ASSA ABLOY Door Security Solutions

Senior Product Vulnerability Manager

Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in a product security or application security context.
  • Strong understanding of the vulnerability lifecycle
  • Knowledge of application security principles (e.g., OWASP Top 10)
  • Experience with vulnerability detection tools and their integration into development pipelines.
  • Familiarity with regulatory requirements such as the EU Cyber Resilience Act (CRA).
  • Excellent communication skills to convey technical risk in a business context.
  • Experience managing small teams and working in multi-product environments.

Responsibilities

  • Define and maintain the enterprise Product Vulnerability Management framework.
  • Establish standardized vulnerability triage and risk prioritization methodologies.
  • Own the Coordinated Vulnerability Disclosure (CVD) program and engagement with external researchers.
  • Translate regulatory requirements into operational processes and controls.
  • Develop scalable guidance materials for product teams on vulnerability processes.
  • Establish metrics and reporting for measuring vulnerability management effectiveness.
  • Build and lead a small team for program operations and disclosure coordination.

Benefits

  • Competitive benefits and annual leave offering for work-life balance.
  • A vibrant, welcoming, and inclusive culture.
  • Extensive career development opportunities and resources.
  • Part of a global organization pioneering secure navigation in physical and digital realms.
Full Job Description
Location: Remote (US)

Job ID: 47562

As part of the Product Security and Privacy team, you will own and operate the corporate-wide Product Vulnerability Management program.

You will establish the organization's technical and operational capabilities to detect, triage, prioritize, and respond to product vulnerabilities across a diverse portfolio of products and technologies.

Accountable for the consistency, scalability, and defensibility of vulnerability management practices, you will ensure processes, tooling, and outputs are standardized, audit-ready, and aligned with regulatory expectations, including the EU Cyber Resilience Act (CRA).

You will operate at a strategic level, enabling product teams to execute vulnerability management activities effectively through defined standards, tooling, and governance, rather than performing hands-on remediation or investigation.

As our Senior Product Vulnerability Manager, you'll support HID's success by:
  • Defining and maintaining the enterprise Product Vulnerability Management framework, including processes for intake, triage, prioritization, remediation tracking, and disclosure.
  • Establishing standardized vulnerability triage and risk prioritization methodologies that work across the organization
  • Defining and implementing the corporate-wide vulnerability management policies and standards ensuring our Product Security Incident Response processes are appropriate with the organization's expectations and regulatory requirements.
  • Owning the Coordinated Vulnerability Disclosure (CVD) program, including external intake channels, researcher engagement, and coordination.
  • Translating regulatory requirements (e.g., EU Cyber Resilience Act) into operational processes, controls, and reporting obligations.
  • Defining and managing the enterprise tooling strategy for vulnerability detection (e.g., SAST, DAST, SCA, container scanning), including selection, configuration, and integration into CI/CD pipelines.
  • Establishing minimum tooling and coverage baselines across product types and ensure consistent adoption.
  • Defining and operationalize SBOM-driven vulnerability management practices, including monitoring and response to third-party component vulnerabilities.
  • Developing scalable playbooks, guidance, and decision frameworks enabling product teams to independently triage and respond to vulnerabilities.
  • Defining training requirements and developing enablement materials for product teams on vulnerability identification, triage, and response processes.
  • Establishing metrics, reporting, and dashboards to measure vulnerability management effectiveness, including SLA adherence, backlog, and remediation timelines.
  • Providing executive-level reporting and insights on product vulnerability risk posture.
  • Defining governance processes, including exception handling, risk acceptance, and escalation pathways.
  • Leading audit and assessment readiness related to vulnerability management processes and outputs.
  • Building and leading a small team responsible for program operations, tooling, and disclosure coordination.
  • Partnering with Product Security Architects, Engineering, Legal, and Compliance teams to ensure alignment and effective execution across the organization.
  • Acting as the central authority for product vulnerability management practices across the organization.
  • Enabling a federated operating model where product teams own remediation while adhering to centralized standards and processes.
  • Driving consistency in vulnerability handling across a large and diverse product portfolio.
  • Ensuring vulnerability management practices scale effectively across hundreds of products and multiple technology domains.
  • Providing strategic direction for continuous improvement of vulnerability management capabilities, tooling, and processes.
  • Supporting regulatory audits and customer inquiries related to vulnerability management and disclosure practices.


Your Experience and Background include:
  • Experience designing, building, or scaling a vulnerability management or PSIRT program within a product security or application security context.
  • Strong understanding of the vulnerability lifecycle, including detection, triage, prioritization, remediation tracking, and disclosure.
  • Working knowledge of application security principles and common vulnerability classes (e.g., OWASP Top 10).
  • Experience with vulnerability detection tooling (SAST, DAST, SCA, container scanning) and integration into development pipelines.
  • Experience defining or applying vulnerability scoring methodologies (e.g., CVSS) in a product context.
  • Familiarity with Coordinated Vulnerability Disclosure (CVD) processes and external researcher engagement.
  • Familiarity with regulatory requirements related to product security and vulnerability management, such as the EU Cyber Resilience Act (CRA).
  • Experience working within or supporting Secure Software Development Lifecycle (SSDL/SSDLC) programs.
  • Strong ability to define processes, standards, and governance models that scale across large organizations.
  • Excellent communication skills with the ability to translate technical risk into business impact.
  • Experience operating in large-scale, multi-product environments with distributed engineering teams is preferred.
  • Experience establishing or managing SBOM and software supply chain vulnerability programs is preferred.
  • Experience with vulnerability disclosure programs or bug bounty platforms is preferred.
  • Experience working in regulated industries or environments with strong compliance requirements is preferred.
  • Experience with Agile/SAFe methodologies is preferred.
  • Experience leading or mentoring small, high-impact teams is preferred.


What we can offer you:
  • Competitive salary and rewards package
  • Competitive benefits and annual leave offering, allowing for work-life balance
  • A vibrant, welcoming & inclusive culture
  • Extensive career development opportunities and resources to maximize your potential
  • To be a part of a global organization that is pioneering the hardware, software and services that allow people to confidently navigate the physical and digital worlds


The wage range for this role considers a broad scope of factors that are considered when making compensation decisions, including but not limited to: skill sets, experience and training, licensure and certifications, and other business and organizational needs. The disclosed range does not account for geographic differentials based on the location where the position may be filled. At HID, it is uncommon for individuals to be hired at or near the top of the range. Final compensation decisions depend on the specific facts and circumstances of each case.

The base salary in the United States is $170,000 to $200,000.

This opportunity may be open to flexible working arrangements.

HID does not accept unsolicited resumes from headhunters, recruitment agencies, or fee-based recruitment services. We are not responsible for any fees related to unsolicited resumes.

#LI-HIDGlobal

About ASSA ABLOY Door Security Solutions

ASSA ABLOY Door Security Solutions is a division of ASSA ABLOY, the global leader in access solutions. The company provides a wide range of door security and safety solutions for commercial and institutional customers. Its products include locks, door closers, exit devices, electromechanical products, and access control systems. ASSA ABLOY Door Security Solutions operates in North America and has manufacturing facilities in the United States and Canada. The company is committed to sustainability and has implemented various initiatives to reduce its environmental impact.
Learn more about ASSA ABLOY Door Security Solutions
Size
50,000 employees
Industry
Founded
1992

Similar Jobs

More Jobs at ASSA ABLOY Door Security Solutions

  • ASSA ABLOY Door Security Solutions
    AEM Technical Lead
    $100K — $130K *
    Berlin, CT 06037 (Capitol County)
    Technical Services
    In-Person
  • ASSA ABLOY Door Security Solutions
    Electrical Component Engineer
    $90K — $120K *
    New Haven, CT 06511 (South Central Ct County)
    Manufacturing & Automotive
    In-Person
  • ASSA ABLOY Door Security Solutions
    Controls Engineer
    $75K — $95K *
    Tulsa, OK 74133 (Tulsa County)
    Manufacturing & Automotive
    In-Person
  • ASSA ABLOY Door Security Solutions
    Corporate Development Manager
    $90K — $130K *
    New Haven, CT 06511 (South Central Ct County)
    Finance & Insurance
    In-Person
  • ASSA ABLOY Door Security Solutions
    Project Engineer
    $75K — $95K *
    Tulsa, OK 74133 (Tulsa County)
    Manufacturing & Automotive
    In-Person

More Information Technology Jobs

Find similar Senior Product Vulnerability Manager jobs: