Product Security Lead securing Miovision’s intelligent transportation products, cloud services, and connected devices. Leading secure-by-design engineering and product risk management for safer smart transportation networks.
Responsibilities
Define, build, and lead Miovision’s Product Security function, including its vision, roadmap, and operating model
Advise the CISO, Product, and Engineering leadership
Embed security-by-design into the engineering lifecycle
Lead threat modeling, secure design reviews, and architectural risk assessments
Partner with Engineering to enforce secure coding and CI/CD pipeline security gates
Influence cloud and platform architecture through network segmentation, least-privilege access, resilience, and defense-in-depth strategies
Lead product-level risk identification and the vulnerability management lifecycle for product code, APIs, cloud services, and embedded components
Oversee penetration testing and remediation tracking
Partner with GRC, Sales, and RevOps on RFPs, RFIs, and customer security reviews
Serve as a technical authority in customer-facing discussions
Translate ISO 27001, SOC 2, NIST, and Tx-RAMP requirements into product-level security controls
Collaborate with Security Operations and Cloud Ops on product telemetry, logging, secure-by-default deployment patterns, and incident-response integration
Requirements
Extensive technical experience in application security, product security, secure engineering, or cloud security, ideally within SaaS or critical-infrastructure environments
Hands-on experience applying Secure Software Development Lifecycle practices
Experience with SAST/DAST integration, threat modeling, and automated security gates in modern CI/CD pipelines
Experience mapping controls to ISO 27001, SOC 2, NIST CSF / 800-53
Working knowledge of NIST SP 800-82 (OT/ICS Security)
Proven track record securing connected devices, IoT, or OT-adjacent systems
Strong expertise in cloud-native architectures, AWS preferred, APIs, and microservices
Ability to influence senior engineers and product leaders without direct authority
Ability to translate technical risks for auditors, executives, and non-technical stakeholders
Analytical mindset and exceptional critical-thinking skills
Practical experience using the OWASP security tool suite and CISA Cyber Security Evaluation Tool (CSET)
IT Security Officer overseeing information security for Desjardins’ property and casualty insurance sector. Managing risks, vulnerabilities, suppliers, complex projects, and executive security reporting.
Azure SA&A Specialist supporting Government of Canada security assessments, controls, evidence, and testing. PLATO delivers Indigenous - owned software testing and technology services across Canada.
Senior Security Engineer owning identity, IT automation, and cloud security for Maze, a user research platform. Driving vulnerability management, compliance, and secure infrastructure at scale.
Product Security Engineer securing WorkOS developer tools and APIs for enterprise authentication and identity. Leading secure design, offensive testing, tooling, and vulnerability remediation.
Staff Product Security Engineer securing Phantom’s self - custodial multi - chain crypto wallet. Assessing vulnerabilities, leading security projects, and integrating protection across development and platform teams.