The application window is expected to close on:
Job posting may be removed earlier if the position is filled or if a sufficient number of applications are received.
Senior Staff Product Manager - Platform Security We are hiring a
Senior Staff Product Manager to lead Platform Security - defining and driving the core security primitives that power Splunk's platform, cloud services, and AI future. This role owns product strategy and execution for PKI, certificate lifecycle automation, TLS and cryptographic upgrades, FIPS compliance, secrets management, and secure service identity for a multi-billion-dollar product portfolio.
You will drive the next generation of Splunk's secure foundation - ensuring every workload, every customer action, and every AI agent at Splunk is backed by strong identity=, standards-compliant hardened cryptography, and secure-by-default design. You will also lead security direction for
AI agent workloads and runtime environments, ensuring safe credentials, isolationed boundaries, encrypted inter-agent communication, and trust-anchored execution models as Splunk scales into distributed automation and agentic decisioning.
This is a pivotal role for Splunk's future. You will act as the product authority and single-threaded owner working across engineering, architecture, and product leadership to deliver crypto-resilient infrastructure that customers rely on every second of every day.
Responsibilities - Develop and maintain a multi-year roadmap for Platform Security capabilities including certificate lifecycle management, PKI infrastructure, secrets management, token security, and cryptographic compliance (FIPS 140-3, TLS modernization).
- Manage strategic decisions to ensure the highest impact from security engineering investments in a dynamic and fast-paced environment.
- Lead product strategy for secure-by-default foundation services - certificate authority enablement, key/secret management, automated rotation, secure bootstrapping, and encrypted data-in-transit/at-rest standards across Splunk products.
- Drive security strategy for AI agent workloads and runtime environments - credential isolation, secret-safe execution, secure inter-agent messaging, and identity-backed trust between agents, services, and compute surfaces.
- Partner closely with engineering, architecture, compliance, and product teams to deliver security-critical outcomes tied to regulatory requirements and Cisco-Splunk alignment.
- Drive product development end-to-end - shaping RFCs, technical requirements, prioritization, and execution through GA delivery at enterprise scale.
- Influence direction and elevate standards through clear roadmap narratives, technical proposals, and risk-impact evaluations across multiple product organizations.
- Champion a platform-wide security culture focused on resilience, crypto-agility, and continuous improvement of secrets, certificates, and machine identity posture.
Minimum Requirements - Bachelor's, Master's, PhD in Computer Science, Security Engineering, or equivalent technical experience - with demonstrable depth in cryptographic or distributed security domains.
- 10+ years Product Management or Technical Leadership experience in cloud, enterprise infrastructure, or high-security systems.
- Proven expertise owning and scaling platform security systems - sucha as PKI, certificate automation pipelines, CA/RA models, HSM/KMS integration, token/secret stores, mTLS authentication, and access trust chains.
- Direct experience leading large-scale cryptographic modernization (TLS 1.3 upgrades, OpenSSL 3.x migrations, cipher deprecation, FIPS 140-2/3 certification, crypto agility frameworks).
Preferred Requirements - Ability to influence architecture and technical standards across multiple business units - establishing long-term direction, governance, and execution rhythm across distributed engineering teams.
- Exceptional written and spoken communication - able to articulate proposals at exec level and drive alignment across technical decision-makers.
- Splunk or distributed observability platform experience strongly preferred; background in large-fleet runtime security or agent-based compute models a plus.