Easter Seals Jobs

Job Information

Bose Corporation Sr Manager, Product Security - R26994 in Atlanta, Georgia

You know the moment. It's the first notes of that song you love, the intro to your favorite movie, or simply the sound of someone you love saying "hello." It's in these moments that sound matters most.

At Bose, we believe sound is the most powerful force on earth. We've dedicated ourselves to improving it for nearly 60 years. And we're passionate down to our bones about making whatever you're listening to a little more magical.

The Information Technology team at Bose exists to deliver valuable and reliable business and technology solutions with an innovative, engaged, and collaborative team focused on contributing to our corporate vision.

Job Description

The Product Security manager will drive multi-disciplinary activities focused on supporting a secure product development lifecycle as part of Bose's broader vision to maintain a world-class secure product portfolio. Role responsibilities will be organized across three (3) primary focus areas: strategic design and thought leadership around the fundamentals of the Product Security program, optimization of product security engineering practices, and management of product security operations. This includes design, management of implementation and operations of people, processes, and technologies focused on embedding cybersecurity best practices into Bose products and services. Proactively managing oversight of functions for modeling, identification, and remediation of security issues in Bose software, hardware, and services. Ensure security and privacy of customer data for software services, device hardware, on-device software/firmware, and applications while serving as the strategic liaison between Product teams and Bose Legal.

Primary Responsibilities: Execute on product security strategies, roadmaps, and maturity with current and future business models Embeds product security practices into engineering lifecycles from early planning, through launch, and beyond Ensures product generations remain secure and reliable during full lifetimes, increasing lifetime value and decreasing friction of adoption Provide product security expertise and technical direction for product security initiatives defined by the business Oversee efforts to conduct product security risk assessments and risk response processes Provide guidance and support to product development teams throughout the product development lifecycle on a variety of security requirements Build strong partnerships with counterparts in Enterprise Security, Architecture and Engineering, Governance and Risk, business operations units, Legal, and with compliance stakeholders Manage development of portfolio security strategy and capability planning Manage product security architectural blueprint development to guide engineering Management of product security talent, culture development, change management, and incentive structures Platform trust, safety, compliance, and cross-product governance and reporting Secure product development to include risk assessments, threat modeling, architecture reviews, and security requirements development Oversee development security operations (DevSecOps), to include environment and code scanning Manage security validation and verification which includes internal and 3rd party product penetration testing Development of supply chain security analysis and strategy Security update planning with the Chief Information Security Officer (CISO) Oversee product line specific trust, safety and security, and privacy compliance Manage the organizational interface to the security researcher community, to include bug bounty management, exploit analysis and reverse engineering Oversee functional development and enhancement of the product vulnerability management program Oversee the design, build, and management of the product security components of the Security Operations Center and govern product security monitoring capabilities Oversee the design, build, and management of the P oduct Security Incident Response (PSIRT) function

Qualifications: Leadership experience managing a team of Security Engineers focused within Product Security Technical expert, with experience consulting other teams on product security best practices Demonstrated expertise in recruiting and managing a team of experienced engineers on complex projects Experience analyzing systems and identifying security problems, threat modeling, code auditing, data security and design, and security and privacy unified reviews (SPUR) Excellent leadership, communication (written and oral) and interpersonal skills Strong organizational skills and analytical and problem-solving skills Strong organizational skills to juggle multiple tasks within the constraints of timelines and budgets with business acumen Ability to work and thrive in a fast-paced environment, learn rapidly, and master diverse technologies and techniques Experience in technology strategy or consulting Proven success in contributing to a team-oriented environment Proven ability to work creatively and analytically in a problem-solving environment Minimum requirement for this U.S.-based position is the ability to work legally in the United States No visa sponsorship/support is available for this position, including for any type of U.S. permanent residency (green card) process

Other Preferred Qualifications: Bachelor's degree in Computer Science, Information Technology/Management, or related fields are a plus, but not required; practical experience is taken into consideration Experience with both automated (i.e., SAST, DAST) and manual secure code reviews (penetration...

Equal Opportunity Employer - minorities/females/veterans/individuals with disabilities/sexual orientation/gender identity

DirectEmployers