Crunchyroll

Director, Product Security

Crunchyroll$249K — $305K *
Media
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years of progressive experience in information security or software engineering, particularly with enterprise-scale initiatives.
  • Demonstrated Principal-level technical leadership through influence and implementation of secure systems.
  • Strong understanding of application security fundamentals, including authentication, secure API design, and data protection.
  • Proficiency in risk management, with an emphasis on setting practical guardrails for teams.
  • Experience in cloud and platform security, including IAM, secrets management, and logging concepts.
  • Familiarity with DevSecOps principles and integrating security tools into CI/CD pipelines.
  • Exceptional communication skills, capable of technical coaching and providing executive-ready guidance.

Responsibilities

  • Drive security controls adoption through clear playbooks and secure platform capabilities.
  • Facilitate vulnerability management processes, ensuring accountability and timely remediation.
  • Integrate security tooling within CI/CD processes to automate compliance evidence production.
  • Embed security considerations into engineering design workflows using approved patterns.
  • Manage pragmatic risk requirements, guiding teams on alternatives that maintain project momentum.
  • Lead cross-team alignment efforts to address architectural risks and ensure stakeholder engagement.
  • Enhance incident preparedness with actionable runbooks and post-incident improvements.

Benefits

  • Flexible time off policies to support work-life balance.
  • Generous medical, dental, vision, and life insurance options.
  • 401(k) plan with employer matching contribution.
  • Support programs for new parents, indicating a family-friendly work environment.
  • Pet insurance and pet-friendly office spaces to foster a welcoming culture.
Full Job Description
About the role

Crunchyroll is growing and evolving, creating both new opportunities and new challenges as it protects millions of anime fans worldwide while still shipping quickly and with high quality. We are looking for a security leader who wants to shape how engineering builds and operates securely at scale. In this Principal-level, hands-on Director role reporting to the VP of Information Security, you will connect strategy to execution by turning security goals into secure-by-default, compliant systems and practices that teams actually use. You will partner closely with engineering leaders and senior ICs to reduce friction, align on priorities, and drive consistent follow-through, protecting our fans and our platform without sacrificing delivery velocity. Success will be through influence and enablement, and you will also periodically build practical solutions, such as reference implementations and tooling integrations, that make it easier for teams to adopt the right security patterns.
Core Areas of Responsibility

In this role, you will be a force multiplier for engineering, setting the direction, building key parts, and ensuring follow-through so security becomes a durable part of how Crunchyroll ships. You will own the engineering-facing mechanisms that make security real in day-to-day delivery:
  • Security execution at scale: Drive adoption of security controls across engineering by driving adoption of clear engineering playbooks, paved paths, and secure-by-default platform capabilities that can be consistently adopted across services, regardless of engineering domain. Engineering teams remain accountable for design, implementation, operation, and remediation of their services. This role provides security strategy, guidance, tooling, visibility, coordination, and escalation mechanisms that enable teams to meet those obligations consistently at scale
  • Vulnerability closure and systemic risk reduction: Facilitate the operating rhythm across engineering for vulnerability intake, triage, tracking of vulnerability ownership, SLAs, remediation planning, verification, and escalation. Establish systems and processes that ensure timely fixes and eliminate repeat issues through improvements.
  • Tooling integration and evidence readiness: Coordinate with engineering teams to integrate enterprise security tooling into CI/CD and production environments, and ensure engineering can reliably produce evidence of compliance in a low-friction, automated way.
  • Design-time security embedded in engineering workflows: Ensure threat modeling and security architecture considerations are built into how engineering designs and ships using approved patterns and reference architectures as the default starting point.
  • Pragmatic requirements shaping: When requirements are infeasible or disproportionately costly, you'll drive early escalation and propose alternatives (sequencing, compensating controls, platform changes) so we maintain momentum without accepting unmanaged risk.
  • Cross-team alignment and escalation: Identify cross-domain architectural risks and drive alignment / decision-making through established engineering leadership and architecture governance processes, bringing the right stakeholders together and escalating when tradeoffs require executive judgment.
  • Incident readiness and closure: Improve security incident preparedness in engineering (runbooks, exercises, detection hooks) and ensure post-incident actions translate into durable engineering improvements.
  • Partner with Global Security for execution: Serve as the primary engineering counterpart to Global Security, translating enterprise policies, controls, tooling, and compliance requirements into recommendations or actionable insights that are adoptable engineering practices, and feeding back where standards need better patterns, automation, or sequencing to scale.
What success looks like

Success in this role is not about managing security reviews, success is measurable engineering outcomes:
  • Drive enterprise-wide adoption of Security and Privacy by Design, ensuring security, privacy, and compliance requirements are proactively integrated into products, services, and technology platforms
  • Security controls are implemented broadly with minimal friction because the secure path is well defined
  • Vulnerabilities have clear owners, predictable remediation, and decreased recurring issues
  • Success in this role is about partnering with Engineering teams on security initiatives and enabling them to be effective with an understanding that Engineering teams have clear ownership of platforms and will be accountable for them
About You

We get excited about candidates like you, because ...
  • You have 12+ years of progressive experience in information security, application security, cloud security, or software engineering, including significant experience leading enterprise-scale security initiatives through technical influence rather than direct authority.
  • You exhibit Principal-level technical leadership with a proven track record of leading cross-team security initiatives through influence, clarity, and shipping real systems-not just policies.
  • You possess strong application security fundamentals such as: authn/authz, session security, secure API design, data protection, threat modeling, and secure SDLC practices.
  • You have pragmatic risk management, with the ability to prioritize, quantify tradeoffs, and create guardrails that teams actually adopt.
  • You have cloud & platform security experience such as: IAM concepts, secrets management, key management, service-to-service auth patterns, and logging/detection fundamentals.
  • You possess a DevSecOps and automation mindset and have experience integrating security checks into CI/CD with minimal developer friction.
  • You exhibit depth in vulnerability management, knowing how to triage, develop remediation strategies, verify fixes, all while partnering with teams to close the loop quickly.
  • You possess excellent communication skills that include concise, executive-ready writing and strong technical coaching abilities for engineers.
  • You meet people where they are and endeavor to build intrinsic motivation to develop solutions to problems through shared understanding.

Preferred, but not required:
  • Experience with streaming/media security and DRM ecosystems and output protection concepts.
  • Experience with mobile and device ecosystems (iOS/Android/TV devices), including secure storage patterns and platform attestation.
  • Familiarity with reverse engineering tools and client hardening/anti-tamper approaches.
  • Exposure to privacy/security compliance partnerships (GRC) and working with legal/product on policy requirements.
About the Team

Crunchyroll's Security team is focused on partnering with teams across the organization to provide secure solutions and protect company assets as we serve the Anime community. We provide Security, GRC (Governance, Risk, and Compliance), Data Privacy, and Network Infrastructure services to the enterprise. Everyday we have an opportunity to make a positive impact while being at the center of innovative initiatives. If you are looking to join a team where you will make a difference, we would love to hear from you.
Why you will love working at Crunchyroll

In addition to getting to work with fun, passionate and inspired colleagues, you will also enjoy the following benefits and perks:
  • Receive a great compensation package including salary plus performance bonus earning potential, paid annually.
  • Flexible time off policies allowing you to take the time you need to be your whole self.
  • Generous medical, dental, vision, STD, LTD, and life insurance
  • Health Saving Account HSA program
  • Health care and dependent care FSA
  • 401(k) plan, with employer match
  • Employer paid commuter benefit
  • Support program for new parents
  • Pet insurance and some of our offices are pet friendly!

#LifeAtCrunchyroll #LI-Hybrid

The Pay Range for this position is listed. Actual pay will vary based on factors including, but not limited to location, experience, and performance. The range listed is just one component of Crunchyroll's Total Rewards offerings for employees. Other rewards may include performance bonuses, employer matched retirement savings, time-off programs, and progressive health benefits and perks.

Pay Transparency - Los Angeles, CA

$249,000-$305,000 USD

About Crunchyroll

Crunchyroll is a streaming service that specializes in anime, manga, and Asian dramas. The company was founded in 2006 and is headquartered in San Francisco, California. Crunchyroll offers a wide selection of anime and manga titles, as well as simulcasts of popular shows from Japan. The company also produces its own original content, including anime series and live-action dramas. Crunchyroll has over 3 million paid subscribers and is available in over 200 countries.
Learn more about Crunchyroll
Size
250 employees
Industry
Founded
2008

Similar Jobs

More Jobs at Crunchyroll

More Media Jobs

Find similar Director, Product Security jobs: