Senior Director of Product Security
OneTrust is the trust intelligence cloud platform organizations use to transform trust from an abstract concept into a measurable competitive advantage. Organizations globally use OneTrust to enable the responsible use of data while protecting the privacy rights of individuals, implement and report on their cyber security program, make their social impact goals a reality, and create a speak up culture of trust. Over 14,000 customers use OneTrust's technology, including half of the Global 2,000. OneTrust currently ranks #24 on the Forbes Cloud 100 list of top private cloud companies in the world and employs over 2,000 people in regions across North America, South America, Asia, Europe, and Australia.
The ChallengeWe are seeking an experienced Senior Director to join our growing product security team. In this role, you will be responsible for overseeing the company's application security program, including penetration testing, vulnerability management, and secure coding practices. The Senior Director will work closely with cross-functional teams, including IT, Development, and Operations, to ensure that the company's applications and systems are protected from security threats and vulnerabilities. This individual will develop and implement comprehensive strategies to protect the integrity and confidentiality of the organization's applications and data, ensuring the highest standards of security are maintained. The successful candidate will have a deep understanding of container security and experience implementing security measures in a continuous integration and continuous deployment (CICD) environment. This is a critical role responsible for ensuring the security and integrity of our company's applications and systems.
Your Responsibilities Include- Develop and maintain the company's application security program, including policies, procedures, and standards.
- Provide guidance to development teams on secure coding practices and review code for potential security vulnerabilities.
- Ensure compliance with relevant industry standards, regulations, and best practices related to application security and vulnerability management.
- Stay informed about emerging threats and trends in application security, adjusting strategies and controls accordingly.
- Develop security standards and guidelines to ensure the secure design and development of applications.
- Collaborate with cross-functional teams to ensure that security is integrated into the application development process.
- Monitor and track security vulnerabilities and work with development teams to remediate identified issues.
- Maintain relationships with external security vendors, consultants, and other stakeholders to stay current with emerging security threats and technologies.
- Manage a team of application security professionals and provide coaching and guidance as needed.
- Evaluate and implement security controls for CICD pipelines.
- Conduct security assessments of applications and infrastructure.
- Manage relationships with external vendors providing application security services.
- Establish and monitor key performance indicators (KPIs) to measure the effectiveness of the application security program.
- Develop and maintain security documentation, including standards and procedures.
- Collaborate with development teams to integrate security into the software development life cycle.
- Lead the design and implementation of secure container-based infrastructure.
- Develop and maintain an incident response plan specific to application security incidents.
- Lead the response to and resolution of application security incidents, ensuring a rapid and effective containment.
- Provide specialized assistance to internal incidents team to effectively respond to application related security incidents.
- Develop and deliver security training and awareness programs to increase security awareness across the organization.
- Evaluate and select security tools and technologies to enhance the application security program.
- Prepare and present regular reports to executive leadership on the state of application security.
- Bachelor's degree in Computer Science, Information Systems, or related field
- 7+ years of experience in application security, penetration testing, vulnerability management, or related field
- Strong understanding of application security principles, technologies, and best practices
- Experience with security testing tools, such as Burp Suite, Metasploit, and Nessus
- Knowledge of software development lifecycle (SDLC) methodologies and agile development practices
- Excellent communication and collaboration skills, with the ability to work effectively with cross-functional teams
- Industry certifications, such as CISSP, CISM, or CEH, are preferred but not required
- Experience working with security tools such as Burp Suite, Nessus, and Qualys.
- Strong understanding of containerization technologies such as Docker, Kubernetes.
- Knowledge of programming languages such as Java, Python.
- Experience with CICD tools such as Jenkins, Azure DevOps and CircleCI.
- Knowledge of security concepts such as network security, access controls, encryption, and vulnerability management.
- Strong understanding of web application security concepts, OWASP Top 10, and security standards such as PCI-DSS and ISO 27001.
- Working knowledge of Web Application Firewall (WAF).
- Strong interpersonal and communication skills, with the ability to explain technical security concepts to non-technical stakeholders.
- Self-motivated, with the ability to work independently and as part of a team.
For California, Colorado, Connecticut, Nevada, New York, Rhode Island, and Washington-based candidates: the annual base pay range for this role is listed below. Within this range, individual pay is determined by several factors, including location, job-related skills, work experience, and relevant education and/or training. This role may also be eligible for discretionary bonuses, equity, and/or commissions, as well as benefits.
Salary Range$225,500—$338,225 USDBenefitsAs an employee at OneTrust, you will be part of the OneTeam. That means you’ll receive support physically, mentally, and emotionally so that you can do your best work both in and out of the office. This includes comprehensive healthcare coverage, remote or hybrid workplace flexibility, flexible PTO, equity stock options, annual performance bonus opportunities, retirement account support, 14+ weeks of paid parental leave, career development opportunities, company-paid privacy certification exam fees, and much more. Specific benefits differ by country. For more information, talk to your recruiter or visit onetrust.com/careers.
ResourcesCheck out the following to learn more about OneTrust and its people:
- OneTrust Careers on YouTube
- @LifeatOneTrust on Instagram
You have the right to have your personal data updated or removed. You also have the right to have a copy of the information OneTrust holds about you. Further details about these rights are available on the website in our Privacy Overview. You can change your mind at any time and have your personal data removed from our database. In order to do this you must contact us and let us know you wish to be removed. The request should be made on the Data Subject Request Form.
Our Commitment to YouWhen you join OneTrust you are stepping onto a launching pad — the countdown has begun. The destination? A career without boundaries working alongside a diverse and inclusive crew who is passionate about doing meaningful work. As a pioneer, your voice and expertise will help chart the direction of an entirely new industry — Trust. Our commitment to putting people first starts with you. Your growth is part of the mission. Our goal is to give you the power to embark on the next phase of your uniquely, unique career
OneTrust provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by local laws.