At a Glance
- Tasks: Lead product development for security and compliance, integrating it into the software delivery lifecycle.
- Company: Join CloudBees, a top software delivery platform empowering enterprises to innovate and secure their software.
- Benefits: Enjoy fully remote work, competitive salary, and opportunities for professional growth.
- Why this job: Make a real impact in the DevSecOps landscape while collaborating with diverse teams in a dynamic environment.
- Qualifications: 5+ years in product management with expertise in cybersecurity and compliance frameworks.
- Other info: Ideal for tech-savvy individuals passionate about security and innovation.
The predicted salary is between 48000 - 72000 £ per year.
CloudBees provides the leading software delivery platform for enterprises, enabling them to continuously innovate, compete, and win in a world powered by the digital experience. Designed for the world's largest organisations with the most complex requirements, CloudBees enables software development organisations to deliver scalable, compliant, governed, and secure software from the code a developer writes to the people who use it.
This specific opening is for an exceptional candidate to work with our partners to build a compelling Security & compliance offering that is fully integrated into the SDLC, providing our customers the ability to build faster and stay secure by automating the control assurance activities revolving around the CI/CD workflows and providing evidence as a service. According to Gartner, by 2026, 70% of enterprises will have integrated compliance as code into their DevOps toolchains, reducing risk management and improving lead time by at least 15%. Hence this is a significant opportunity to drive a positive transformation across the DevSecOps landscape delivering value to our customers.
You will leverage your skills as a security and compliance expert, strategic thinker, data-driven decision-maker, and tactical execution master to drive the product towards further adoption and revenue growth.
What the Role Requires- Solid understanding of how developers and security teams use popular security scanners like Checkmarx, Snyk, Wiz, Tenable, Palo Alto Prisma (Twistlock), Black Duck (Synopsys) and more.
- Good understanding of AWS, Google, Microsoft Azure clouds.
- Demonstrated expertise in cybersecurity with a thorough understanding of the latest trends, solutions, and best practices in the industry e.g. Application Security Posture Management (ASPM), Continuous Cyber and IT controls monitoring (CCM).
- Thorough understanding of compliance frameworks like NIST and FedRAMP and the audit process around demonstrating compliance effectively.
- Practical experience of the System Development Life Cycle, Software Development Life Cycle, and Agile framework.
- Expertise in risk analysis, threat modeling, and vulnerability assessments.
- Experience in coordinating with diverse cross-functional teams, including software engineers, designers, and stakeholders to drive the necessary outcomes.
- Strong technical abilities and a track record of working through complex technical problems.
- Strong troubleshooting and problem-solving skills.
- Excellent communication skills, both written and verbal, to effectively convey complex technical concepts to non-technical stakeholders.
- Demonstrated understanding of the techniques and methods of modern product discovery, design and product delivery.
- 5+ years working on technology-powered products as a product manager.
- Demonstrated ability to learn multiple functional areas of business – engineering, design, finance, sales, or marketing.
- Proven ability to engage with engineers, designers, and company leaders in a constructive and collaborative relationship (especially in a remote environment).
- Proven ability to think with a platform mindset, considering not only direct customer value, but also indirect customer value, by enabling all other products to be more impactful when leveraging your capability.
- Proven ability to convert specific customer requirements into extensible and reusable platform capability.
- Practical experience of ISO27001/27004/27005 or NIST Risk Management Framework (RMF);
- Experience in security accreditation e.g. PCI-DSS, FedRAMP, SSDF (NIST SP800-218), FISMA/NIST SP800-53, ISO 27001, DORA.
- Cyber security certification e.g. Certified Information System Security Professional (CISSP), Cloud Certified Security Professional (CCSP).
- Own the “why” for your product. Understand and synthesise the corporate objectives, customer/user pains, industry trends, current customer/user behaviour, and anything else that can provide context to drive the product team’s decision-making.
- Partner with design, engineering, and documentation to deliver a product that achieves the desired business outcomes.
- Collaborate with and enable all internal stakeholders including: sales, marketing, customer support, finance, legal; and represent them when they’re not in the room.
- Partner with other product teams to drive corporate objectives.
- Communicate verbally and through writing with anyone and everyone interested in your product for whatever reason.
- Define product specs, user stories, mockups, and acceptance criteria in collaboration with your team of PMs, engineering or independently.
- Develop a deep understanding of the market landscape and identify key areas of competitive differentiation and market disruption.
- Contribute actively to the creation and refinement of CloudBees product's cybersecurity features, maintaining a deep understanding of emerging technologies and industry best practices.
- Conduct regular security analysis and threat assessments, identifying vulnerabilities and potential improvements in the product's security.
- Generation of technical marketing requirements documents and creation of product roadmaps.
- Collaborate closely with CloudBees cybersecurity team to develop comprehensive security measures and strategies for the product, ensuring alignment with organisational objectives.
Principal Product Manager - Security and Compliance employer: CloudBees
Contact Detail:
CloudBees Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Principal Product Manager - Security and Compliance
✨Tip Number 1
Familiarise yourself with the latest trends in security and compliance, especially those related to DevSecOps. Understanding frameworks like NIST and FedRAMP will give you an edge in discussions and demonstrate your commitment to the role.
✨Tip Number 2
Network with professionals in the cybersecurity field, particularly those who have experience with tools like Checkmarx and Snyk. Engaging in relevant online communities or attending webinars can help you gain insights and make valuable connections.
✨Tip Number 3
Prepare to discuss your experience with cross-functional teams. Highlight specific examples where you've successfully collaborated with engineers and designers to drive product outcomes, as this is crucial for the Principal Product Manager role.
✨Tip Number 4
Stay updated on the competitive landscape of software delivery platforms. Being able to articulate how CloudBees differentiates itself from competitors will show your strategic thinking and understanding of the market.
We think you need these skills to ace Principal Product Manager - Security and Compliance
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in product management, particularly in security and compliance. Use specific examples that demonstrate your understanding of the System Development Life Cycle and Agile frameworks.
Craft a Compelling Cover Letter: In your cover letter, express your passion for cybersecurity and compliance. Discuss how your skills align with the role's requirements and how you can contribute to CloudBees' mission of delivering secure software solutions.
Showcase Technical Expertise: Include details about your experience with security tools like Checkmarx, Snyk, and AWS. Highlight any certifications you hold, such as CISSP or CCSP, to reinforce your qualifications for the position.
Demonstrate Communication Skills: Since excellent communication is key for this role, ensure your application materials are well-written and free of errors. Use clear language to convey complex ideas, showcasing your ability to communicate effectively with both technical and non-technical stakeholders.
How to prepare for a job interview at CloudBees
✨Understand the Product Landscape
Before your interview, make sure you have a solid grasp of CloudBees' product offerings and how they integrate security and compliance into the software development lifecycle. Familiarise yourself with the latest trends in DevSecOps and be ready to discuss how these can impact product strategy.
✨Showcase Your Technical Knowledge
Be prepared to demonstrate your understanding of popular security scanners and compliance frameworks like NIST and FedRAMP. Highlight any practical experience you have with these tools and frameworks, as well as your ability to communicate complex technical concepts to non-technical stakeholders.
✨Emphasise Collaboration Skills
This role requires working closely with cross-functional teams. Share examples from your past experiences where you successfully collaborated with engineers, designers, and other stakeholders to achieve product goals, especially in a remote setting.
✨Prepare for Scenario-Based Questions
Expect questions that assess your problem-solving skills and ability to handle real-world challenges. Think of specific scenarios where you had to conduct risk analysis or threat assessments, and be ready to explain your thought process and the outcomes.