> Markdown version of [/jobs/ext/2687193-senior-product-owner-app-security](https://www.wearedevelopers.com/jobs/ext/2687193-senior-product-owner-app-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Product Owner App Security - **Company:** myra group GmbH - **Location:** München, Germany - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), E-Business, Internet Traffics, Open Web Application Security, PCI Data Security Standards, Web Applications, Captcha - **Published:** September 3, 2026 - **Apply:** https://www.adzuna.de/details/5867245107 ## About the Role * Deep Security Domain Expertise - Genuine, hands-on expertise in at least one of the four product areas: WAF, Bot Management, API Protection, or Captcha - with working fluency across the others. * Application Security Fundamentals - Strong understanding of how web application attacks work at a technical level, including OWASP Top 10, the HTTP request lifecycle, and application-layer defence mechanisms. * B2B SaaS Product Management Experience - Full product lifecycle ownership experience - writing Outcome Briefs, running evidence-based prioritisation, and measuring success through customer outcomes. * Usability Ownership in a Security Context - Proven experience owning not just the effectiveness of a security product but its operational experience - reducing friction for security teams without compromising protection. * Enterprise Security Buyer Understanding - Ability to navigate conversations with both CISOs and security engineers, including compliance frameworks such as PCI DSS, SOC 2, and ISO 27001 - without needing support from a solutions engineer. * Adversarial Thinking - Ability to evaluate every product decision through an attacker's lens - understanding how threat actors adapt and how that should shape roadmap and detection strategy. ## Description At Myra, we develop and operate a certified Security-as-a-Service platform designed to protect digital business processes. Our technology monitors, analyzes, and filters malicious internet traffic before cyberattacks can cause actual damage., * Product vision and roadmap across WAF, Bot Management, Captcha, and API Protection - four products with a shared threat-model domain and a shared enterprise customer base. * Security effectiveness and usability in equal measure: the product must protect customers and be intuitive to configure, monitor, and operate. These are not competing priorities - they are both non-negotiable. * The end-to-end customer experience within each product: onboarding, configuration workflows, dashboards and reporting, alert management, and the operational interfaces that security teams use every day. Friction in any of these is a product problem you own. * Threat landscape tracking: new attack vectors, evasion techniques, OWASP updates, and CVE patterns relevant to application-layer security - translated into product decisions, not just awareness. * Competitive positioning across all four products - where Myra leads, where competitors have pulled ahead, and where market expectations are shifting. * Direct customer relationships with the security practitioners who use these products: engineers and architects making technical decisions, not mediated through sales. * Outcome Briefs for the engineering team: the customer problem, the measurable outcome, and the evidence that makes prioritisation defensible. You own the what. Engineering owns the how. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Is Flutter ready for the web yet? - A live coding comparison between Flutter and React](https://www.wearedevelopers.com/videos/401-is-flutter-ready-for-the-web-yet-a-live-coding-comparison-between-flutter-and-react) - [From clicks to cribs - How to find your dream home with web scraping](https://www.wearedevelopers.com/videos/767-from-clicks-to-cribs-how-to-find-your-dream-home-with-web-scraping) - [Secure and Accessible Login Systems - Ramona Schwering](https://www.wearedevelopers.com/videos/1847-secure-and-accessible-login-systems-ramona-schwering) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Generate AI in the Browser with Chrome AI - Raymond Camden](https://www.wearedevelopers.com/videos/1770-generate-ai-in-the-browser-with-chrome-ai-raymond-camden) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders)