About this role
Job title: Product Security Manager
About the Role Northwood is a modern space infrastructure company bringing the benefits of space to the masses through advanced communications technology. As Product Security Lead, you will own the security of Northwood's software and systems from design through deployment, guiding the security program and collaborating with product and infrastructure teams. This is a senior technical leadership role responsible for threat modeling, secure architecture reviews, vulnerability management, and cryptographic foundations to protect mission-critical space communications.
What You'll Do
- Own application security across the full software development lifecycle, ensuring security requirements are defined, validated, and enforced from design through production release.
- Conduct security architecture reviews and threat modeling for new product features, platform changes, and third-party integrations.
- Establish and maintain secure coding standards, security review gates, and developer security training programs.
- Serve as the primary security liaison for product engineering teams, translating compliance and security requirements into actionable engineering guidance.
- Deploy, manage, and continuously improve SAST and DAST tooling integrated into development workflows; own the vulnerability management program end-to-end: discovery, triage, remediation tracking, and reporting.
- Conduct and coordinate penetration testing against Northwood's products and infrastructure, including scoping, execution, findings management, and remediation validation.
- Build and maintain container security scanning, dependency analysis, and software composition analysis (SCA) pipelines.
- Integrate automated security validation and policy enforcement into CI/CD pipelines; own secrets management infrastructure, including deployment, policy configuration, access controls, and audit logging.
- Review and harden Infrastructure as Code, GitOps workflows, and deployment automation for security misconfigurations and policy violations.
- Design and implement cryptographic controls for data at rest/in transit and satellite protocols, including key management and certificate lifecycle management; align with NIST standards and government requirements.
- Identify and remediate cryptographic weaknesses across product systems.
- Hire and develop product security engineers; collaborate with network operations, mission management, and compliance teams to maintain a security posture that enables mission success.
- Build security documentation, audit evidence, and reporting standards that satisfy FedRAMP, CMMC, and NIST 800-171 requirements.
What We're Looking For
- 5+ years in product security, application security, or a closely related security engineering discipline, with demonstrated technical leadership.
- Deep expertise in SAST and DAST tooling, including tool selection, CI/CD integration, and remediation programs.
- Hands-on experience conducting or coordinating penetration testing engagements, including scoping, execution, and remediation validation.
- Strong applied cryptography knowledge, including symmetric cryptography, key management, and secure protocols.
- Proven ability to collaborate with cross-functional teams and translate security requirements into actionable guidance.
- Familiarity with container security, IaC security, and secure software supply chain concepts.
Compensation & Benefits
- Salary: $120,000 - $190,000 per year. Onsite, full-time role.