> Markdown version of [/jobs/ext/2733478-director-saas-cloud-product-security](https://www.wearedevelopers.com/jobs/ext/2733478-director-saas-cloud-product-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director - SaaS, Cloud & Product Security - **Company:** TALENTO, INC. - **Location:** Florence, KY, United States - **Experience:** Expert - **Salary:** $160,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software System Penetration Testing, Automation of Tests, Software as a Service, Cloud Computing, Cloud Engineering, Continuous Integration, DevOps, Key Management, Open Web Application Security, Systems Development Life Cycle, Reliability Engineering, Secure Coding, Security Software, Data Logging, Software Security, Kubernetes, Information Technology, Devsecops, Static Application Security Testing, Microservices, Dynamic Application Security Testing - **Published:** September 5, 2026 - **Apply:** https://www.careerboard.com/us/en/find-jobs-in-United-States/-FE7A8B67EE4047943A/ ## About the Role * AI-first approach to securing SaaS and cloud-native architectures (multi-tenancy, microservices, containers/Kubernetes, service meshes, CI/CD, infrastructure-as-code). * Strong application & product security fundamentals (secure design, threat modeling, secure coding patterns, API security, authn/authz, cryptography, secrets management). * Fluency with secure development frameworks and maturity models (eg, NIST SSDF practice groups and outcomes; OWASP framework, metrics-driven improvement). * Strong stakeholder influence at senior levels-able to navigate ambiguity and drive alignment across Product, Engineering, Platform/SRE, and Compliance. Experience * 8+ years in security engineering and/or product security, with significant experience in cloud and SaaS environments. * 4+ years scaling security programs across multiple products or business units. * Demonstrated success embedding security into engineering workflows (agile/DevOps) and improving release quality through automated testing and standard gates. * Track record partnering with engineering leadership to influence architecture/roadmaps and drive remediation accountability. * Experience supporting customer assurance and compliance obligations tied to secure development expectations (SSDF-aligned language helpful). Minimum Qualifications * Bachelor's degree in Computer Science, Engineering, or equivalent practical experience. * Proven people leadership experience building and scaling security teams. ## Description The Director, SaaS, Cloud & Product Security is a senior security leader responsible for helping define and executing the product security strategy across our Cloud Native SaaS platforms and cloud infrastructure. The role partners closely with Product Engineering, Product Management, SRE/Platform, and GRC/Compliance to embed security into architecture, design, development, deployment, and runtime operations-driving measurable risk reduction while enabling product velocity. This leader runs a high-performing organization that serves as trusted security advisors to product and platform teams, influencing roadmaps and ensuring accountability for remediation of cyber risks., * Help set strategy and cybersecurity operations: Along with product counterparts, execute a multi-year product/security strategy and across AI, SaaS, cloud, and product lines; establish a durable operating rhythm. * Lead the function: Operate and lead a product security organization, including hiring, coaching, and performance management * Engage directly with customers to support sales cycles: Join customer and prospect calls to speak as the security SME, helping close deals by building trust and addressing concerns while also participating in RFP/RFI responses where product security expertise is needed. * Embed security into the SDLC/DevSecOps: Ensure security is integrated into agile delivery through developer security training, design/architecture reviews, threat modeling, security user stories, automated security testing, penetration testing, and audit readiness. * Review contracts for security and compliance requirements: Evaluate customer agreements, security addendums, DPAs, and vendor contracts for alignment with internal capabilities and risk thresholds. Partner with Legal, Sales, and GRC to ensure commitments are feasible, enforceable, and do not introduce undue operational or compliance risk. * Architecture & design influence: Serve as a senior security advisor to engineering leadership; drive secure-by-design decisions for multi-tenant SaaS, APIs, identity, encryption, secrets, logging/monitoring, and tenant isolation. * Secure SDLC governance & standards: influence and help modernize secure development policies/standards, release security criteria, and definition of done expectations (eg, required SAST/DAST/SCA gates; pre-release validation). * Metrics & continuous improvement: Establish measurable outcomes and reporting frameworks to track program effectiveness (risk reduction, coverage, remediation speed, escaped defects, incident trends) and guide investment decisions. * Cross-functional partnership: Partner with product engineering groups as trusted security counterparts across architecture, design, deployment, and runtime operations; influence backlogs and roadmaps without slowing delivery. * Customer & regulatory assurance: Support customer security reviews, attestations, and compliance-driven requirements by translating expectations into practical engineering controls and evidence. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift)