Zeta Global logo
Zeta GlobalPosted 3 weeks ago

Senior Product Manager, Application Security

$170,000–$185,000 year

On-siteSan Francisco, California, United States

Full TimeSenior LevelLargeMarketing Technology

Job Summary

Own the Application Security product strategy and multi-quarter roadmap, driving delivery of an enterprise-grade capability that protects the platform while enabling engineering teams to ship with confidence. Build and ship core product surfaces including AI-powered threat modeling, code evaluation, and a unified security risk and remediation platform. Prioritize critical risk surfaces across the Zeta platform and define clear requirements, user stories, and success metrics for AppSec capabilities. Drive day-to-day execution with Application Security, platform/DevOps, Architecture, and InfoSec teams to establish governance frameworks, incident intake processes, and secure coding standards. Lead tool strategy and procurement decisions with clear risk justification, aligning initiatives with company objectives and communicating risk to executive stakeholders. Use data and KPIs to measure posture and inform prioritization, running post-incident loops to convert findings into durable product and process improvements. Mentor Security Champions and scale the program across the organization while comfortably using AI tools for threat modeling, triage, and code review guidance.

Required Qualifications

  • 4-6+ years of product management experience
  • meaningful ownership of enterprise Application Security, platform security, DevSecOps, or adjacent security-product domains in SaaS/B2B environments
  • Deep working knowledge of modern AppSec practices and tooling (SAST, DAST, SCA, container/IaC/secrets scanning, vulnerability management, threat modeling, API security, and secure SDLC)
  • Proven ability to drive enterprise-tier security programs: risk-based prioritization, remediation SLAs, cross-org governance, and executive risk communication—not only feature delivery
  • Strong technical background (Computer Science or related field preferred)
  • credible with security engineers, architects, and engineering leaders on topics such as authn/authz, multi-tenancy, cryptography boundaries, supply chain, and AI/LLM security risks
  • Demonstrated experience shipping developer-facing security products or workflows (CI/CD gates, IDE/MR integrations, security dashboards, or remediation orchestration)
  • Excellent communication and stakeholder influence skills across Engineering, InfoSec, DevOps/Infrastructure, Architecture, and leadership
  • Proven ability to work independently in ambiguity while building durable process, metrics, and operating cadence

Desired Qualifications

  • Experience building or operating AI-assisted security capabilities (threat modeling automation, AI code review, exploitability/reachability-informed triage, or unified findings platforms)
  • Familiarity with MarTech/AdTech or other high-scale multi-tenant platforms handling sensitive customer data
  • Experience with tool evaluation and vendor management for AppSec platforms (e.g. Snyk, Wiz, Rapid7, or equivalents)

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce