Responsibilities
- Provide extended on-call support during critical security incidents to address urgent product vulnerabilities.
- Exercise technical and operational leadership during high-pressure events by establishing clarity and guiding decisive actions.
- Coordinate with incident leads, security leadership, engineering units, and customer-facing groups to ensure clear ownership and workflow alignment.
- Accelerate response timelines by managing coordinated fixes across multiple product versions, weighing risk against implementation practicality.
- Utilize knowledge of software development lifecycles and cross-functional partnerships to advance patches through release stages efficiently.
- Ensure remediation measures are fully implemented and validated prior to public release.
- Manage the end-to-end CVE disclosure process, including CVE identification, severity scoring, advisory drafting, and release scheduling.
- Work with external security researchers, vendors, and partners to synchronize disclosure timelines and communication strategies.
- Review third-party advisories, researcher publications, and joint disclosures for technical precision before public release.
- Serve as technical representative for the incident response team in multi-party coordination and external researcher interactions.
- Lead post-incident reviews and ensure identified issues are resolved through actionable follow-up measures.
- Engage in retrospective analyses after major incidents to convert insights into process and system enhancements.
- Support teams monitoring recurring security risk patterns across product lines.
- Inform improvements in the software development lifecycle by integrating lessons from past incidents into secure coding and design practices.
Compensation
Competitive salary and benefits package commensurate with experience
Work Arrangement
Hybrid work model with flexibility based on role and location
Team
Part of a global product security team focused on rapid incident response and long-term resilience
Responsibilities
- Provide extended on-call support during critical security incidents to address urgent product vulnerabilities.
- Exercise technical and operational leadership during high-pressure events by establishing clarity and guiding decisive actions.
- Coordinate with incident leads, security leadership, engineering units, and customer-facing groups to ensure clear ownership and workflow alignment.
- Accelerate response timelines by managing coordinated fixes across multiple product versions, weighing risk against implementation practicality.
- Utilize knowledge of software development lifecycles and cross-functional partnerships to advance patches through release stages efficiently.
- Ensure remediation measures are fully implemented and validated prior to public release.
- Manage the end-to-end CVE disclosure process, including CVE identification, severity scoring, advisory drafting, and release scheduling.
- Work with external security researchers, vendors, and partners to synchronize disclosure timelines and communication strategies.
- Review third-party advisories, researcher publications, and joint disclosures for technical precision before public release.
- Serve as technical representative for the incident response team in multi-party coordination and external researcher interactions.
- Lead post-incident reviews and ensure identified issues are resolved through actionable follow-up measures.
- Engage in retrospective analyses after major incidents to convert insights into process and system enhancements.
- Support teams monitoring recurring security risk patterns across product lines.
- Inform improvements in the software development lifecycle by integrating lessons from past incidents into secure coding and design practices.
Available for qualified candidates where permitted by policy and regulation