and empower a high-performing team of product security engineers, fostering a culture of engineering excellence, psychological safety, and continuous learning. • Own and evolve the secure development lifecycle (SDLC), driving "shift-left" initiatives across architecture reviews, threat modeling, SAST/DAST, continuous end-to-end testing, and advanced fuzzing. • Design and launch a Security Foundations program focused on secure-by-default engineering. The goal is to systematically eradicate entire classes of vulnerabilities through paved roads and developer guardrails, not just find bugs. • Own the security roadmap and day-to-day operations of the FedRAMP program. • Drive sustained improvement and manage complex projects spanning multiple teams and business units. • Build strong partnerships with software engineering, DevOps, product management, and operations teams. Required qualifications: • 7+ years of cybersecurity experience, with focus on Product Security, Application Security, or Platform Security. • 2+ years directly managing and mentoring security engineers. • Deep, hands-on experience integrating security into modern CI/CD pipelines, with proficiency in threat modeling, architecture reviews, automated testing (SAST, DAST, SCA, Fuzzing), and SDLC program management. • Fluency in one or more modern programming languages (Python, Go, Ruby, Java) for code reviews, script automation, and security tooling. • Strong understanding of cloud-native architectures (AWS, GCP, Azure), containerization (Kubernetes, Docker), Linux, and Infrastructure as Code (Terraform). • Practical experience supporting compliance requirements such as FedRAMP (preferred), PCI, SOC2, ISO27001, NIST 800-53. Bonus experience includes managing bug bounty programs, building secure-by-default internal libraries, and working in fast-paced, high-growth security or SaaS companies.

Similar roles