About this role
Come work at a place where innovation and teamwork come together to support the most exciting missions in the world!
Qualifications
Leadership & Executive Management
• 12+ years of progressive experience in cybersecurity, application security, product security, cloud security, or security architecture, including 7+ years in senior leadership roles managing globally distributed security, engineering, and architecture teams.
• Proven experience building, scaling, and leading high-performing Product Security organizations supporting large-scale SaaS, cloud-native, and enterprise software platforms.
• Demonstrated success leading directors, senior managers, architects, and security engineering teams across multiple geographies and product portfolios.
• Experience owning multi-million-dollar security budgets, strategic planning processes, headcount forecasting, vendor relationships, and security program execution.
• Strong executive presence with the ability to communicate technical risk, business impact, and security strategy to Boards of Directors, Executive Leadership Teams, auditors, regulators, and customer executives.
• Proven ability to influence security and product roadmaps across Engineering, Product Management, Cloud Operations, Legal, Compliance, Customer Success, Sales Engineering, and Corporate Security organizations.
• Experience participating in M&A due diligence, product security assessments, and post-acquisition security integration activities is highly desirable.
Product Security & Secure Engineering
• Deep expertise in product security, application security, cloud security, DevSecOps, software supply chain security, and secure software development lifecycle (SSDLC) practices.
• Demonstrated experience implementing and scaling:
• Security-by-design principles
• Threat modeling frameworks
• Secure coding standards
• Vulnerability management programs
• Red teaming exercises
• Bug bounty and responsible disclosure programs
• Software supply chain security controls
• SBOM management
• Secure CI/CD pipelines
• Container and Kubernetes security
• Extensive knowledge of modern authentication and identity architectures including:
• Zero Trust
• OAuth2
• OpenID Connect
• SAML
• PKI
• Hardware-backed cryptography
• Secrets management
• PAM solutions
• Deep understanding of modern security frameworks including:
• NIST Cybersecurity Framework
• NIST SP 800-53
• NIST SP 800-171
• NIST SP 800-218 (SSDF)
• CIS Controls
• OWASP Top 10
• OWASP ASVS
• SOC 2
• ISO 27001
Federal Compliance & Government Security Experience
FedRAMP
• 10+ years of experience supporting U.S. federal cybersecurity programs and regulatory frameworks.
• Proven experience leading, achieving, and sustaining multiple FedRAMP Moderate and FedRAMP High Authorizations to Operate (ATO) for cloud-native SaaS products.
• Extensive experience working directly with:
• Federal Agencies
• Joint Authorization Board (JAB) stakeholders
• Third Party Assessment Organizations (3PAOs)
• Authorizing Officials
• Government security assessors
• Deep knowledge of:
• NIST SP 800-53 Rev. 5
• FedRAMP Continuous Monitoring
• POA&M management
• Significant Change Requests
• Annual Assessments
• Vulnerability remediation requirements
• Configuration management controls
• Demonstrated ownership of security strategy and product architecture supporting regulated government cloud environments.
CMMC & DoD Cloud Requirements
• Hands-on experience implementing and managing environments aligned to:
• CMMC Level 2 requirements
• NIST SP 800-171
• DFARS 252.204-7012
• DFARS 252.204-7019
• DFARS 252.204-7020
• DFARS 252.204-7021
• Experience designing and securing solutions deployed within Department of Defense environments requiring Impact Level (IL) authorization.
• Demonstrated knowledge and practical experience supporting:
• DoD Impact Level 4 (IL4)
• DoD Impact Level 5 (IL5)
• DoD Impact Level 6 (IL6)
• Experience working with government customers handling Controlled Unclassified Information (CUI), National Security Systems (NSS), and classified or highly regulated workloads.
• Familiarity with DISA STIGs, SRGs, DoD Cloud Computing Security Requirements Guide (CC SRG), and associated authorization processes.
NIAP & Common Criteria
• Experience leading or supporting NIAP Common Criteria certification efforts for enterprise software, networking products, endpoint security solutions, or cybersecurity technologies.
• Strong understanding of:
• Common Criteria Evaluation and Validation Scheme (CCEVS)
• Protection Profiles
• Security Targets
• Evaluation Assurance Levels (EAL)
• NIAP product certification lifecycle
• Experience working with accredited testing laboratories and certification authorities to achieve and maintain product certifications.
Multi-Cloud Security & Hyperscaler Expertise
• 15+ years of experience designing and securing cloud-native SaaS platforms operating at enterprise scale.
• Demonstrated architecture and operational expertise across multiple hyperscale cloud service providers including:
Amazon Web Services (AWS)
• Experience securing AWS environments leveraging:
• Organizations
• IAM
• KMS
• CloudTrail
• GuardDuty
• Security Hub
• Control Tower
• ECS/EKS
• Native compliance controls
Microsoft Azure
• Experience securing Azure environments utilizing:
• Entra ID
• Azure Policy
• Defender for Cloud
• Key Vault
• Azure Monitor
• Microsoft Sentinel
• AKS
• Landing Zone architectures
Google Cloud Platform (GCP)
• Experience designing secure GCP architectures leveraging:
• Cloud IAM
• Security Command Center
• Cloud KMS
• Anthos
• Chronicle
• Organization Policies
• GKE security controls
Oracle Cloud Infrastructure (OCI)
• Experience securing OCI environments including:
• OCI IAM
• OCI Vault
• Cloud Guard
• Security Zones
• OCI Logging
• OCI Container Engine for Kubernetes (OKE)
• Experience developing governance models and security architectures across multi-cloud and hybrid-cloud environments.
• Demonstrated track record implementing consistent security controls, monitoring, identity governance, and compliance frameworks across AWS, Azure, GCP, and OCI.
Preferred Qualifications
• CISSP, CCSP, GIAC, SABSA, or equivalent advanced security certifications.
• Prior experience serving as:
• VP Product Security
• Head of Product Security
• Chief Product Security Officer
• Distinguished Security Architect
• Senior Security Executive within a cybersecurity or cloud technology company.
• Experience working in publicly traded technology organizations and interacting with Audit Committees and Board-level Cybersecurity Committees.
• Experience supporting enterprise cybersecurity products, vulnerability management platforms, endpoint security solutions, cloud security tools, SIEMs, or security operations technologies.
Qualys is an Equal Opportunity Employer, please see our EEO policy.