DescriptionJob Overview and ResponsibilitiesThe Senior Manager - Product Cybersecurity is a technical leader responsible for managing a team of highly innovative cybersecurity engineers responsible for developing and maintaining end-to-end security architecture of United's product(s)/application(s)/service(s). This person will create and implement a vision for security across all products within the United portfolio.
- Responsible for recruiting and talent development of team, including personnel management
- Define, prioritize, allocate resources, track, and provide status reporting of work assignments, projects, and programs
- Monitors changes in legislation and compliance standards that affect assigned areas of responsibility and proactively acts to update standards, best practices and architectures based on this information
- Coordinates remediation of non-compliant items to meet applicable compliance standards and best practices
- Assist with annual budgeting and monthly forecasting
QualificationsWhat's needed to succeed (Minimum Qualifications):- Bachelor's degree required (STEM field preferred)
- At least 5 years of relevant experience
- Proficiency with OWASP Top 10
- Proficient knowledge of threat modeling
- Proficient knowledge of risk management processes
- Ability to secure AI, ML, or LLM products or familiarity with SDLC for AI, ML, or LLMs
- Proficiency with application testing (e.g., SAST, DAST, MAST, RAST, IAST, Pen Test tooling)
- Proficiency with programming languages and modern programming language structure (i.e., Object Oriented Programming, web framework)
- Proficient with DevSecOps technology stacks (i.e., AWS, Harness, TeamCity, GitHub, Artifactory, CHEF, CloudWatch)
- Proficiency with SDLC process
- Proficiency with web and app security stack (e.g., API security)
- Proven ability to lead people
- Able to build and execute a workforce transformation strategy that develops the team's capabilities in AI-assisted security engineering, frontier-model application security testing, secure AIDLC, and agentic automation
- Ability to manage business and external partners
- Excellent problem solving, critical thinking, interpersonal, collaboration, written and verbal communication skills
- Must be legally authorized to work in the United States for any employer without sponsorship
- Successful completion of interview required to meet job qualification
- Reliable, punctual attendance is an essential function of the position
What will help you propel from the pack (Preferred Qualifications):- Master's degree
- One or more of the following: CEH, GSEC, CISM, Security +, CISSP, CISA, SSCP, CASP, OSCP, AWS Solution Architect Pro., Networking, and Security Specializations
- 10+ years of relative experience
- Strong subject matter expertise in the fields of IT security and risk management
- Experience with technical documentation / SOP creation
- Proficient understanding of compliance frameworks (e.g., NIST 800-53) and processes
- Demonstrated experience applying security and risk-management practices to AI/ML or generative AI systems, including secure AI lifecycle reviews, AI threat modeling, adversarial testing and component supply-chain risk and runtime guardrails
- Demonstrated experience implementing or governing frontier-model-enabled application security testing, including context-aware code analysis, vulnerability discovery, exploitability validation, remediation generation, threat-model-informed testing. Experience must include human validation, secure execution environments, model and prompt governance, quality measurement and integration with developer and CI/CD workflows
- Strong knowledge of IT infrastructure security best practices, procedures, and standards
- Experience with cloud native products and in-depth understanding microservice topologies and implementations
- Expertise in application development and dev-ops security technologies and integration
- Demonstrated ability to think strategically about business, product, and technical challenges
- Experience within the transformation of traditional data center security measures into industry adopted cloud technologies
- Proven ability to work with compliance frameworks and requirements
- Ability to work in a fast-paced and Agile development environment
- Ability to perform manual security code reviews
- Ability to interpret dynamic/static analysis tools, and penetration test results
- Proficient knowledge of cloud technologies and security
- Proficiency with vulnerability management processes and providing remediation guidance
- Proficiency in cryptography
- Proficient understanding of IAM (i.e., authentication and authorization)
- Proficient understanding of networks and network security
Job Post Expiration: 10/1/2026