Sawell

Open role

Vice President, Product Security

Qualys

Virginia, United StatesFull Time

Qualys

Posted 2026-09-09

About the role

Come work at a place where innovation and teamwork come together to support the most exciting missions in the world! Qualifications   Leadership & Executive Management   1 2 + years of progressive experience in cybersecurity, application security, product security, cloud security, or security architecture, including   7 + years in senior leadership roles managing globally distributed security, engineering, and architecture teams.   Proven experience building, scaling, and leading high-performing Product Security organizations supporting large-scale SaaS, cloud-native, and enterprise software platforms.   Demonstrated success leading directors, senior managers, architects, and security engineering teams across multiple geographies and product portfolios.   Experience owning multi-million-dollar security budgets, strategic planning processes, headcount forecasting, vendor relationships, and security program execution.   Strong executive presence with the ability to communicate technical risk, business impact, and security strategy to Boards of Directors, Executive Leadership Teams, auditors, regulators, and customer executives.   Proven ability to influence security and product roadmaps across Engineering, Product Management, Cloud Operations, Legal, Compliance, Customer Success, Sales Engineering, and Corporate Security organizations.   Experience   participating   in M&A due diligence, product security assessments, and post-acquisition security integration activities is highly desirable.   Product Security & Secure Engineering   Deep   expertise   in product security, application security, cloud security,   DevSecOps, software supply chain security, and secure software development lifecycle (SSDLC) practices.   Demonstrated experience implementing and scaling:   Security-by-design principles   Threat modeling frameworks   Secure coding standards   Vulnerability management programs   Red teaming exercises   Bug bounty and responsible disclosure programs   Software supply chain security controls   SBOM management   Secure CI/CD pipelines   Container and Kubernetes security   Extensive knowledge of modern authentication and identity architectures including:   Zero Trust   OAuth2   OpenID Connect   SAML   PKI   Hardware-backed cryptography   Secrets management   PAM solutions   Deep understanding of modern security frameworks including:   NIST Cybersecurity Framework   NIST SP 800-53   NIST SP 800-171   NIST SP 800-218 (SSDF)   CIS Controls   OWASP Top 10   OWASP ASVS   SOC 2   ISO 27001     Federal Compliance & Government Security Experience   FedRAMP   10+ years of experience supporting U.S. federal cybersecurity programs and regulatory frameworks.   Proven experience leading, achieving, and sustaining multiple FedRAMP Moderate and FedRAMP High Authorizations to Operate (ATO) for cloud-native SaaS products.   Extensive experience working directly with:   Federal Agencies   Joint Authorization Board (JAB) stakeholders   Third Party Assessment Organizations (3PAOs)   Authorizing Officials   Government security assessors   Deep knowledge of:   NIST SP 800-53 Rev. 5   FedRAMP Continuous Monitoring   POA&M management   Significant Change Requests   Annual Assessments   Vulnerability remediation requirements   Configuration management controls   Demonstrated ownership of security strategy and product architecture supporting regulated government cloud environments.   CMMC & DoD Cloud Requirements   Hands-on experience implementing and managing environments aligned to:   CMMC Level 2 requirements   NIST SP 800-171   DFARS 252.204-7012   DFARS 252.204-7019   DFARS 252.204-7020   DFARS 252.204-7021   Experience designing and securing solutions deployed within Department of Defense environments requiring Impact Level (IL) authorization.   Demonstrated knowledge and practical experience supporting:   DoD Impact Level 4 (IL4)   DoD Impact Level 5 (IL5)   DoD Impact Level 6 (IL6)   Experience working with government customers handling Controlled Unclassified Information (CUI), National Security Systems (NSS), and classified or highly regulated workloads.   Familiarity with DISA STIGs, SRGs, DoD Cloud Computing Security Requirements Guide (CC SRG), and associated authorization processes.   NIAP & Common Criteria   Experience leading or supporting NIAP Common Criteria certification efforts for enterprise software, networking products, endpoint security solutions, or cybersecurity technologies.   Strong understanding of:   Common Criteria Evaluation and Validation Scheme (CCEVS)   Protection Profiles   Security Targets   Evaluation Assurance Levels (EAL)   NIAP product certification lifecycle   Experience working with accredited testing laboratories and certification authorities to achieve and   maintain   product certifications.     Multi-Cloud Security &   Hyperscaler   Expertise   15+ years of experience designing and securing cloud-native SaaS platforms   operating   at enterprise scale.   Demonstrated architecture and operational   expertise   across multiple hyperscale cloud service providers including:   Amazon Web Services (AWS)   Experience securing AWS environments   leveraging:    Organizations   IAM   KMS   CloudTrail   GuardDuty   Security Hub   Control Tower   ECS/EKS   Native compliance controls   Microsoft Azure   Experience securing Azure environments   utilizing:    Entra ID   Azure Policy   Defender for Cloud   Key Vault   Azure Monitor   Microsoft Sentinel   AKS   Landing Zone architectures   Google Cloud Platform (GCP)   Experience designing secure GCP architectures   leveraging:    Cloud IAM   Security Command Center   Cloud KMS   Anthos   Chronicle   Organization Policies   GKE security controls   Oracle Cloud Infrastructure (OCI)   Experience securing OCI environments including:   OCI IAM   OCI Vault   Cloud Guard   Security Zones   OCI Logging   OCI Container Engine for Kubernetes (OKE)   Experience developing governance models and security architectures across multi-cloud and hybrid-cloud environments.   Demonstrated   track record   implementing consistent security controls, monitoring, identity governance, and compliance frameworks across AWS, Azure, GCP, and OCI.     Preferred Qualifications   CISSP, CCSP, GIAC, SABSA, or equivalent advanced security certifications.   Prior experience serving as:   VP Product Security   Head of Product Security   Chief Product Security Officer   Distinguished Security Architect   Senior Security Executive within a cybersecurity or cloud technology company.   Experience working in publicly traded technology organizations and interacting with Audit Committees and Board-level Cybersecurity Committees.   Experience supporting enterprise cybersecurity products, vulnerability management platforms, endpoint security solutions, cloud security tools, SIEMs, or security operations technologies.   Qualys is an Equal Opportunity Employer, please see our EEO policy.

AI apply unlocks in the Sawell app

Prefer desktop? Sign in on web

Related roles

View more

Powered by Xiaojia Cai

Vice President, Product Security at Qualys — Virginia, United States | Sawell