Product Security Lead
3 days ago
Montreal, Quebec, Canada
Miovision
Full-time
Free with email or Google
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
Free with email or Google
By continuing, you agree to our Terms & Privacy Policy.
About Miovision:
At Miovision, we’re unlocking transportation networks that move you. Our vision and mission is to enable smart, fast, safe communities that simply flow, as we drive the Intelligent Mobility Revolution. Backed by the world’s most advanced traffic AI, Miovision’s innovations in traffic signal planning and operations are making it possible for cities to improve the transportation experience for drivers, cyclists and pedestrians. Our values drive us. They’re at the core of everything we do. If they align with yours, proceed through the GREEN light
All in to win:
We're driven by a winning mindset, approaching every challenge with intensity, clarity, and speed.
One Miovision:
We succeed as one team, uniting diverse talents, building on trust, and putting our shared mission before ego.
Be better every day:
We're committed to continuous growth, staying curious, building mastery, and embracing challenges as learning opportunities.
Make it happen:
We are proactive and results-driven, taking ownership, acting with urgency, and focusing on solutions that deliver real impact.
Earn the customer:
We are deeply customer-centric, focused on earning our customers' partnership every day by delivering exceptional experiences that drive their success.
Position Summary: At Miovision, we are engineering the future of smart transportation, and to keep our infrastructure safe from digital collisions, we need a highly motivated Product Security Lead to take the wheel. Reporting directly to the Chief Information Security Officer (CISO), you will be the ultimate defensive driver for our Product Security & Engineering vertical. Your mission is to build security directly into our products, platforms, and engineering lifecycle from the ground up, ensuring we can accelerate down the fast lane of growth without ever compromising safety. You will act as the master traffic controller for product risk, fortifying our software, cloud services, and connected devices against emerging threats. If you are ready to steer our secure-by-design practices, clear the road for major enterprise deals, and ensure security is always a green light for revenue growth, buckle up and join our team Objectives and Responsibilities: Strategic Leadership:
Define, build, and lead the vision, roadmap, and operating model for Miovision’s Product Security function, acting as the primary trusted advisor to the CISO, Product, and Engineering leadership.
Secure Development (SSDLC):
Deeply embed security-by-design into the engineering lifecycle. Lead threat modeling, secure design reviews, and architectural risk assessments while partnering with Engineering to enforce secure coding and CI/CD pipeline security gates.
Cloud & Platform Fortification:
Influence cloud and platform architecture to guarantee system resilience, strict network segmentation, least privilege access, and robust defense-in-depth strategies.
Risk & Vulnerability Management:
Lead product-level risk identification and own the vulnerability management lifecycle for product code, APIs, cloud services, and embedded components, overseeing penetration testing and remediation tracking.
Go-To-Market Enablement:
Partner closely with GRC, Sales, and RevOps to crush RFPs, RFIs, and customer security reviews. Act as a technical authority in customer-facing discussions, turning our security maturity into a massive competitive differentiator.
Regulatory Translation:
Translate complex regulatory, contractual, and audit requirements (ISO 27001, SOC 2, NIST, Tx-RAMP) into highly practical, defensible, and scalable product-level security controls.
Cross-Functional Operations:
Collaborate with Security Operations and Cloud Ops to define product telemetry and logging requirements, ensuring secure-by-default deployment patterns and seamless integration into incident response workflows.
The Ideal Profile: The Security Veteran:
You bring extensive technical experience in application security, product security, secure engineering, or cloud security, ideally within SaaS or critical-infrastructure environments.
The SSDLC Master:
You have serious hands‑on experience applying Secure Software Development Lifecycle practices, including SAST/DAST integration, threat modeling, and building automated security gates into modern CI/CD pipelines.
The Framework Authority:
You are highly experienced in mapping controls to major standards like ISO 27001, SOC 2, and NIST CSF / 800-53, with a working knowledge of NIST SP 800-82 (OT/ICS Security) for connected infrastructure.
The IoT & Cloud Defender:
You have a proven track record of securing connected devices, IoT, or OT‑adjacent systems, backed by strong expertise in cloud‑native architectures (AWS p
We're driven by a winning mindset, approaching every challenge with intensity, clarity, and speed.
One Miovision:
We succeed as one team, uniting diverse talents, building on trust, and putting our shared mission before ego.
Be better every day:
We're committed to continuous growth, staying curious, building mastery, and embracing challenges as learning opportunities.
Make it happen:
We are proactive and results-driven, taking ownership, acting with urgency, and focusing on solutions that deliver real impact.
Earn the customer:
We are deeply customer-centric, focused on earning our customers' partnership every day by delivering exceptional experiences that drive their success.
Position Summary: At Miovision, we are engineering the future of smart transportation, and to keep our infrastructure safe from digital collisions, we need a highly motivated Product Security Lead to take the wheel. Reporting directly to the Chief Information Security Officer (CISO), you will be the ultimate defensive driver for our Product Security & Engineering vertical. Your mission is to build security directly into our products, platforms, and engineering lifecycle from the ground up, ensuring we can accelerate down the fast lane of growth without ever compromising safety. You will act as the master traffic controller for product risk, fortifying our software, cloud services, and connected devices against emerging threats. If you are ready to steer our secure-by-design practices, clear the road for major enterprise deals, and ensure security is always a green light for revenue growth, buckle up and join our team Objectives and Responsibilities: Strategic Leadership:
Define, build, and lead the vision, roadmap, and operating model for Miovision’s Product Security function, acting as the primary trusted advisor to the CISO, Product, and Engineering leadership.
Secure Development (SSDLC):
Deeply embed security-by-design into the engineering lifecycle. Lead threat modeling, secure design reviews, and architectural risk assessments while partnering with Engineering to enforce secure coding and CI/CD pipeline security gates.
Cloud & Platform Fortification:
Influence cloud and platform architecture to guarantee system resilience, strict network segmentation, least privilege access, and robust defense-in-depth strategies.
Risk & Vulnerability Management:
Lead product-level risk identification and own the vulnerability management lifecycle for product code, APIs, cloud services, and embedded components, overseeing penetration testing and remediation tracking.
Go-To-Market Enablement:
Partner closely with GRC, Sales, and RevOps to crush RFPs, RFIs, and customer security reviews. Act as a technical authority in customer-facing discussions, turning our security maturity into a massive competitive differentiator.
Regulatory Translation:
Translate complex regulatory, contractual, and audit requirements (ISO 27001, SOC 2, NIST, Tx-RAMP) into highly practical, defensible, and scalable product-level security controls.
Cross-Functional Operations:
Collaborate with Security Operations and Cloud Ops to define product telemetry and logging requirements, ensuring secure-by-default deployment patterns and seamless integration into incident response workflows.
The Ideal Profile: The Security Veteran:
You bring extensive technical experience in application security, product security, secure engineering, or cloud security, ideally within SaaS or critical-infrastructure environments.
The SSDLC Master:
You have serious hands‑on experience applying Secure Software Development Lifecycle practices, including SAST/DAST integration, threat modeling, and building automated security gates into modern CI/CD pipelines.
The Framework Authority:
You are highly experienced in mapping controls to major standards like ISO 27001, SOC 2, and NIST CSF / 800-53, with a working knowledge of NIST SP 800-82 (OT/ICS Security) for connected infrastructure.
The IoT & Cloud Defender:
You have a proven track record of securing connected devices, IoT, or OT‑adjacent systems, backed by strong expertise in cloud‑native architectures (AWS p