> Markdown version of [/jobs/ext/2718367-product-manager-identity-user-security](https://www.wearedevelopers.com/jobs/ext/2718367-product-manager-identity-user-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Product Manager, Identity & User Security - **Company:** Airwallex US, LLC - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software as a Service, Fraud Prevention and Detection, Identity and Access Management, Phishing, SQL Databases, Management of Software Versions, Data Pipelines - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/senior-product-manager-identity-user-security-airwallex-3-8030012 ## About the Role * 6+ years of Product Management experience, including leading complex, cross-functional initiatives for platform, infrastructure, or B2B products at scale. * Experience building and shipping customer- or developer-facing capabilities in domains like payments, financial services, SaaS platforms, or security/infra - ideally including access, permissions, or notifications, but not strictly required. * Strong technical fluency (APIs, services, data pipelines, observability), and the ability to go deep with engineering on architecture and trade-offs. * Demonstrated experience working in regulated or risk-sensitive environments (fintech, payments, banking, or similar), or a strong track record of quickly ramping up in complex, policy-heavy domains. * Data-driven mindset with the ability to define metrics, self-serve analyses (e.g. SQL, dashboards), and use both qualitative and quantitative insights to drive decisions. * Strong cross-functional leadership skills - you've successfully led complex, multi-team initiatives spanning Product, Engineering, Security, Risk, Compliance, Operations, and Design. * Excellent written and verbal communication - able to simplify complex technical and risk concepts for different audiences, from engineers to executives and external partners. * Track record of owning problems end-to-end, from problem framing and discovery through design, delivery, rollout, and iteration., * Experience with identity, access, or security platforms (e.g. IAM, authN/authZ, policy engines, audit/logging) or large-scale notification systems (email/SMS/push). * Background in fraud prevention, security engineering, or risk - especially in account security, abuse prevention, or incident response. * Experience building platform capabilities (APIs, services, SDKs, shared components) that are consumed by multiple product teams, including versioning, SLAs, and documentation. * Familiarity with SMS/email infrastructure and abuse vectors (including SMS pumping and phishing) and with designing mitigations that balance cost, deliverability, and security. * Experience operating at global scale, shipping features across multiple countries and regulatory regimes. Applicant Safety Policy: Fraud and Third-Party Recruiters ## Description * Lead and grow core Identity & User Security products - with an initial focus on authorization (roles, permissions, approvals) and customer/security notifications that thousands of businesses rely on every day. * Set the vision and roadmap for identity, authorization, and notifications, sequencing bets that move company-level metrics across onboarding, day-to-day usage, and recovery. * Craft best-in-class access and communications journeys that feel simple for customers while quietly doing the hard work to keep accounts safe from abuse, fraud, and account takeover. * Orchestrate cross-functional delivery with Engineering, Design, Risk, Compliance, and Data Science to ship high-quality, scalable, AI-ready platform capabilities (APIs, services, components) that can be safely consumed by AI agents, and users. * Own the global notification strategy - define what we notify, when, and via which channels to drive engagement and trust, while controlling risk and cost (including managing vectors like SMS pumping and fatigue). ## Related Videos - [No More Post-its: Boost your login security with APIs](https://www.wearedevelopers.com/videos/1043-no-more-post-its-boost-your-login-security-with-apis) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Why and when should we consider Stream Processing frameworks in our solutions](https://www.wearedevelopers.com/videos/1085-why-and-when-should-we-consider-stream-processing-frameworks-in-our-solutions) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) - [Inside Bitpanda's Tech Stack: Scaling a European Fintech Leader - Markus Dorner](https://www.wearedevelopers.com/videos/1979-inside-bitpanda-s-tech-stack-scaling-a-european-fintech-leader-markus-dorner) ## Related Articles - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)