Product Security Lead
Madison-Davis, LLC · New York City Metropolitan Area
Apply & track with Apply EdgeA global financial institution is seeking a hands-on Product Security Lead to embed security throughout application and data lifecycles. The role works closely with software engineering, platform, and data teams to strengthen secure development, automate security controls, assess application designs, and identify risk earlier in the delivery process.This person will operate across application security, DevSecOps, cloud security, data security, and emerging AI-security initiatives. The position requires someone who can remain technically involved while helping engineering teams adopt stronger security practices.ResponsibilitiesEmbed security into application and data-development lifecycles.Advance secure-development and DevSecOps practices.Integrate automated security testing and policy controls into CI/CD pipelines.Conduct threat modeling and application-design risk assessments.Deliver and improve SAST, DAST, and software composition analysis capabilities.Validate and prioritize security findings while reducing false positives.Address open-source and third-party dependency risk.Support security across cloud and data environments.Guide security practices for emerging AI-enabled applications.Partner with engineering, platform, and data teams to strengthen security ownership.Role RequirementsExtensive experience in product, application, or software-security engineering.Financial-services experience.Strong Secure SDLC and DevSecOps expertise.Hands-on threat-modeling and design-risk-assessment experience.SAST, DAST, and software composition analysis experience.Strong data-security knowledge.Hands-on cloud-security experience across IaaS, PaaS, and SaaS.Practical knowledge of emerging AI-security risks and controls.Strong communication, stakeholder-management, and influencing skills.Ability to meet the required New York City hybrid schedule.How We WorkSecurity partners directly with engineering, platform, and data teams.Security controls are expected to be integrated into the development lifecycle.The role balances hands-on technical involvement with security-practice leadership.The position follows a hybrid New York City schedule.