Back to jobs

Director, Product Security

Portland, Oregon, USA

We are a global team of innovators and pioneers dedicated to shaping the future of observability. At New Relic, we build an intelligent platform that empowers companies to thrive in an AI-first world by giving them unparalleled insight into their complex systems. As we continue to expand our global footprint, we're looking for passionate people to join our mission. If you're ready to help the world's best companies optimize their digital applications, we invite you to explore a career with us!

Your opportunity

Do you want to drive the future of innovative product security capabilities that customers can trust to run their business? Interested in leading a stellar product security team for a rapidly scaling SaaS business? Then we're very interested in speaking with you!

Our new security leader will drive a comprehensive product security roadmap for customer trust and assurance. As a key member of the Chief Information Security Officer's staff, you will build a solid foundation for the product security ecosystem while executing on critical priorities. This is a critical leadership role for an individual who deeply understands the technical challenges of rapid product delivery and can embed security as a foundational element of our engineering culture.

You will be the vital link between Engineering, Product Management, and Security. This role will visibly represent the New Relic Security Team throughout the company, working with product managers, engineering leadership, industry thought-leaders, and customers.


What you'll do

Strategy & Execution

  • Work closely with the CISO to provide leadership for product security strategy execution, product security architecture, and the secure engineering ecosystem.
  • Help build and deliver on the CISO's vision for the growth of information security programs such as SDLC, audit logging, product security standards, security testing, and bug bounties.
  • Own and Execute the Product Security Strategy, defining a clear, actionable roadmap that aligns with business goals and reduces organizational risk.
  • Act as the principal security advisor to Engineering and Product leadership, translating high-level product strategy into technical security requirements and engineering practices.

Engineering & DevSecOps Leadership

  • Drive DevSecOps Adoption by architecting and leading the implementation of our DevSecOps program, integrating security testing, validation, and controls seamlessly into the CI/CD pipeline17.
  • Leverage deep experience with a broad range of development, build, and deploy systems (e.g., Jenkins, GitLab CI, Kubernetes) to identify and eliminate security friction points.
  • Design, implement, and run an effective Product Vulnerability Management lifecycle, from automated scanning and triage to developer remediation and verification.
  • Work directly with development teams to improve and scale secure coding practices, focusing on developer experience and automation.

Governance & Team Growth

  • Feed and grow a global security organization that motivates team members to face challenges and deliver significant work.
  • Coach and mentor managers and team members by understanding their career goals and providing opportunities for professional growth.
  • Drive security collaboration with partners in Legal, Data Compliance, and Privacy to develop and execute policy and controls related to product development, software supply chain, open-source, and mergers & acquisitions.
  • Build partnerships with product, engineering, go-to-market, and sales leaders to deliver on security initiatives.
  • Provide leadership and confidence during Product security incidents.
  • Develop and deliver internal security scorecards for use with executive and board reporting.

This role requires

  • 10+ years of technical hands-on security experience or security program management.
  • Deep Engineering Background: Substantial, hands-on experience in software engineering and development roles prior to, or integrated with, security leadership (i.e., you can speak the language of engineers).
  • Demonstrated ability leading multiple managers and teams.
  • SaaS Product Delivery Experience: Proven track record of securing rapidly scaling SaaS products delivered on cloud platforms.
  • Strong product security program planning, project management, and execution skills.
  • DevSecOps Mastery: Extensive, practical experience designing and implementing advanced DevSecOps toolchains and methodologies.
  • A background involving open-source security, vulnerability disclosure, SaaS cloud security technologies, product incident response, and a deep understanding of risk and threat assessments.
  • Experience identifying and resolving potential security issues involving compliance, mergers and acquisitions, and regulatory issues as related to Software as a Service (SaaS).
  • Demonstrated communication skills with detailed, technical information in a manner comprehensible by individuals at varying degrees of experience and skill level.

Bonus points if you have

  • Experience defining, documenting, and implementing controls required for compliance frameworks such as FedRAMP, HIPAA, and/or ISO 27001.
  • Demonstrated success with achieving cross-organizational security goals.
  • A history of publishing, public speaking, and involvement with security industry working groups.
  • Experience with assessing/building multi-year roadmaps/advancing cybersecurity program maturity.



Please note that visa sponsorship is not available for this position.

#LI-JH1

The pay range below represents a reasonable estimate of the salary for the listed position. This role is eligible for a corporate bonus plan. Pay within this range varies by work location and may also depend on job-related factors such as an applicant’s skills, qualifications, and experience.

New Relic provides a variety of benefits for this role, including healthcare, dental, vision, parental leave and planning, and mental health benefits, a 401(k) plan and match, flex time-off, 11 paid holidays, volunteer time-off, and other competitive benefits designed to improve the lives of our employees.

Estimated Base Pay Range

$224,000 - $280,000 USD

Fostering a diverse, welcoming and inclusive environment is important to us. We work hard to make everyone feel comfortable bringing their best, most authentic selves to work every day. We celebrate our talented Relics’ different backgrounds and abilities, and recognize the different paths they took to reach us – including nontraditional ones. Their experiences and perspectives inspire us to make our products and company the best they can be. We’re looking for people who feel connected to our mission and values, not just candidates who check off all the boxes. 

If you require a reasonable accommodation to complete any part of the application or recruiting process, please reach out to resume@newrelic.com.

We believe in empowering all Relics to achieve professional and business success through a flexible workforce model. This model allows us to work in a variety of workplaces that best support our success, including fully office-based, fully remote, or hybrid.

Our hiring process

In compliance with applicable law, all persons hired will be required to verify identity and eligibility to work and to complete employment eligibility verification. Note: Our stewardship of the data of thousands of customers means that a criminal background check is required to join New Relic.

We will consider qualified applicants with arrest and conviction records based on individual circumstances and in accordance with applicable law including, but not limited to, the San Francisco Fair Chance Ordinance.

Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. New Relic does not accept unsolicited headhunter and agency resumes, and will not pay fees to any third-party agency or company that does not have a signed agreement with New Relic.

New Relic develops and distributes encryption software and technology that complies with U.S. export controls and licensing requirements. Certain New Relic roles require candidates to pass an export compliance assessment as a condition of employment in any global location. If relevant, we will provide more information later in the application process.

Candidates are evaluated based on qualifications, regardless of race, religion, ethnicity, national origin, sex, sexual orientation, gender expression or identity, age, disability, neurodiversity, veteran or marital status, political viewpoint, or other legally protected characteristics. 

Review our Applicant Privacy Notice at https://newrelic.com/termsandconditions/applicant-privacy-policy

Create a Job Alert

Interested in building your career at New Relic? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...

If you do not live in the United States or Australia, please select "N/A"

Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in New Relic’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.