> Markdown version of [/jobs/ext/2303849-ai-scanning-product-owner](https://www.wearedevelopers.com/jobs/ext/2303849-ai-scanning-product-owner). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AI Scanning Product Owner - **Company:** Eliassen Group - **Location:** Richmond, VA, United States (Remote available) - **Experience:** Expert - **Salary:** $166,400.0 - $176,800.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Agile Methodology, Artificial Intelligence, Amazon Web Services, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, Github, Systems Development Life Cycle, Regression Testing, Software Engineering, Systems Integration, Software Vulnerability Management, Large Language Models, Software Security, Technical Debt, Git, AI Platforms, Jenkins, Static Application Security Testing, Vulnerability Analysis - **Published:** August 30, 2026 - **Apply:** https://dejobs.org/x/x/1DB9C40DDB8140C5B7F5EDADE4C0E2E2/job/ ## About the Role Our client seeks a Senior Product Owner to define, prioritize, and drive the roadmap for an AI-driven code vulnerability detection and reporting capability. The product leverages large language models and automation to identify potential security weaknesses in source code, evaluate detection quality, and integrate actionable results into enterprise security and software development workflows. This role will partner with Information Security, Technology, Application Development, Risk, Compliance, Architecture, Finance, and other stakeholders to translate requirements into capabilities and measurable outcomes. The Senior Product Owner will guide a squad of engineers building and operating the scanner, evaluation harness, integrations, and telemetry. Technical knowledge of application security, AI and LLM systems, cloud platforms, and software development practices is preferred., * 4+ years of related product ownership, product management, information security, software development, or technology delivery experience. * Experience managing a technical product through design, implementation, deployment, adoption, and operations. * Ability to define strategy, maintain a roadmap, manage a backlog, and make prioritization decisions across competing objectives. * Experience translating technical, security, risk, and business requirements into Features, Stories, acceptance criteria, and outcomes. * Working knowledge of SDLC, Git-based development, CI/CD pipelines, APIs, cloud platforms, and production support practices. * Understanding of application security concepts, common vulnerability classes, workflows, and software security testing. * General understanding of AI and large language models, including limitations, prompt or agent behavior, evaluation, and human review. * Ability to interpret metrics such as precision, recall, false positives and negatives, reproducibility, coverage, and reliability. * Ability to evaluate tradeoffs among security risk reduction, customer experience, engineering effort, cost, support, and regulatory impact. * Experience in Agile or SAFe environments. * Strong written and verbal communication skills. * Ability to influence decisions and build alignment across stakeholders without direct authority. * Analytical skills, curiosity, and structured problem solving. * Self-motivated and able to work independently across multiple teams in a regulated environment. * Eligible to work in the United States without sponsorship now or in the future. * Preferred: Product ownership for application security, vulnerability management, developer security, cloud security, or AI-enabled products. * Preferred: Experience with SAST, SCA, composition analysis, or vulnerability detection. * Preferred: Familiarity with AWS hosted AI services or enterprise LLM platforms. * Preferred: Familiarity with GitHub, Jenkins, IaC, containers, and cloud-native architectures. * Preferred: Experience defining evaluation frameworks or quality measures for probabilistic or AI-enabled systems. * Preferred: Experience in regulated financial services. * Preferred: Experience with audit, compliance, model governance, risk assessment, or control evidence. * Preferred: Relevant certifications in product management, Agile, SAFe, cloud, AI, or information security. Recruitment Transparency Notice ## Description * Define and communicate the product vision, strategy, objectives, and roadmap for the AI-driven code vulnerability detection capability. * Own and prioritize the product backlog based on security risk, exploitability, regulatory impact, customer value, operational requirements, and engineering capacity. * Translate business, security, technical, and regulatory needs into clear Features, Stories, acceptance criteria, and measurable outcomes. * Partner with Information Security Engineering, Application Security, Technology, Architecture, Risk, Compliance, Legal, Finance, Operations, and Lines of Business to define and execute product strategy. * Guide delivery of the scanner, evaluation harness, CI/CD integrations, reporting capabilities, operational telemetry, and supporting infrastructure. * Establish success measures for detection effectiveness, precision, recall, reproducibility, coverage, adoption, reliability, cost, and delivery performance. * Define evaluation approaches, regression testing, ground-truth datasets, and release acceptance criteria with engineering and security experts. * Ensure material changes to models, prompts, agents, detection logic, integrations, or evaluation methods are tested, documented, reviewed, and governed. * Prioritize technical debt, reliability improvements, defects, security requirements, and operational enhancements alongside new capabilities. * Provide transparency on roadmap priorities, delivery status, risks, dependencies, performance, and key decisions. * Collaborate across analysis, design, implementation, testing, deployment, and support phases. * Coordinate integrations with GitHub, CI/CD pipelines, enterprise reporting, security monitoring, and vulnerability management workflows. * Engage product consumers and development teams to understand workflow requirements, validate usability, and improve adoption. * Define disposition and workflow for scanner outputs with clear accountability for operations, triage, and remediation. * Maintain documentation, procedures, control evidence, training materials, and stakeholder communications. * Maintain a healthy backlog and participate in planning, refinement, prioritization, demos, retrospectives, and ceremonies. * Communicate capabilities, limitations, roadmap, and performance to technical teams, leadership, and governance bodies. * Maintain controls and documentation to support company, audit, regulatory, and Information Security requirements. * Perform other duties as assigned. ## Related Videos - [Spot, Squash, Secure: Fighting Security Bugs with GitHub Copilot](https://www.wearedevelopers.com/videos/100052-spot-squash-secure-fighting-security-bugs-with-github-copilot) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [How a Small Team Shrank a Microsoft Monorepo by 94%](https://www.wearedevelopers.com/videos/1236-how-a-small-team-shrank-a-microsoft-monorepo-by-94) - [Our GitOps approach for deploying an Identity Provider and an API Gateway in a SaaS company](https://www.wearedevelopers.com/videos/776-our-gitops-approach-for-deploying-an-identity-provider-and-an-api-gateway-in-a-saas-company) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Transforming Software Development: The Role of AI and Developer Tools](https://www.wearedevelopers.com/magazine/527-transforming-software-development-the-role-of-ai-and-developer-tools) - [Dev Digest 196: AI Killed DevOps, LLM Political Bias & AI Security](https://www.wearedevelopers.com/magazine/659-dev-digest-196-ai-killed-devops-llm-political-bias-ai-security) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship)