Unlock Full Resume Report

New offer - be the first one to apply!

September 16, 2026

Senior Director, Security Engineering (PSIRT)

Senior • Remote

159,300 - 273,200 USD/yr

Plymouth, MN

Quick Facts

  • Role: Senior Director, Security Engineering (PSIRT)

  • Focus: Product security incident response across the SDLC

Description

Lead the enterprise response to product-related cybersecurity incidents across the software development lifecycle. Build and operationalize a PSIRT team that proactively detects, investigates, and mitigates threats to product integrity, supply chain security, and customer trust.

Responsibilities

  • Lead incident response for product security events such as codebase compromise, supply chain vulnerabilities (e.g., NPM, GitHub), and third-party dependency risks

  • Oversee the incident management lifecycle: detection, triage, containment, eradication, recovery, and post-incident review

  • Define PSIRT strategy (“North Star”) and roadmap with quarterly milestones tied to business outcomes

  • Develop and maintain incident response playbooks, escalation protocols, and tooling strategies for product environments

  • Integrate threat intelligence into product pipelines to proactively identify risks

  • Collaborate with engineering to embed security controls (secrets scanning, firewall rules, build runner protections) into CI/CD workflows

  • Partner with Product Management, Engineering, Legal, and Cloud Infrastructure to coordinate response and remediation

  • Provide executive-level briefings on incident status, impact, and remediation

  • Maintain documentation for audit, compliance, and continuous improvement

  • Build and lead a multidisciplinary team; foster operational excellence, continuous learning, and proactive risk management

Benefits

  • Comprehensive benefits package

  • Incentive and recognition programs

  • Equity stock purchase

  • 401k contribution (eligibility requirements apply)

  • Salary range: $159,300 to $273,200 annually (based on factors including local labor markets, education, work experience, and certifications)

Requirements

  • 10+ years combined Software and Security engineering experience across the full SDLC at scale

  • 10+ years threat modeling and deep-dive code reviews across diverse stacks (cloud-native/Kubernetes, embedded systems, or SaaS)

  • 10+ years implementing and maturing secure development lifecycles (SDL) with automated SBOM generation and SCA scanning in CI/CD pipelines

  • 5+ years managing high-stakes security incidents specifically in product security/PSIRT

  • 5+ years overseeing the full lifecycle of CVE assignments from researcher report through coordinated disclosure and patch verification

Similar jobs you might like