Candescent logo

Director of Product Security

Candescent
10 days ago
Full-time
On-site
Atlanta, Georgia, United States
AI Product Manager

Candescent is a forward-thinking technology company transforming how financial institutions deliver Intelligent Banking experiences. We unite digital banking, account opening, and branch solutions that power and connect digital banking, account opening, and branch solutionsโ€”creating seamless engagement across digital, remote, and in-person channels.

Our Experience-Led, Intelligence-Driven approach combines human-centered design with data, automation, and cloud-based innovation. Built on an API-first architecture, our extensible ecosystem enables institutions to adapt quickly, integrate easily, and unlock new opportunities for growthโ€”turning every customer interaction into a moment of clarity, confidence, and connection.

The Executiveย Director ofย Product Securityย atย Candescentย will lead the strategic direction, development, and execution of the enterprise-wideย product andย application security program with specialized focus onย Candescentโ€™sย SaaS products serving regulatedย enterprises.

This roleย is responsible forย embedding security into the software development lifecycle (SDLC) and AI development lifecycle (AIDLC), partnering with engineering, product data science, AI/ML engineering, and infrastructure teams to ensure secureย softwareย design, development, and deployment ofย Candescentย applications. The ideal candidate will be a visionary leader with deep technical expertise inย securingย softwareย developmentย lifecycles,ย shift-leftย security,ย AI/MLย applicationย security, strong business acumen, regulatory complianceย awareness, and a proven track record of building and scaling secure development practices in complex Saas and AI-driven environments.ย 

ย 

Key Responsibilities and Deliverablesย 

Strategic Leadershipย 

  • Define and drive theย product,ย application and AI/ML security strategy aligned withย Candescentโ€™sย business and riskย objectivesย for regulatedย enterprise clients.ย 

  • Lead the development and execution of secure SDLC and AI development lifecycle (AIDLC) practices across all engineering and data science teams.ย 

  • Serve as a trusted advisor to senior leadership on application security risks, AI/ML security risks,ย platform security,ย model governance, trends, and mitigation strategies.ย 

  • Participate in the establishment ofย AI security governance frameworks that meet regulatory requirements (EU AI Act, NIST AI RMF, ISO 42001).ย 

  • Develop security strategies for supply chain, third-party integrations, LLM/GenAI implementations, and SBOMย generationย (Software Bill ofย Materials).ย 

Program Development & Executionย 

  • Build and mature the application security program, including threat modeling, secure coding, code reviews, and security testing across traditional applications and AI/ML systems.ย 

  • Develop andย maintainย security standards, policies, and guidelines forย secureย application development, secure codeย repository controls,ย andย associatedย AI modelย integration.ย 

  • Oversee the integration of security tools (SAST, DAST, SCA, IAST, RASP) and AI security tools (model scanning, adversarial testing, data poisoning detection, model monitoring) into CI/CD and ML pipelines.ย 

  • Implementย industry leadingย DevSecOpsย practices and secure AI pipeline architectures.ย 

  • Establish data governance and privacy controls forย development andย training data, includingย sensitiveย dataย handling and data lineage tracking.ย 

Collaboration & Enablementย 

  • Partner withย Information Security,ย DevOps, Engineering, Data Science, ML Engineering, and Product teams to ensure security is embedded early and continuously.ย 

  • Lead security champions programsย forย developer and data scientist training initiatives to foster a security-first culture with securityย awareness.ย 

  • Collaborate with GRC, Risk, and Compliance teams to ensure regulatory and policy alignment specific to regulations and industry-specific requirementsย that apply to product and application developmentย (HIPAA, SOC 2, GDPR, CCPA,ย AI,ย etc....).ย 

  • Work closely with customer-facing teams to address clientย productย security requirements and regulatory audit needs.ย 

  • Partner with legal and compliance teams onย relevantย product security andย AIย compliance.ย 

Risk Management & Incident Responseย 

  • Identifyย and prioritize application and AI security risks through assessments, penetrationย testing, redย teamingย and threat intelligence.ย 

  • Conduct specific risk assessments including adversarial attacks,ย threatย modeling, prompt injection, data exfiltration risks, etc.ย 

  • Lead response efforts for application-related and AI security incidents and vulnerabilities.ย 

  • Provide executive-level reporting on application and AI security posture, KPIs, and risk metrics with regulatory reporting capabilities.ย 

  • Participate inย third-party vendor security assessments and AI supply chain riskย whenย .ย 

ย 

Qualifications and Experienceย 

  • Bachelorโ€™s degree in computer science, Information Technology, or equivalentย 

  • 10+ years of experience inย cloud-firstย software developmentย environmentsย with anย information securityย focus, with at least 5 years inย productย security leadership roles.ย 

  • Deep understanding of modern application architectures (e.g.ย microservices, containers, APIs, cloud-native) and AI architectures.ย 

  • Hands-on experience with secure coding practices, threat modeling, and vulnerability management including AIย specific threat modeling.ย 

  • Proficiencyย with security tools such as SAST, DAST, SCA, and container security platforms plus AI security tools.ย 

  • Strong knowledge of OWASP Top 10, OWASP ML Top 10, OWASP LLM Top 10, CWE, CVE, and secure development frameworks.ย 

  • Experience working in Agile/DevOps environments and integrating security into CI/CD and ML pipelines.ย 

  • Proven ability to lead cross-functional teams and influence at all levels of the organization.ย 

  • Deep understanding of regulatory compliance requirements for SaaS products serving highly regulated industries.ย 

ย 

Preferred Distinctionsย 

  • Advanced degree in Computer Science, Cybersecurity, or related field.ย 

  • Relevant industry certifications,ย and/orย securityย certificationsย as a plus.ย 

  • Experience with cloud security (AWS, Azure, GCP) and infrastructure-as-code security.ย 

Statement to Third Party Agencies
To ALL recruitment agencies: Candescent only accepts resumes from agencies on the preferred supplier list. Please do not forward resumes to our applicant tracking system, Candescent employees, or any Candescent facility. Candescent is not responsible for any fees or charges associated with unsolicited resumes.