Back to Jobs
Miovision Technologies
Engineering & Architecture 5h ago

Product Security Lead

Miovision Technologies
CanadaCanada
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

Cloud SecuritySecure Software Development Lifecycle (SSDLC)NIST CSF / 800-53CybersecurityIoT Security

Want to know if you're a match for this job?

Calculate My Match Score

At Miovision, we are engineering the future of smart transportation, and to keep our infrastructure safe from digital collisions, we need a highly motivated Product Security Lead to take the wheel.

Reporting directly to the Chief Information Security Officer (CISO), you will be the ultimate defensive driver for our Product Security & Engineering vertical. Your mission is to build security directly into our products, platforms, and engineering lifecycle from the ground up, ensuring we can accelerate down the fast lane of growth without ever compromising safety. You will act as the master traffic controller for product risk, fortifying our software, cloud services, and connected devices against emerging threats.

If you are ready to steer our secure-by-design practices, clear the road for major enterprise deals, and ensure security is always a green light for revenue growth, buckle up and join our team!

Objectives and Responsibilities:

  • Strategic Leadership: Define, build, and lead the vision, roadmap, and operating model for Miovision’s Product Security function, acting as the primary trusted advisor to the CISO, Product, and Engineering leadership.
  • Secure Development (SSDLC): Deeply embed security-by-design into the engineering lifecycle. Lead threat modeling, secure design reviews, and architectural risk assessments while partnering with Engineering to enforce secure coding and CI/CD pipeline security gates.
  • Cloud & Platform Fortification: Influence cloud and platform architecture to guarantee system resilience, strict network segmentation, least privilege access, and robust defense-in-depth strategies.
  • Risk & Vulnerability Management: Lead product-level risk identification and own the vulnerability management lifecycle for product code, APIs, cloud services, and embedded components, overseeing penetration testing and remediation tracking.
  • Go-To-Market Enablement: Partner closely with GRC, Sales, and RevOps to crush RFPs, RFIs, and customer security reviews. Act as a technical authority in customer-facing discussions, turning our security maturity into a massive competitive differentiator.
  • Regulatory Translation: Translate complex regulatory, contractual, and audit requirements (ISO 27001, SOC 2, NIST, Tx-RAMP) into highly practical, defensible, and scalable product-level security controls.
  • Cross-Functional Operations: Collaborate with Security Operations and Cloud Ops to define product telemetry and logging requirements, ensuring secure-by-default deployment patterns and seamless integration into incident response workflows.

The Ideal Profile:

  • The Security Veteran: You bring extensive technical experience in application security, product security, secure engineering, or cloud security, ideally within SaaS or critical-infrastructure environments.
  • The SSDLC Master: You have serious hands-on experience applying Secure Software Development Lifecycle practices, including SAST/DAST integration, threat modeling, and building automated security gates into modern CI/CD pipelines.
  • The Framework Authority: You are highly experienced in mapping controls to major standards like ISO 27001, SOC 2, and NIST CSF / 800-53, with a working knowledge of NIST SP 800-82 (OT/ICS Security) for connected infrastructure.
  • The IoT & Cloud Defender: You have a proven track record of securing connected devices, IoT, or OT-adjacent systems, backed by strong expertise in cloud-native architectures (AWS preferred), APIs, and microservices.
  • The Strategic Influencer: You possess the rare ability to influence senior engineers and product leaders without relying on direct authority, effortlessly translating highly technical risks for auditors, executives, and non-technical stakeholders.
  • The Analytical Problem Solver: You boast a fiercely analytical mindset and exceptional critical thinking skills, allowing you to make sound, high-stakes judgments under ambiguity.
  • The Tooling Expert: You bring strong, practical experience utilizing the OWASP security tool suite and the CISA Cyber Security Evaluation Tool (CSET) to drive rigorous security assessments.

How would you rate this job post?

See what other professionals think about this role.

banner
logo

Miovision Technologies

View Company Profile

Miovision (operating at miovision.com) is a traffic management platform developer engineered for smart cities. Founded by Kurtis McBride and headquartered in Not specified, Miovision provides modern tools to fix today's traffic problems. Under the hood, the platform collects multimodal traffic data and uncovers actionable insights. This allows cities to optimize traffic signal operations and improve traffic flow. Miovision has secured $120 million in funding.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More