Full-Time

Sr. Manager

Product Security

Posted on 8/23/2024

Smarsh

Smarsh

1,001-5,000 employees

Archiving and compliance solutions provider

Enterprise Software
Cybersecurity
Financial Services

Senior, Expert

Portland, OR, USA

Hybrid position in Portland.

Category
Cybersecurity
IT & Security
Required Skills
Kubernetes
Microsoft Azure
AWS
Google Cloud Platform
Requirements
  • A degree in Computer Science, Cybersecurity, Information Technology, or a related field.
  • Relevant cybersecurity certifications such as CISSP, CISM, CEH, or equivalent preferred.
  • 10-15 years of experience in cybersecurity or related fields.
  • At least 5 years of specific experience in product security, ideally in FinTech related roles.
  • Proven leadership skills with a minimum of 3-5 years in a managerial role, overseeing cybersecurity teams or projects.
  • In-depth knowledge of cybersecurity principles, secure coding, vulnerability management and risk assessment.
  • Proficiency in modern cloud technologies (AWS, Azure, GCP), containerization (Docker), and orchestration (Kubernetes).
  • Strong understanding of serverless computing, API security, OS hardening, SDLC and network security.
  • Strong ability to analyze and mitigate security risks and vulnerabilities.
  • Effective collaboration skills to work with cross-functional teams.
  • Commitment to staying updated with the latest security trends and technologies.
Responsibilities
  • Conduct comprehensive threat modelling to identify potential threats and vulnerabilities.
  • Perform detailed risk assessments to evaluate the impact and likelihood of risks.
  • Develop and implement secure design principles and practices.
  • Ensure secure coding practices are followed by the development teams.
  • Lead regular security testing, including static and dynamic analysis and penetration testing.
  • Evaluate and prioritize vulnerability fixes based on risk and impact.
  • Identify and eliminate false positives to streamline remediation efforts.
  • Ensure products comply with relevant security standards and regulations.
  • Maintain and update documentation and evidence of compliance.
  • Support internal and external audit processes for the product.
  • Develop and maintain product-specific incident response plans.
  • Provide expert knowledge and support to the SOC (Security Operations Center) for effective incident management.
  • Stay updated with the latest security threats, technologies, and best practices.
  • Continuously improve security practices and processes within the product development lifecycle.

Smarsh provides archiving and compliance solutions specifically designed for financial services, government agencies, and other regulated industries. Their main product is a cloud-based archive that allows organizations to securely store, search, and manage their communications data, including emails, text messages, and social media interactions. This system helps businesses meet complex security, data privacy, and regulatory requirements. Smarsh differentiates itself from competitors by offering a scalable Software-as-a-Service (SaaS) model that caters to both large enterprises and smaller organizations, ensuring that clients can adapt to evolving regulations. Their goal is to help organizations efficiently manage their communication data, identify risks, and maintain compliance, particularly through tools like Connected Capture for Microsoft Teams, which supports remote workforces.

Company Stage

Acquired

Total Funding

$42.4M

Headquarters

Portland, Oregon

Founded

2001

Growth & Insights
Headcount

6 month growth

2%

1 year growth

2%

2 year growth

-3%
Simplify Jobs

Simplify's Take

What believers are saying

  • Smarsh's global expansion includes a new office in Costa Rica for enhanced support.
  • Integration with OpenAI's ChatGPT API enhances Smarsh's AI compliance capabilities.
  • Partnership with Verizon simplifies mobile compliance procurement for Verizon's clients.

What critics are saying

  • Integration with OpenAI's API may pose compliance and security challenges.
  • EU's AI Act requires significant adjustments to Smarsh's AI systems.
  • Expansion into Latin America may expose Smarsh to regional instability.

What makes Smarsh unique

  • Smarsh offers cloud-native, context-aware archiving solutions for regulated industries.
  • The company integrates with popular tools like Microsoft Teams for seamless compliance.
  • Smarsh serves 9 of the top 10 banks, showcasing its industry trust.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Life Insurance

Disability Insurance

Unlimited Paid Time Off

Paid Vacation

Paid Sick Leave

Paid Holidays

Hybrid Work Options

Stock Options

401(k) Company Match

Employee Assistance Programme

Wellness Program

Adoption Assistance

Group Income Protection

Group Life Assurance

Maternity Leave

Paternity Leave

Workplace Pension Scheme

Monthly Wellness Allowance

Company Bonus

INACTIVE