Education: Bachelor's degree or related field
Experience: 10+ years
We are looking for a Principal Product Manager - Defensive Engineering Programs & Controls reporting within the Defensive Engineering organization in Global Cyber Security (GCS). This role will lead the modernization of our security engineering control landscape - part program manager, part GRC strategist, embedded directly within a security engineering organization.
If you can drive complex technical programs while fluently speaking the language of controls, risk, and compliance, let's talk. Financial services experience is a plus.
The team you will be joining is a part of Defensive Engineering, a function that is vital to the company as it delivers and operates security capabilities that protect the firm's workforce, platforms, and data. This role serves as a bridge between security engineering, risk, compliance, and audit teams, ensuring security controls are measurable, effective, and aligned with business and regulatory requirements.
As a Principal Product Manager - Defensive Engineering Programs & Controls, you will:
- Lead strategic initiatives to modernize and mature the security engineering control landscape across multiple cybersecurity domains. - Define control objectives, success criteria, KPIs, and metrics that measure control effectiveness, coverage, and risk reduction. - Partner with engineering, risk, compliance, legal, and audit teams to drive control implementation, remediation, and continuous improvement. - Translate regulatory, audit, and risk requirements into technical roadmaps and executable engineering programs. - Drive complex cross-functional programs from strategy through execution while providing executive-level reporting and governance.
- Experience leading large-scale cybersecurity, risk, compliance, or security transformation programs. - Strong understanding of security controls, governance frameworks, regulatory requirements, and risk management practices. - Ability to bridge technical engineering teams with risk, compliance, and audit stakeholders. - Strong program management, executive communication, stakeholder management, and decision-making skills. - Experience in financial services or other highly regulated industries preferred.
- Bachelor's degree in Computer Science, Information Security, Engineering, Business, or a related field. - 10+ years of experience in cybersecurity, product management, program management, risk management, or governance functions. - Experience leading regulatory, audit, controls, or security modernization initiatives. - Certifications such as CISSP, CISM, CRISC, PMP, or equivalent preferred. - Familiarity with security control frameworks such as NIST, CIS Controls, ISO 27001, or similar.
- Ability to influence and drive outcomes across engineering, risk, compliance, and executive stakeholders. - Experience developing governance frameworks, control libraries, KPIs, KRIs, and executive reporting. - Knowledge of cybersecurity operations, security engineering, and enterprise security controls.
- Hybrid work model in accordance with company policy. - Ability to collaborate across global teams and time zones. - Standard business hours with flexibility to support key regulatory, audit, and risk initiatives as needed.
Search Principal Product Manager - Defensive Engineering Programs & Controls jobs near Boston, MA → Browse all live jobs
This posting was published by State Street Bank GmbH on their own careers system and is shown here with a direct link to apply there. Employers: for corrections or removal, contact jobs@veritahire.com.