Simplify Logo

Full-Time

Sr. Manager

Product Security

Updated on 9/18/2024

Smarsh

Smarsh

1,001-5,000 employees

Cloud-based archiving and compliance solutions

Data & Analytics
Hardware
Government & Public Sector
Enterprise Software
Fintech
Cybersecurity
Legal

Senior, Expert

Portland, OR, USA

Category
Cybersecurity
IT & Security
Required Skills
Kubernetes
Microsoft Azure
AWS
Google Cloud Platform
Requirements
  • A degree in Computer Science, Cybersecurity, Information Technology, or a related field.
  • Relevant cybersecurity certifications such as CISSP, CISM, CEH, or equivalent preferred.
  • 10-15 years of experience in cybersecurity or related fields.
  • At least 5 years of specific experience in product security, ideally in FinTech related roles.
  • Proven leadership skills with a minimum of 3-5 years in a managerial role, overseeing cybersecurity teams or projects.
  • In-depth knowledge of cybersecurity principles, secure coding, vulnerability management and risk assessment.
  • Proficiency in modern cloud technologies (AWS, Azure, GCP), containerization (Docker), and orchestration (Kubernetes).
  • Strong understanding of serverless computing, API security, OS hardening, SDLC and network security.
  • Strong ability to analyze and mitigate security risks and vulnerabilities.
  • Effective collaboration skills to work with cross-functional teams.
  • Commitment to staying updated with the latest security trends and technologies.
Responsibilities
  • Conduct comprehensive threat modelling to identify potential threats and vulnerabilities.
  • Perform detailed risk assessments to evaluate the impact and likelihood of risks.
  • Develop and implement secure design principles and practices.
  • Ensure secure coding practices are followed by the development teams.
  • Lead regular security testing, including static and dynamic analysis and penetration testing.
  • Evaluate and prioritize vulnerability fixes based on risk and impact.
  • Identify and eliminate false positives to streamline remediation efforts.
  • Ensure products comply with relevant security standards and regulations.
  • Maintain and update documentation and evidence of compliance.
  • Support internal and external audit processes for the product.
  • Develop and maintain product-specific incident response plans.
  • Provide expert knowledge and support to the SOC (Security Operations Center) for effective incident management.
  • Stay updated with the latest security threats, technologies, and best practices.
  • Continuously improve security practices and processes within the product development lifecycle.

Smarsh provides archiving and compliance solutions specifically designed for financial services, government agencies, and other regulated industries. Their main product is a cloud-based archive that allows organizations to securely store, search, and manage their communications data, including emails, text messages, and social media interactions. This system helps businesses meet complex security, data privacy, and regulatory requirements. Smarsh differentiates itself from competitors by offering a scalable Software-as-a-Service (SaaS) model that caters to both large enterprises and smaller organizations, ensuring that clients can adapt to evolving regulations. Their goal is to help organizations efficiently manage their communication data, identify risks, and maintain compliance, particularly through tools like Connected Capture for Microsoft Teams, which supports remote workforces.

Company Stage

Series D

Total Funding

$156.8M

Headquarters

Portland, Oregon

Founded

2001

Growth & Insights
Headcount

6 month growth

-8%

1 year growth

0%

2 year growth

-8%
Simplify Jobs

Simplify's Take

What believers are saying

  • Smarsh's strategic partnerships, such as with SOCi and Verizon, enhance its market reach and product capabilities.
  • The appointment of experienced leaders to the board and executive team positions Smarsh for robust governance and strategic growth.
  • Integration with popular tools like Microsoft Teams and OpenAI's ChatGPT ensures Smarsh remains relevant and valuable in the evolving digital communication landscape.

What critics are saying

  • The highly regulated nature of Smarsh's target industries means any compliance failures could have severe repercussions.
  • Dependence on strategic partnerships, such as with Verizon and SOCi, could pose risks if these relationships falter.

What makes Smarsh unique

  • Smarsh's focus on regulated industries like financial services and government sets it apart from competitors who target broader markets.
  • Their integration with OpenAI's ChatGPT Enterprise Compliance API showcases a commitment to leveraging cutting-edge AI for compliance solutions.
  • The partnership with Verizon's Bill-on-Behalf-of program simplifies procurement and deployment, making Smarsh's mobile capture solutions more accessible to Verizon's extensive customer base.