What are the responsibilities and job description for the Director, Product Security position at Circle?
What you’ll be responsible for:
Circle is looking for a passionate Security Leader with an expertise in Product Security, deep understanding of different Blockchain technologies and Cloud based Product development. You’ll be part of the Security Engineering team and closely partner with the Engineering teams responsible for the development, deployment of USDC and supporting services.
What you'll work on:
- Own Circle’s Product Security strategy, implementation and operationalization.
- Actively partner with our Engineering teams on the development, deployment of USDC and supporting services.
- Assess and evaluate new Products and Features in partnership with Product Compliance, Product and Engineering teams.
- Recommend and validate Security controls and improvements across our technology stack.
- Own and build relationships with key external stakeholders such as customers, vendors, and auditors.
- Produce data-based reports on technology risk for senior management.
- Drive continuous improvement in the tech stack.
You will aspire to our four core values:
- Multistakeholder - you have dedication and commitment to our customers, shareholders, employees and families and local communities.
- Mindful - you seek to be respectful, an active listener and to pay attention to detail.
- Driven by Excellence - you are driven by our mission and our passion for customer success which means you relentlessly pursue excellence, that you do not tolerate mediocrity and you work intensely to achieve your goals.
- High Integrity - you seek open and honest communication, and you hold yourself to very high moral and ethical standards. You reject manipulation, dishonesty and intolerance.
What you’ll bring to Circle:
- Expertise with Cloud Infrastructure like AWS, GCP or Azure.
- Extensive knowledge of secure best practices for Cloud based software development.
- Extensive knowledge of Security tool usage across SDLC including SAST, DAST and/or Security end to end testing.
- Enthusiasm for automation, scalable and reproducible security practices.
- Self-motivated and creative problem-solver able to work independently .
- Proficiency in managing multiple competing priorities and use good judgment to establish order or priorities on the fly for themselves and their team.
- Ability to influence internal and external customers to expediently resolve issues and achieve organizational objectives.
- The ability to design and operate controls that are easy to test and audit.
- Experience/familiarity with application security including standards like OWASP, tools like Burp Suite, and secure coding practices a plus.
- Experience working in financial services or financial technology desired.
- Advanced degree in computer science, or related fields strongly preferred.
- An understanding of standards such as ISO 27001/27002 and the NIST Cybersecurity Framework desirable.
- 12 years of experience as a security engineer or product security engineering leader with a minimum of five years (can be overlapping) with a focus on cybersecurity.
- 5 years of experience building and managing small to medium sized teams.
- Experience/familiarity with Slack, Apple MacOS and GSuite.