Jobs and Careers
MI

Director Security Engineering

Miro
The Netherlandsfull_timeVerifiedPosted 25 Jun 2025

About the role

About the Team

The primary objective of the Head of Product Security role is to prevent security breaches, feature abuse, and compliance non-conformities that could result in financial loss, reputational damage, or failure to achieve Miro’s business objectives by ensuring that security, privacy, compliance, and misuse risks are systematically identified and mitigated throughout the Product Development Life Cycle—integrated into Miro’s AMPED (Analytics & Marketing & Product & Engineering & Design) Ways of Working and Operating Model. The role enables secure and compliant product development to support the successful delivery of Miro's business objectives.

About the Role

The Head of Product Security is responsible for defining and managing Miro’s product security strategy, with a primary focus on embedding security, privacy, and abuse-prevention practices throughout the Product Development Life Cycle (PDLC)—spanning the Discover, Define, and Deliver phases. The PDLC is embedded within Miro’s AMPED Ways of Working (WoW) and AMPED Operating Model, and this role ensures that product teams apply consistent security considerations as part of how products are scoped, shaped, and shipped.

The position includes responsibility for enabling product teams to identify and mitigate both technical risks and misuse scenarios, where legitimate product functionality could be abused for malicious purposes (e.g., phishing, data leakage, account enumeration). The Head of Product Security sets expectations for risk ownership and ensures that non-functional security requirements are integrated into product delivery frameworks.

This role reports directly to the Chief Information Security Officer (CISO) and collaborates closely with Product, Engineering, Application Security, Privacy, Legal, and Compliance functions.

What you’ll do

  • Define and maintain a product security governance framework aligned with the Discover, Define, Deliver phases of the PDLC, as structured within the AMPED Ways of Working and Operating Model.
  • Establish clear ownership models assigning product managers accountability for identifying, documenting, and mitigating security and abuse risks.
  • Lead the development of security guidance, policy, and review processes tailored to each PDLC phase within the AMPED framework.
  • Implement methods for identifying both traditional vulnerabilities and abuse of functionality, where users exploit legitimate features for malicious purposes.
  • Specify non-functional security requirements to be considered in product requirements, architecture, and delivery checkpoints.
  • Collaborate with Product teams to incorporate threat modeling, misuse case analysis, and privacy risk assessments into the Discover and Define stages.
  • Coordinate with Application Security to ensure alignment of secure software development practices with broader product strategy and roadmaps.
  • Maintain tooling, documentation, and checklists to support structured product security reviews and approvals.
  • Integrate compliance, privacy, and regulatory requirements (e.g., GDPR, DSA, AI Act) into product planning and delivery processes.
  • Develop and deliver education programs to raise awareness of product misuse risks and the responsibility of product teams to mitigate them.
  • Participate in product strategy reviews, roadmap reviews, and high-risk feature assessments, providing security input and risk-based recommendations.
  • Define and report on product security KPIs and maturity metrics aligned with AMPED governance forums and risk review processes.
  • Act as a point of contact for internal audit, security certifications, and external customer assurance related to product-level security risks.
  • Drive continuous improvement in security integration by incorporating learnings from incidents, threat intelligence, and peer benchmarks into the PDLC.
  • Ensure alignment of all product security activities with Miro’s AMPED cross-functional execution model, enabling scalable and repeatable secure product development practices.

What you’ll need

  • 10+ years of experience in information security, with a strong focus on software and product security.
  • 5+ years of leadership experience in a security function, with a proven track record of building and mentoring high-performing teams.
  • Deep expertise in Secure Software Development Lifecycles (SSDLC), including integrating security into agile and custom development frameworks.
  • Extensive experience with threat modeling methodologi

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Miro

View company profile →