Director, Product Security

Crunchyroll - Los Angeles, CA

Hiring: Director, Product Security Company: Crunchyroll Location: Los Angeles, CA Job Posted Time: 2026-09-10 11:06:31 Target Skills & Keywords : API Design, Android, CI/CD, Embedded Systems, IAM, Risk Management, iOS About the job Experience: •12+ years of progressive experience in information security, application security, cloud security, or software engineering, including significant experience leading enterprise-scale security initiatives through technical influence rather than direct authority. Required Skills: •Vulnerability closure and systemic risk reduction: Facilitate the operating rhythm across engineering for vulnerability intake, triage, tracking of vulnerability ownership, SLAs, remediation planning, verification, and escalation. Establish systems and processes that ensure timely fixes and eliminate repeat issues through improvements. •Tooling integration and evidence readiness: Coordinate with engineering teams to integrate enterprise security tooling into CI/CD and production environments, and ensure engineering can reliably produce evidence of compliance in a low-friction, automated way. •Design-time security embedded in engineering workflows: Ensure threat modeling and security architecture considerations are built into how engineering designs and ships using approved patterns and reference architectures as the default starting point. •Pragmatic requirements shaping: When requirements are infeasible or disproportionately costly, you’ll drive early escalation and propose alternatives (sequencing, compensating controls, platform changes) so we maintain momentum without accepting unmanaged risk. •Cross-team alignment and escalation: Identify cross-domain architectural risks and drive alignment / decision-making through established engineering leadership and architecture governance processes, bringing the right stakeholders together and escalating when tradeoffs require executive judgment. •Incident readiness and closure: Improve security incident preparedness in engineering (runbooks, exercises, detection hooks) and ensure post-incident actions translate into durable engineering improvements. •Drive enterprise-wide adoption of Security and Privacy by Design, ensuring security, privacy, and compliance requirements are proactively integrated into products, services, and technology platforms •Security controls are implemented broadly with minimal friction because the secure path is well defined Qualifications: •We get excited about candidates like you, because … •You have 12+ years of progressive experience in information security, application security, cloud security, or software engineering, including significant experience leading enterprise-scale security initiatives through technical influence rather than direct authority. •You exhibit Principal-level technical leadership with a proven track record of leading cross-team security initiatives through influence, clarity, and shipping real systems—not just policies. •You possess strong application security fundamentals such as: authn/authz, session security, secure API design, data protection, threat modeling, and secure SDLC practices. •You have pragmatic risk management, with the ability to prioritize, quantify tradeoffs, and create guardrails that teams actually adopt. •You have cloud & platform security experience such as: IAM concepts, secrets management, key management, service-to-service auth patterns, and logging/detection fundamentals. •You possess a DevSecOps and automation mindset and have experience integrating security checks into CI/CD with minimal developer friction. •You exhibit depth in vulnerability management, knowing how to triage, develop remediation strategies, verify fixes, all while partnering with teams to close the loop quickly. •You possess excellent communication skills that include concise, executive-ready writing and strong technical coaching abilities for engineers. •You meet people where they are and endeavor to build intrinsic motivation to develop solutions to problems through shared understanding. Compensation: •$249,000 - $305,000 / year •Receive a great compensation package including salary plus performance bonus earning potential, paid annually Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!