Skip to main content
Back to jobs

Product Security Lead

External
northwoodspace logoNorthwoodspace · Torrance, CA
$156K–$232K/yrFull-timeOn-site4d ago
Application SecurityCI/CDComplianceCross-functional CollaborationCryptographyDocumentation
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


Responsibilities

  • Application Security & SDLC
  • Own application security across the full software development lifecycle, ensuring security requirements are defined, validated, and enforced from design through production release.
  • Conduct security architecture reviews and threat modeling for new product features, platform changes, and third-party integrations.
  • Establish and maintain secure coding standards, security review gates, and developer security training programs.
  • Serve as the primary security liaison for product engineering teams, translating compliance and security requirements into actionable engineering guidance.
  • SAST, DAST & Vulnerability Management
  • Deploy, manage, and continuously improve static application security testing (SAST) and dynamic application security testing (DAST) tooling integrated into development workflows.
  • Own the vulnerability management program end-to-end: discovery, triage, prioritization, remediation tracking, and reporting across product and infrastructure systems.
  • Conduct and coordinate penetration testing against Northwood's products and infrastructure, including scoping, execution, findings management, and remediation validation.
  • Build and maintain container security scanning, dependency analysis, and software composition analysis (SCA) pipelines.
  • CI/CD Security & Secrets Management
  • Integrate automated security validation and policy enforcement into CI/CD pipelines, ensuring security controls do not impede engineering velocity.
  • Own secrets management infrastructure, including deployment, policy configuration, access controls, and audit logging for platforms such as HashiCorp Vault.
  • Implement and enforce controls for secure artifact management, signing, and supply chain integrity across build and deployment pipelines.
  • Review and harden Infrastructure as Code, GitOps workflows, and deployment automation for security misconfigurations and policy violations.
  • Cryptography & Secure Communications
  • Design and implement cryptographic controls for data at rest, data in transit, and satellite communication protocols, ensuring alignment with NIST standards and government customer requirements.
  • Evaluate and advise on cryptographic library selection, key management architecture, and certificate lifecycle management.
  • Identify and remediate cryptographic weaknesses across product systems, including legacy protocol usage, weak cipher configurations, and improper key handling.
  • Team Leadership & Cross-Functional Collaboration
  • Hire and develop product security engineers as the team scales.
  • Collaborate with network operations, mission management, and compliance teams to maintain a security posture that enables mission success without breaking deployment cycles.
  • Build security documentation, audit evidence, and reporting standards that satisfy FedRAMP, CMMC, and NIST 800-171 requirements.

Requirements

  • 5+ years in product security, application security, or a closely related security engineering discipline, with demonstrated technical leadership experience.
  • Deep expertise in SAST and DAST tooling, including tool selection, integration into CI/CD pipelines, and results-driven vulnerability remediation programs.
  • Hands-on experience conducting or coordinating penetration testing engagements, including scoping, execution, and remediation validation.
  • Strong applied cryptography knowledge, including symmetric and asymmetric encryption, PKI, key management, and secure protocol design.
  • Experience owning vulnerability management programs, including prioritization frameworks, SLA enforcement, and executive reporting.
  • Proficiency with secrets management platforms such as HashiCorp Vault, including policy design and access control architecture.
  • Experience securing CI/CD pipelines and GitOps workflows, including IaC security review and automated security

Benefits

Paid time off

Additional Information

ABOUT NORTHWOOD Northwood is deploying a global network of phased array ground stations that will fundamentally change how satellites communicate with Earth. These systems support real-time, high-throughput communications that commercial and government customers rely on for mission-critical operations. Role Overview As Product Security Lead, you will own the security of Northwood's software and systems from design through deployment. This is a senior technical leadership role for an engineer with deep expertise across the full product security lifecycle - from threat modeling and secure architecture review to penetration testing, vulnerability management, and the cryptographic foundations that protect mission-critical space communications. You will embed security into every stage of our software development lifecycle, build and mature our application security program, and ensure that the products Northwood delivers to government and commercial customers meet the most demanding security requirements in the industry. This role partners closely with product and infrastructure engineering teams and reports to the Head of Security.


Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at northwoodspace? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect