The ProblemAs Flock rapidly expands its fleet of connected hardware devices and cloud platforms, establishing a dedicated, centralized product security response program is critical to protecting our public safety network. Managing vulnerabilities across hardware, firmware, and cloud systems requires a single point of accountability to coordinate disclosures and drive fixes to closure. You will stand up our Product Security Incident Response Team (PSIRT), serve as the technical owner of our Coordinated Vulnerability Disclosure (CVD) program, and safeguard the products our customers depend on.
What You'll Own- Own the operational model and execution of Flock's Product Security Incident Response Team (PSIRT) across every externally reported and internally discovered product vulnerability.
- Serve as the operational lead for our CVE Numbering Authority (CNA), managing vulnerability intake, triage SLAs, severity rubrics, and public CVE record publishing.
- Drive cross-functional remediation efforts across Hardware, Firmware, Device SRE, Cloud SRE, Mobile, Legal, Communications, and Support to ensure timely patch delivery.
- Author clear, accurate public security advisories, internal postmortems, and executive summaries tailored to technical, legal, and leadership audiences.
- Establish metrics and operational reporting for PSIRT performance, tracking time-to-triage, time-to-fix, and time-to-disclose.
What This Role is Not- This isn't a people management position, you are an individual contributor who drives execution and policy adherence through cross-functional influence.
- This is not a corporate security or internal SOC role, your sole focus centers on product security, field devices, and embedded software platforms.
- This isn't a passive triage desk, you will actively guide technical remediation strategies and defend severity decisions with engineering leaders and external security researchers.
What You Bring- Demonstrated experience leading or running a PSIRT, product security, or coordinated vulnerability disclosure function, ideally within connected hardware or IoT environments.
- Deep operational experience acting as a CVE Numbering Authority (CNA) or implementing the FIRST PSIRT Services Framework across discovery, triage, remediation, and disclosure.
- Hands-on technical background in product security across embedded or firmware security, Linux or Android device security, AWS cloud security, or mobile application security.
- Expertise applying CVSS, CWE, EPSS, and SSVC frameworks to evaluate risk and assign accurate vulnerability severities.
- Strong written communication skills with the capability to translate complex technical vulnerabilities into clear advisories for customers, engineers, and executives.
CompensationIn this role, you'll receive a starting salary between $185,000 and $230,000 as well as Flock Stock Options. Base salary is determined by job-related experience, education/training, as well as market indicators. Your recruiter will discuss this in depth with you during our first chat.
Some problems get solved faster in the same room, so we prioritize candidates in Atlanta and Boston. Hub-based roles mean real in-person time with your coworkers. Remote roles exist, and when a posting is open to remote work, it says so.