Dragos, Inc. is a global leader in xOT cybersecurity, dedicated to protecting critical infrastructure systems. The Manager, Product Security Engineering will lead the product security team while also contributing as a hands-on security engineer, focusing on certification, accreditation, and vulnerability management efforts.
Responsibilities:
- Manage, mentor, and grow the product security engineering team, including the Principal Product Security Engineer and Staff Product Security Engineer, covering hiring, career development, and performance management
- Personally own and drive certification and accreditation initiatives, including DISA STIG hardening and authorization packages, SOC 2, ISO 27001, and other frameworks required by customers or regulators
- Give the Principal Product Security Engineer room to own technical strategy and PSIRT leadership, while you translate that strategy into an executable roadmap and hold the team accountable to it
- Remain hands-on: contribute directly to vulnerability remediation, SAST/DAST tooling, security assessments, or PSIRT response alongside the team, while trusting your ICs to own the majority of day-to-day vulnerability hunting and patching
- Prioritize and track the team's vulnerability hunting and patching work — including 0-days found in Dragos products, not just dependency CVEs — to keep it aligned with certification deadlines and customer commitments
- Coordinate with Compliance, Legal, and Sales Engineering to respond to customer security questionnaires, audits, and certification renewals
- Track and report on the team's certification posture, audit readiness, and vulnerability remediation SLAs to Engineering leadership
- Establish and maintain evidence collection processes so certifications and accreditations can be renewed and audited efficiently
- Foster a strong technical community by developing close relationships amongst Engineering Managers
Requirements:
- 5+ years of direct cybersecurity or product security experience
- 1-2+ years of experience managing or leading a team of security engineers, or demonstrated team-lead/player-coach experience
- Direct, hands-on experience obtaining or maintaining compliance certifications (SOC 2 Type II, ISO 27001, FedRAMP, or similar) and/or DISA STIG hardening and authorization processes
- Comfortable operating as a working manager, splitting time between people leadership and individual technical contribution
- Experience with SAST/DAST implementation and integrating security tooling into CI/CD pipelines
- Experience with security in cloud (AWS/Azure/GCP), on-premise, and virtualized environments
- Excellent communication and cross-functional collaboration skills; comfortable representing product security to Compliance, Legal, Sales, and customers
- Management experience with Agile and working in cross-functional Product Teams
- Knowledge of ICS/OT security is a plus