openqareer

Manager, Product Security and Trust

A10 Networks · San Jose, CA

# Manager, Product Security and Trust **A10 Networks** · San Jose, CA · `On-site` 🕒 **Статус:** *Опубликовано: вчера* · *Источник: Indeed* --- ### About the Role Manager, Product Security and Trust About A10 Driving the future of innovation is core to everything we do at A10 Networks. Our 7,000+ customers rely on A10 to help them tackle the challenges of digital transformation, secure their infrastructure, and deliver business-critical applications at hyperscale. With the rapid adoption of AI, we're extending our leadership to secure and deliver AI applications across on-premises, multi-cloud, and edge-cloud environments. Come help us build a better future, for our customers, partners, and our employees. #BeA10 About the Role The Manager, Product Security and Trust serves as a hands-on leader responsible for the security of what A10 ships and the credibility of how A10 proves it. This role owns the application security testing program across the A10 portfolio — SAST, DAST, SCA, secrets and container scanning, and the emerging discipline of AI and model security testing — and works shoulder to shoulder with engineering to embed those capabilities into the development pipeline rather than bolt them on at the end. In parallel, this role partners with Product Management to scope and land product security compliance initiatives, and with IT and Cybersecurity to maintain A10's internal certifications and answer the security questions our customers and prospects ask before they buy. Reporting to the CISO, this manager sits at the intersection of engineering, product, and enterprise security — turning security testing into automated, measurable engineering practice, and turning A10's security posture into something customers can verify. Responsibilities Product Security Engineering - Own and mature A10's application security testing capabilities across the portfolio, including SAST, DAST, SCA, software composition and license analysis, secrets detection, container and image scanning, and fuzzing - Partner with engineering leaders to integrate security testing directly into CI/CD pipelines, define build and release gates, and drive findings to closure with clear ownership, SLAs, and escalation paths - Build and extend security testing capabilities for AI and ML components — model and dependency scanning, adversarial and prompt injection testing, agentic workflow abuse cases, and evaluation of AI-specific attack surface as A10 expands its AI security portfolio - Reduce toil through automation: tune tooling to suppress false positives, automate triage and ticket routing, generate SBOMs as part of the build, and instrument the program with metrics leadership can act on - Track emerging threats, vulnerability classes, and offensive research relevant to network, application delivery, and AI infrastructure, and translate them into testing coverage before they reach our customers Coordinate third-party penetration testing and interlock with PSIRT and the Emberstrike team so external findings, internal red team results, and pipeline findings feed a single remediation backlog - Product Security Compliance - Partner with Product Management to identify, scope, and execute product security compliance initiatives that unlock revenue and satisfy customer and regulatory requirements - Drive certification and conformance efforts across the portfolio, working with engineering and third-party labs to plan evidence, remediation, and timelines against product release schedules - Translate emerging regulatory requirements — secure-by-design expectations, SBOM and supply chain mandates, and regional product security regulation — into concrete engineering requirements and roadmap inputs Represent product security requirements in the NPI process and product governance forums, ensuring security is a defined gate rather than a late-stage discovery - Internal Compliance and Customer Trust - Work with IT and Cybersecurity teams to complete and maintain A10's internal cybersecurity compliance programs, including control ownership, evidence collection, audit readiness, and remediation tracking - Serve as a primary responder for customer and prospect inquiries into A10's security posture — security questionnaires, RFP and RFI security sections, audit requests, and contractual security terms — in partnership with Sales, Legal, and Cybersecurity - Build reusable trust artifacts that scale ahead of demand: standard questionnaire responses, security whitepapers, architecture and data flow documentation, and customer-facing posture summaries Participate in customer and partner security briefings as a credible technical voice on how A10 builds, tests, and secures its products - Leadership - Lead, mentor, and grow a small team of product security engineers, setting technical direction and holding a high bar for engineering rigor - Build durable working relationships across engineering, product, IT, and cybersecurity, influencing outcomes in teams that do not report to this role Communicate risk clearly and without drama to audiences ranging from individual engineers to executive leadership and customers - Required Qualifications - 7+ years of experience in product security, application security, or a closely related cybersecurity discipline, including 2+ years leading a team or owning a program end to end - Hands-on depth with application security testing tooling and the practical realities of running it at scale — tuning, triage, false positive management, and developer adoption - Demonstrated experience integrating security testing into CI/CD pipelines and automating security workflows - Working knowledge of software supply chain security, including SBOM generation, open source license and vulnerability management, and dependency risk - Experience with security compliance frameworks and audit processes, and with producing evidence that withstands external scrutiny - Strong written communication skills, with the ability to produce customer-facing security documentation that is accurate and defensible - Ability to work effectively with engineering teams as a partner rather than a gatekeeper Bachelor's degree in Computer Science, Information Security, a related field, or equivalent practical experience - Preferred Qualifications - Experience securing networking, application delivery, or infrastructure security products - Familiarity with AI/ML security testing, model risk, and the OWASP Top 10 for LLM Applications - Scripting or development experience sufficient to build automation and integrations without waiting on another team - Experience supporting SOC 2, ISO 27001, or product certification efforts in a commercial software or hardware environment - Experience responding to enterprise, government, or service provider security due diligence - Relevant certifications such as CISSP, CSSLP, OSCP, or GIAC equivalents #LI-AN1 - Hyb rid AI Use Guidelines for Int erviews: Our interviews are designed to reflect your own skills and thinking. The use of AI or recording tools during live interviews is not permitted unless explicitly invited by the interviewer or approved in advance as part of a reasonable accommodation. If these tools are used inappropriately or in a way that misrepresents your work, your application may not move forward in the process. Targeted compensation guideline: up to $180,000; Compensation will vary based on number of factors, including market demand for specific skills, role type, job level, and individual qualifications. Final salary offers are determined by considerations including, but not limited to, subject matter expertise, demonstrated skill level, relevant experience, geographic location, education, certifications, and training.

Наблюдалась 2026-09-29, впервые 2026-09-28, источник — Indeed.

Открыть у работодателя