Product Security Risk Manager responsible for evolving risk management capabilities at Red Hat. Collaborating across product management and engineering to drive risk governance and reporting.
Responsibilities
Own and Evolve the Risk Management Methodology : Develop, own, and manage the central Product Security risk register, establishing it as the single source of truth for tracking and decision-making.
Assess and Quantify Risk : Partner with technical teams to establish a consistent methodology for assessing and quantifying risk that goes beyond traditional severity scores to incorporate business context such as product impact, revenue, and reputational damage.
Translate and Articulate Risks : Translate complex technical issues and compliance gaps into clear, quantifiable business impact for non-technical audiences.
Drive Governance and Coordination : Lead a cross-functional risk governance committee to review and act on top risks.
Create Tailored Reporting : Design and deliver tailored risk reports, metrics, and dashboards for diverse audiences, including executive leadership, product engineering leaders, legal, and sales organizations.
Improve and Standardize Processes : Build a structured, repeatable program for risk identification, assessment, and communication across the organization.
Build Thought Leadership : Develop learning and development materials to foster a culture of risk awareness.
Requirements
7+ years of experience in product security, application security, or a technical GRC (Governance, Risk, and Compliance) role.
Deep understanding of core security concepts, including the Secure Development Lifecycle (SDL), threat modeling, vulnerability management, and risk assessment methodologies.
Experience building and managing a risk register using dedicated GRC platforms or other tools like Jira.
A bachelor's degree in a related field or an industry certification like CISSP, CGRC, CRISC or CISM are beneficial but not required.
Exceptional ability to translate deep technical issues into clear business risks, explaining the "so what" to senior leaders.
Excellent verbal and written communication skills, with experience presenting to both executive and technical audiences in highly collaborative environments.
Proven skill in influencing cross-functional teams and senior leadership without direct authority.
A process-oriented mindset with demonstrated experience building structured programs from ambiguous or ad-hoc processes.
High attention to detail and the ability to break down large, complex strategies into achievable actions and tasks.
Strong organizational skills to manage multiple stakeholders and drive complex projects to completion.
Proactively leverage AI technologies to streamline workflows, simplify complexity, and enhance overall efficiency.
Benefits
Comprehensive medical, dental, and vision coverage
Flexible Spending Account - healthcare and dependent care
Health Savings Account - high deductible medical plan
Retirement 401(k) with employer match
Paid time off and holidays
Paid parental leave plans for all new parents
Leave benefits including disability, paid family medical leave, and paid military leave
Additional benefits including employee stock purchase plan, family planning reimbursement, tuition reimbursement, transportation expense account, employee assistance program, and more!
Sales Enablement Manager creating technical content for Upwind Security. Collaborating across teams to translate cloud security concepts into clear narratives for engineers and security leaders.
Security Engineer designing and implementing security measures to protect Snap Inc.'s infrastructure. Collaborating across teams while focusing on threat detection and response strategies.
IT Security & Compliance Head at Lonza leading security strategy and managing global risk. Collaboration with senior leadership to enhance information security across Capsules & Health Ingredients business.
Senior Security Manager leading security for Sanofi meetings and events across North America. Ensuring compliance with global meeting policies and managing event security operations in high - stake environments.
Security Officer maintaining safety protocols at Aloft New Orleans. Responsible for patrolling, monitoring security systems, and assisting guests with safety - related concerns.
Security Detection Specialist responsible for detecting cybersecurity incidents using advanced security technologies. Analyzing data feeds and leveraging security tools for incident detection and reporting.
Senior Incident Response Engineer at Walmart focusing on security threat campaigns to enhance detection and response capabilities. Collaborating with SOC and engineering teams to improve security posture.
Head of Infrastructure & Security at Kinatico, a RegTech leader, focused on cloud infrastructure and security governance. Leading a technically deep team of cloud engineers and security specialists in a hybrid environment.
Security Shift Manager overseeing security operations at WarHorse Gaming Omaha. Responsible for team safety, compliance with regulations, and staffing in the security department.
Security Supervisor responsible for loss prevention and safety at WarHorse Gaming casino in Omaha. Ensuring compliance with regulations and managing security team operations.