Director of Security
KoBold MetalsFull Time
Expert & Leadership (9+ years)
Candidates must be experienced security leaders with a proven track record in building and scaling Product Security functions. A strong understanding of Application Security, including Bug Bounty, Vulnerability Management, and secure SDLC programs, is essential. Experience leading Data and Device Security initiatives and building Security Research teams is required. The role demands people leadership skills, including managing individual contributors and managers, providing feedback, and fostering career development, as well as the ability to hire security professionals. A strategic mindset with a focus on proactive risk reduction and enabling secure innovation, particularly with AI, is necessary. Experience in defining and driving company-wide security strategies, establishing metrics and reporting, and partnering with engineering, product, and security leadership is crucial. Familiarity with secure coding practices, threat modeling, security reviews, code analysis, CI/CD pipeline integration, and shifting security left is expected. Experience overseeing vulnerability management, pentesting, and vulnerability disclosure programs, including rapid triage and remediation, is required. Knowledge of data security, cryptography, cryptographic libraries, codebase secrets management, and device security, including security libraries and frameworks, is necessary. Participation in on-call rotations and support during incident management processes is part of the role.
The Senior Director, Product Security will be responsible for setting the strategy and scaling Product Security programs, including Application Security, Bug Bounty, Vulnerability Management, Data and Device Security, and Secure SDLC. They will lead a team of security professionals, including managers and individual contributors, and foster their career development. The role involves defining and driving the company-wide Product Security strategy with a focus on proactive risk reduction and enabling secure AI innovation. Responsibilities include building and scaling world-class programs, establishing metrics and reporting for program success, and partnering with engineering, product, and security leadership to reduce risk. This includes developing and overseeing secure coding practices, integrating security into the SDLC and CI/CD pipelines, and enabling developers with tools and training. The Director will oversee vulnerability management and pentesting programs, ensuring rapid triage and remediation of vulnerabilities, and partner on a collaborative vulnerability disclosure program. They will also lead the data security program, including cryptography and secrets management, and the device security program, focusing on security libraries and frameworks. The role involves participating in on-call rotations and supporting incident management.
Password management and secure access solution
1Password provides a password management and secure access solution that helps businesses manage and protect their sensitive information. The platform allows employees to securely access applications and share important data like logins and documents while keeping other information private. It operates on a subscription model, offering various plans to meet the needs of different organizations. 1Password integrates with existing identity and access management systems such as Azure AD and Okta, enabling automatic employee provisioning and enhancing security without disrupting workflow. The goal of 1Password is to help businesses improve their cybersecurity measures while ensuring ease of use and maintaining productivity.