Back to jobs
New

Senior Product Manager, Application Security

Remote - United States

WHO WE ARE 

Zeta Global (NYSE: ZETA) is the AI-Powered Marketing Cloud that leverages advanced artificial intelligence (AI) and trillions of consumer signals to make it easier for marketers to acquire, grow, and retain customers more efficiently. Through the Zeta Marketing Platform (ZMP), our vision is to make sophisticated marketing simple by unifying identity, intelligence, and omnichannel activation into a single platform – powered by one of the industry’s largest proprietary databases and AI. Our enterprise customers across multiple verticals are empowered to personalize experiences with consumers at an individual level across every channel, delivering better results for marketing programs. Zeta was founded in 2007 by David A. Steinberg and John Sculley and is headquartered in New York City with offices around the world. To learn more, go to www.zetaglobal.com.

About the Role

We are seeking a Senior Product Manager, Application Security to own Zeta’s Application Security product and program end-to-end. You will set strategy, prioritize the roadmap, and drive delivery of an enterprise-grade AppSec capability that protects Zeta’s platform, data, and customers, while enabling engineering teams to ship with confidence.

This role sits at the intersection of product, security, and platform engineering. You will turn our Application Security vision into a system based on secure-by-design practices across the SDLC, AI-assisted threat modeling and code review, CI/CD enforcement, vulnerability prioritization and remediation at scale, and executive-ready risk visibility. Success means security is invisible when it should be, and highly visible when it must be.

Responsibilities

  • Own the Application Security product strategy and multi-quarter roadmap—from visibility and tooling inventory, through architecture and risk-surface mapping, tool procurement and upgrades, CI/CD enforcement, proactive threat reduction, and scaled institutionalization (Security Champions, architecture review, executive reporting).
  • Build and ship the core AppSec product surfaces: AI-powered threat modeling and code evaluation, and a unified security risk, signal, and remediation platform.
  • Prioritize critical risk surfaces across the Zeta platform.
  • Define clear requirements, user stories, success metrics, and acceptance criteria for AppSec capabilities.
  • Drive day-to-day execution with Application Security engineering, platform/DevOps, Architecture, InfoSec, and product engineering pods.
  • Establish and evolve governance: severity and SLA frameworks, incident intake and escalation, secure coding standards, third-party application integration guardrails, and architecture security review for high-risk changes.
  • Lead tool strategy and procurement decisions with clear risk justification, coverage gaps, budget tradeoffs, and integration into developer workflows.
  • Use data and KPIs to measure posture and inform prioritization.
  • Align AppSec initiatives with company objectives; communicate risk, progress, and asks clearly to engineering and executive stakeholders.
  • Identify and mitigate delivery and security risks; run post-incident learning loops that convert findings into durable product and process improvements.
  • Mentor and elevate AppSec and adjacent product/engineering partners; help scale a Security Champions program across the organization.
  • Comfortably use AI tools as part of everyday product work, and productize AI defensively for threat modeling, triage, code review, and remediation guidance with appropriate human oversight.

Qualifications

  • 4-6+ years of product management experience, with meaningful ownership of enterprise Application Security, platform security, DevSecOps, or adjacent security-product domains in SaaS/B2B environments.
  • Deep working knowledge of modern AppSec practices and tooling (SAST, DAST, SCA, container/IaC/secrets scanning, vulnerability management, threat modeling, API security, and secure SDLC).
  • Proven ability to drive enterprise-tier security programs: risk-based prioritization, remediation SLAs, cross-org governance, and executive risk communication—not only feature delivery.
  • Strong technical background (Computer Science or related field preferred); credible with security engineers, architects, and engineering leaders on topics such as authn/authz, multi-tenancy, cryptography boundaries, supply chain, and AI/LLM security risks.
  • Demonstrated experience shipping developer-facing security products or workflows (CI/CD gates, IDE/MR integrations, security dashboards, or remediation orchestration).
  • Excellent communication and stakeholder influence skills across Engineering, InfoSec, DevOps/Infrastructure, Architecture, and leadership.
  • Proven ability to work independently in ambiguity while building durable process, metrics, and operating cadence.


Preferred Skills

  • Experience building or operating AI-assisted security capabilities (threat modeling automation, AI code review, exploitability/reachability-informed triage, or unified findings platforms).
  • Familiarity with MarTech/AdTech or other high-scale multi-tenant platforms handling sensitive customer data.
  • Experience with tool evaluation and vendor management for AppSec platforms (e.g. Snyk, Wiz, Rapid7, or equivalents).


What We’re Looking For

  • A proactive owner who can run Application Security as a product and a program: curious, decisive, and ready to tackle complex enterprise risk.
  • Someone who thrives in ambiguity, takes end-to-end ownership, and converts strategy into measurable reduction of platform risk.
  • A partner to engineering who values pragmatic, risk-based tradeoffs and continuous improvement over checkbox security.
  • A leader who can make security scalable through automation, clear standards, and AI-native workflows—without becoming a bottleneck.

BENEFITS & PERKS

  • Unlimited PTO
  • Excellent medical, dental, and vision coverage
  • Employee Equity
  • Employee Discounts, Virtual Wellness Classes, and Pet Insurance And more!!

SALARY RANGE

The salary range for this role is $170,000 - $190,000, depending on location and experience. 

PEOPLE & CULTURE AT ZETA

Zeta considers applicants for employment without regard to, and does not discriminate on the basis of an individual’s sex, race, color, religion, age, disability, status as a veteran, or national or ethnic origin; nor does Zeta discriminate on the basis of sexual orientation, gender identity or expression.  

We’re committed to building a workplace culture of trust and belonging, so everyone feels invited to bring their whole selves to work. We provide a forum for employees to celebrate, support and advocate for one another. Learn more about our commitment to diversity, equity and inclusion here:  https://zetaglobal.com/blog/a-look-into-zetas-ergs/ 

ZETA IN THE NEWS!

https://zetaglobal.com/press/?cat=press-releases 

 

#LI-TS1

 

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...

Voluntary Demographic Questions

Zeta collects this Voluntary Demographic Data only with your consent, for the sole purpose of tracking and improving the diversity of our applicant pool. Any information you choose to provide will not be considered for employment purposes, will not be associated with your employment at Zeta if you are offered a position, and is not used to make hiring or employment decisions.  This data will be maintained unless you withdraw your consent. You may withdraw consent for this data to be maintained by Zeta at any time by contacting your Recruiter. If and when you are employed by Zeta, you may withdraw consent by contacting your HR Partner. If and when you onboard with Zeta, you will also be asked to complete an EEOC questionnaire that collects additional demographic data in order for Zeta to meet its legal requirements.

We are committed to building diverse teams with different identities, backgrounds and perspectives. We believe in providing a forum to connect at Zeta, to learn and celebrate differences. Our mission is to ensure we have an environment that enables a deep level of trust and belonging, so everyone feels invited to bring their whole selves to work, and to increase both diversity at Zeta as well as in the technology industry.  

Zeta considers applicants for employment without regard to, and does not discriminate on the basis of an individual’s sex, race, color, religion, age, disability, status as a veteran, or national or ethnic origin, or any other basis protected by applicable federal, state or local law; nor does Zeta discriminate on the basis of sexual orientation or gender identity or expression.  

Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Zeta Global’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.