Key Responsibilities:
Leadership and Strategy
- Lead and manage a team of product security professionals, providing mentorship, guidance, and support.
- Develop and execute a comprehensive product security strategy aligned with organizational goals.
- Foster a culture of continuous learning, collaboration, and a security-first mindset across the organization.
Collaboration and Integration
- Engage and collaborate with leaders and teams across infrastructure, engineering, operations, product development, and legal to integrate trust and security principles throughout the product lifecycle.
- Work closely with product managers, engineers, and architects to embed security into the product lifecycle.
- Collaborate with customer-facing teams to address security concerns and build customer trust.
Security Management
- Define and enforce security policies, standards, and best practices.
- Conduct security assessments, threat modeling, and risk analyses for new and existing products and operational technologies, identifying vulnerabilities in both software and hardware.
- Champion secure coding practices, vulnerability management, and secure design principles.
- Oversee security reviews, code analysis, and penetration testing.
- Lead incident response efforts related to product security incidents and collaborate with legal, compliance, and communication teams as needed.
Metrics and Compliance
- Deliver and improve Product Security KPIs to reflect the security, privacy, availability, and recoverability posture across Altice products and services.
- Ensure compliance with industry regulations and standards, including relevant data protection and privacy regulations such as GDPR and CCPA.
Qualifications:
- Bachelor’s degree in Technology, Engineering, or a related field; or 15 years of experience in software and hardware product development with increasing leadership responsibilities. Master’s degree preferred.
- Minimum of ten years in a leadership role with proven experience managing technical teams in a Dev/Sec/Ops environment.
- In-depth knowledge of security frameworks, standards, and best practices (e.g., ISO 27001, NIST CSF, OWASP Top Ten, SDL, DevSecOps).
- Strong understanding of hybrid cloud infrastructure, web application security, network security, encryption, authentication, and access control mechanisms.
- Familiarity with data protection and privacy regulations (e.g., GDPR, CCPA) and their implications for SaaS products.
- Exceptional customer communication, leadership, and interpersonal skills, with the ability to make informed decisions under pressure and effectively manage crisis situations.
- Demonstrated ability to drive process improvements and optimize operational efficiency.
- Strong project management skills and the ability to oversee multiple initiatives concurrently.