AVP of Product Security

Addison · Hybrid

About this role

At Semperis, our mission is to be a Force for Good. Starting with being a great place to work. We believe that when people feel valued, supported, and empowered, they do their best work. That’s why we focus on creating an employee experience rooted in purpose, growth, and balance. Semperis has been recognized as one of America’s Fastest-Growing Cybersecurity Companies by the Inc. 5000, a DUNS 100 Top Startup to Work For, and a multi-year Inc. Best Workplace awardee.

About the Role

We are seeking an AVP of Product Security, reporting directly to the Chief Information Security Officer. This leader will drive security into product development. This is a transformation role to scale company wide efforts across our products, and the right leader will bring a mindset that drives the business forward and with scalability at top of mind. You will drive the approach, patterns, and engagement that embed security through design standards, threat modeling, and automated processes.

The AVP of Product Security will own security architecture and vulnerability management. Architecture sets the standard at design time, and vulnerability management proves whether it held. This holistic approach means you set the direction and you get the data to steer by, with ownership over the environment.

AI is what makes this the moment. It is moving to the core of what we ship and how we build, and you will define how we secure it, from architecture patterns for models and agents to a vulnerability management program built for threats that did not exist two years ago. This is a chance to build the practice, with executive backing and a company growing fast enough to make it count.

What you will be doing:

  • Establish secure by design standards and the target state security architecture across product development, covering threat modeling, secure design review, secure SDLC, and vulnerability management.

  • Shift security left into product and engineering to reduce risk and cost, so that fewer issues surface late in the release cycle where remediation is most expensive.

  • Build a formal vulnerability management program encompassing both traditional vulnerability management and AI. This includes addressing prompt injection, model manipulation and evasion, training data poisoning, model and data exfiltration, insecure model supply chain, and unsafe agentic behavior.

  • Enable secure AI adoption across our products and internal systems.

  • Define security architecture patterns that drive clarity with the business and enable the right guardrails.

  • Own risk based prioritization, remediation SLAs, and executive reporting for enterprise vulnerability management.

  • Provide senior technical leadership and create clear, consistent standards across Product, Engineering, and Security.

  • Build proactive security leadership and trusted partnerships across Product, Engineering, and Security teams.

  • Recruit, develop, and lead a strong team of product security engineers and security architects.

What you will bring to the table:

A proven track record across a variety of large, product driven organizations, with a focus on transformation, scale, and partnering with the business.

  • 10+ years of information security experience, including 5+ years leading product security, security architecture, and/or vulnerability management functions.

  • Proven experience embedding security into the Software Development Lifecycle SDLC at a software or SaaS company, including threat modeling, secure design review, code and dependency scanning, and penetration testing.

  • Deep security architecture expertise across cloud native and hybrid environments (Azure preferred).

  • Hands on experience implementing AI and ML security controls.

  • Experience building or maturing enterprise vulnerability management programs, including risk based prioritization and remediation governance.

  • A track record of influencing at the executive level and driving alignment across Product, Engineering, and Security organizations.

  • Strong communication skills, with the ability to translate technical risk into clear business terms that enable decisions.

Bonus Points:

  • Experience securing agentic AI systems or AI enabled products in production.

  • Familiarity with identity security, Active Directory, and Entra ID.

  • Experience supporting compliance programs such as FedRAMP, SOC 2, ISO 27001, or NIST frameworks.

  • Relevant certifications (CISSP, CSSLP, SABSA, TOGAF).

Why Join Semperis?
You’ll be part of a global team on the front lines of cybersecurity innovation. At Semperis, we celebrate curiosity, integrity, and people who take initiative. If you’re someone who sees the glass as half full, embraces challenges as growth opportunities, and values a healthy balance between work and life—we’d love to meet you.

**Semperis maintains office locations in several cities across the globe. Where the job description specifies a required location, candidates will follow our hybrid work model. This includes working up to three days per week and remotely the remaining days.

Semperis is an equal opportunity employer and will not discriminate against an applicant or employee based on race, color, religion, creed, national origin or ancestry, ethnicity, sex (including gender, pregnancy, sexual orientation, and gender identity), age, physical or mental disability, veteran or military status, genetic information, citizenship, marital status, or any other legally recognized protected basis under federal, state, or local law. The information collected by the Semperis application is solely to determine suitability for employment, verify identity, and maintain employment statistics.

Applicants with disabilities may be entitled to reasonable accommodation under the Americans with Disabilities Act and/or other applicable state or local laws. A reasonable accommodation is a change in the way things are normally done which will ensure an equal employment opportunity without imposing undue hardship on Semperis. Please inform Semperis representative Anna Taylor, Director of Global Recruiting, if you need assistance completing this application or to otherwise participate in the application process.

Company at a glance

For security teams charged with defending hybrid and multi-cloud environments, Semperis ensures the integrity and availability of critical enterprise directory services at every step in the cyber kill chain and cuts recovery time by 90%. Purpose-built for securing hybrid identity environments—including Active Directory, Entra ID, and Okta—Semperis’ AI-powered technology protects over 100 million identities from cyberattacks, data breaches and operational errors. The world’s leading organizations trust Semperis to spot directory vulnerabilities, intercept cyberattacks in progress and quickly recover from ransomware and other data integrity emergencies. Semperis is headquartered in Hoboken, New Jersey, and operates internationally, with its research and development team distributed throughout the United States, Canada and Israel.

Semperis hosts the award-winning Hybrid Identity Protection conference and podcast series (www.hipconf.com) and built the community hybrid Active Directory cyber defender tools, Purple Knight (www.semperis.com/purple-knight/) and Forest Druid. The company has received the highest level of industry accolades, recently named to Inc. Magazine’s list of best workplaces for 2024 and ranked the fastest-growing cybersecurity company in America by the Financial Times. Semperis is a Microsoft Enterprise Cloud Alliance and Co-Sell partner and is a member of the Microsoft Intelligent Security Association (MISA).

Team Size501-1,000 employees
WorkspaceHybrid
IndustryComputer and Network Security
Location
Addison, Texas, United States
LinkedInLinkedIn

Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?