Skip to main content
Zeta Global

Senior Product Manager, Application Security

RemoteUnited States only
Published
Role
Product
Experience
Senior
$170k–$185k/yr
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Senior product manager with 4-6+ years owning enterprise AppSec, platform security, DevSecOps, or adjacent security products in SaaS/B2B environments. Needs deep AppSec tooling knowledge, security-program leadership, and credibility with security and engineering teams. Remote US only.

Core skills

Threat modelingCI/CDApplication Security

Required skills

SASTDASTSCAContainer scanningIaC scanningSecrets scanningVulnerability managementAPI securitySecure SDLCAILLM

Optional skills

AI-assisted securityThreat modeling automationAI code reviewExploitability-informed triageReachability-informed triageUnified findings platformsSnykWiz

What you'll do

  • Own the Application Security product strategy and multi-quarter roadmap from visibility and tooling inventory through architecture and risk-surface mapping, tool procurement and upgrades, CI/CD enforcement, proactive threat reduction, and scaled institutionalization.
  • Build and ship the core AppSec product surfaces, including AI-powered threat modeling and code evaluation, and a unified security risk, signal, and remediation platform.
  • Prioritize critical risk surfaces across the Zeta platform.
  • Define clear requirements, user stories, success metrics, and acceptance criteria for AppSec capabilities.
  • Drive day-to-day execution with Application Security engineering, platform/DevOps, Architecture, InfoSec, and product engineering pods.
  • Establish and evolve governance, including severity and SLA frameworks, incident intake and escalation, secure coding standards, third-party application integration guardrails, and architecture security review for high-risk changes.
  • Lead tool strategy and procurement decisions with clear risk justification, coverage gaps, budget tradeoffs, and integration into developer workflows.
  • Use data and KPIs to measure posture and inform prioritization.
  • Align AppSec initiatives with company objectives.
  • Communicate risk, progress, and asks clearly to engineering and executive stakeholders.
  • Identify and mitigate delivery and security risks.
  • Run post-incident learning loops that convert findings into durable product and process improvements.
  • Mentor and elevate AppSec and adjacent product/engineering partners.
  • Help scale a Security Champions program across the organization.
  • Use AI tools as part of everyday product work.
  • Productize AI defensively for threat modeling, triage, code review, and remediation guidance with appropriate human oversight.

What they require

  • 4-6+ years of product management experience, with meaningful ownership of enterprise Application Security, platform security, DevSecOps, or adjacent security-product domains in SaaS/B2B environments.
  • Deep working knowledge of modern AppSec practices and tooling.
  • Proven ability to drive enterprise-tier security programs, including risk-based prioritization, remediation SLAs, cross-org governance, and executive risk communication.
  • Strong technical background; Computer Science or related field preferred.
  • Credible with security engineers, architects, and engineering leaders on topics such as authn/authz, multi-tenancy, cryptography boundaries, supply chain, and AI/LLM security risks.
  • Demonstrated experience shipping developer-facing security products or workflows, such as CI/CD gates, IDE/MR integrations, security dashboards, or remediation orchestration.
  • Excellent communication and stakeholder influence skills across Engineering, InfoSec, DevOps/Infrastructure, Architecture, and leadership.
  • Proven ability to work independently in ambiguity while building durable process, metrics, and operating cadence.
  • Preferred: Experience building or operating AI-assisted security capabilities.
  • Preferred: Familiarity with MarTech/AdTech or other high-scale multi-tenant platforms handling sensitive customer data.
  • Preferred: Experience with tool evaluation and vendor management for AppSec platforms.
  • Proactive owner who can run Application Security as a product and a program.
  • Thrives in ambiguity, takes end-to-end ownership, and converts strategy into measurable reduction of platform risk.
  • Values pragmatic, risk-based tradeoffs and continuous improvement over checkbox security.
  • Can make security scalable through automation, clear standards, and AI-native workflows without becoming a bottleneck.

Benefits

  • Unlimited PTO
  • Excellent medical, dental, and vision coverage
  • Employee Equity
  • Employee Discounts
  • Virtual Wellness Classes
  • Pet Insurance
  • Forum for employees to celebrate, support and advocate for one another

Zeta Global is the AI-Powered Marketing Cloud that leverages artificial intelligence and trillions of consumer signals to help marketers acquire, grow, and retain customers through the Zeta Marketing Platform.

🇺🇸 United StatesMarketing TechnologyEnterprisezetaglobal.com/

Details

Apply routeGreenhouse
$170k–$185k/yr