G

GitHub

Code hosting, review, CI/CD collaboration platform

Outbound Product Manager - GitHub Advanced Security

Full-TimeDeadline 4/28/27
$140.4k - $372.3k/yr+ Annual bonus + Stock + Sales incentives
Senior
Bachelor's
Remote in USA
Remote

About the job

Requirements
  • At least 8 years of experience in product, service, project or program management, software development, product design, or a related field; alternatively, a Bachelor's Degree in Computer Science, Engineering, Business, or a related field with at least 6 years of the same experience, or equivalent experience.
  • Experience creating high-quality technical content, including blog posts, demos, presentations, and technical deep-dives, at a sustained cadence.
  • Experience in developer tools, developer platforms, DevOps, or application security product domains.
  • Experience with artificial intelligence or machine-learning-powered product go-to-market, particularly in developer or security workflows.
Responsibilities
  • Translate GitHub's agentic security platform story into audience-specific value propositions, articulating risk reduction and compliance for CISOs, platform consolidation and architecture for CTOs, workflow integration and developer experience for engineers, and return on investment and cost efficiency for CFOs.
  • Become a recognized voice in the application security and developer security community by building a personal and product advocacy presence online, publishing original perspectives, engaging with practitioners and security leaders, shaping industry conversations, and positioning GitHub as an authority on application security.
  • Build and deliver competitive narratives using data, benchmarks, and real-world customer evidence, and translate GitHub's integrated platform advantage into public-facing content.
  • Represent GitHub's security vision at executive business center events, analyst briefings, industry events, and customer advisory boards, and scale executive business center and analyst engagement programs.
  • Enable the sales organization as new capabilities launch by connecting product innovations to the broader platform story and equipping the field with narrative, demos, and technical depth for customer conversations.
  • Drive the public narrative around GitHub Advanced Security's transformation into an agentic security platform by creating technical content such as blog posts, demos, deep-dives, customer stories, and open-source proof points.
  • Synthesize market signals from customer engagements, competitive developments, and field intelligence into actionable insights that influence product roadmap priorities and go-to-market strategy.
Desired Qualifications
  • Hands-on experience with application security concepts and tools, including static analysis, secret detection, and software composition analysis.
  • A track record of building personal or product thought leadership through public content, social media, and conference speaking.
  • Experience developing competitive positioning against well-funded competitors in fast-moving markets.
  • Experience communicating technical products to mixed audiences and tailoring the same product story for practitioners, security leaders, and executive buyers.
  • Experience presenting at industry events, executive briefings, or analyst engagements.

About the company

GitHub hosts code, coordinates collaboration, and tracks work for software development. Developers push code to repositories, create pull requests for review, and automate builds and deployments with GitHub Actions. It offers cloud-hosted and self-hosted options, plus advanced security and administration for large teams, all integrated with Microsoft's developer and cloud ecosystem. Its goal is to help teams build high-quality software by enabling transparent collaboration and automated delivery across a wide set of tools.

Company Size

5,001-10,000

Company Stage

Acquired

Total Funding

$350M

Headquarters

San Francisco, California

Founded

2008

Get referred to GitHub

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Microsoft reported 4.7 million paid Copilot subscribers in Q2 FY26, up 75% year-over-year.
  • GitHub shipped npm staged publishing on May 22, 2026, hardening its security platform.
  • GitHub’s August 2026 Copilot policy changes increase upfront monetization and usage-based expansion revenue.

What critics are saying

  • September 2026 Copilot billing changes raise friction, triggering churn among cost-sensitive enterprise admins.
  • Repeated 2026 outages and Azure migration strain make GitHub unreliable for production engineering teams.
  • Open-source supply-chain attacks on Microsoft repositories expose existential trust risk if GitHub loses developer confidence.

What makes GitHub unique

  • GitHub owns the default collaboration layer for 100 million registered developers, entrenched by network effects.
  • Copilot and npm bundle code generation with repository hosting, reviews, and supply-chain controls.
  • Microsoft keeps GitHub inside Azure, M365, and security workflows, strengthening enterprise distribution.

Help us improve and share your feedback! Did you find this helpful?

Benefits

A diverse and inclusive workplace - At GitHub, we think that a diverse company is a strong company, and we work hard to foster a supportive and welcoming workplace. Learn more about our commitment to diversity.

Work happier - Build amazing things with a balance of autonomy and collaborative teamwork. Set your own work schedule and make use of a flexible PTO plan when you need to recharge.

Lead from any location - GitHub is a remote-first company with offices located throughout the US, Europe, and Asia. Whether you live near an office or not, GitHub believes you can do your best work wherever you are. If you work remotely, you will receive a stipend to outfit your home office and receive reoccurring reimbursement refreshes.

Put your health and family first - You’ll enjoy 100% coverage of health insurance premiums across our medical, dental, and vision plan offerings, including coverage for dependents. We also offer five months of paid family leave to all new parents with the option to use it all at once or throughout the baby’s first year.

Find your zen - GitHub provides a monthly wellness stipend designed to cover anything from gym memberships, massage, meditation apps, or any other wellness related expenses.

Invest in your future - At GitHub, you’ll have a stake in the future success of our platform with equity grants. For full-time employees, we offer competitive 401k planning with a 50% company match up to the IRS 402(g) annual limit.

Keep growing - Learn how you learn best. From books to conferences, you’ll get a yearly budget for your individual learning and development goals.

Give back to your community - We believe in sharing our time, resources, and products to contribute to positive social impact. GitHub matches charitable donations up to $15,000 per calendar year. And for each hour (up to 40 hours) of volunteering per year, you will receive $20 to donate to an organization of your choice.

Growth & Insights and Company News

Headcount

6 month growth

↓ -2%

1 year growth

↑ 0%

2 year growth

↓ -1%
The Register
Sep 23rd, 2026
Jev-powered Slop Mop Chrome extension filters AI and human garbage from LinkedIn feeds

A new Chrome extension called Slop Mop aims to filter low-quality content from LinkedIn feeds, whether written by humans or AI. Released Tuesday by business consultant Tom Frazier, the open-source tool is free and requires no signup. The extension uses Jev, a probabilistic decision-making AI model from TypeSafe released last week. It evaluates posts based on nine indicators derived from research by SEO firm Graphite Growth, including excessive hype words, engagement bait, and flowery language. Slop Mop flags or hides posts meeting its threshold without removing them from feeds. The tool can analyse up to 250 posts daily per installation. Frazier developed it primarily to test Jev's capabilities, covering usage costs himself at approximately $0.005 per user daily. The extension is available on GitHub and the Chrome Web Store.

TechCrunch
Aug 18th, 2026
Cursor launches Origin code hosting platform as Github suffers outages

Cursor, now part of SpaceXAI, has launched Origin, a new code hosting platform designed to rival GitHub. The platform enables developers to collaborate on codebases, manage pull requests, and store repositories. Origin works alongside GitHub, allowing users to sync repositories between both platforms rather than forcing a complete switch. The launch comes amid mounting frustration over GitHub's reliability issues. The platform has experienced 257 outages over the past year, including a six-hour worldwide outage on the same day Origin launched. Despite these challenges, GitHub remains dominant with 180 million developers using the Microsoft-owned platform as of October. Cursor says "agent native" features and a broader app ecosystem will be added to Origin soon, though details remain limited.

The Register
Jul 23rd, 2026
ChatGPT Business users gain unofficial export tool after OpenAI blocks standard data access

OpenAI does not allow ChatGPT Business and Enterprise users to export their workspace chats through its standard data export option, prompting freelance journalist Conrad Quilty-Harper to create an unofficial solution. Quilty-Harper published scrapemychats on GitHub this week, a free tool that enables affected subscribers to retrieve their chat records. The tool works through a logged-in browser session, storing conversations and attachments in a local archive with an HTML interface that can be accessed offline. OpenAI's help page confirms that Free, Plus, Pro, and some Edu customers can export chats, whilst Business and Enterprise workspaces lack this functionality. Enterprise admins can access logs through OpenAI's Compliance Platform, but these are retained for only 30 days. The tool navigates through ChatGPT accounts and downloads conversation data, though the process is slow due to OpenAI's throttling measures.

Associated Press
Jun 17th, 2026
42Crunch launches API security testing plugin for GitHub Copilot to address AI-generated code vulnerabilities

42Crunch has launched an API Security Testing Plugin for GitHub Copilot, enabling developers to audit, test and remediate API security vulnerabilities within AI-assisted development workflows. The plugin addresses growing concerns that AI-generated code often contains security flaws, with Veracode reporting 45% of AI-generated code includes known OWASP Top 10 vulnerabilities. The plugin continuously audits OpenAPI specifications, detects security vulnerabilities, identifies OWASP API Security Top 10 risks, and provides AI-assisted remediation guidance. It aims to ensure security validation scales alongside AI-assisted development rather than becoming a bottleneck. CEO Jacques Declas stated organisations need "deterministic security guardrails that can validate, govern and remediate API security issues at the same speed AI generates them". The plugin is now available to 42Crunch's user base of over two million developers.

The Register
May 21st, 2026
Npm registry adds approval gate to block compromised package distribution

GitHub's npm package registry has introduced staged publishing, a security measure requiring maintainer approval before package distribution. The feature, now merged into npm CLI v11.15.0, addresses supply chain vulnerabilities where attackers compromise maintainer accounts to distribute malware through widely used packages. Staged publishing allows developers to submit packages to a staging area using "npm stage publish" rather than publishing directly. A maintainer must then review and approve the package via two-factor authentication before it becomes publicly available. The feature particularly benefits automated workflows, which typically lack 2FA authorization and rely on tokens that can be stolen. Combined with GitHub's trusted publishing using OpenID Connect authentication, staged publishing strengthens the software supply chain, provided developers implement these tools.