Job Closed
This listing is no longer active.
Dropbox is the one place to keep life organized and keep work moving.
Staff Product Manager, Security
Location
United States
Posted
152 days ago
Salary
$236.3K - $319.7K / year
Seniority
Lead
Job Description
Staff Product Manager, Security
Dropbox
• Build next-generation security products – Shape and deliver innovative solutions by integrating Nira’s governance capabilities into Dropbox and driving a standalone security offering for the broader market. • Lead an AI-driven roadmap – Define and launch intelligent features that use AI and automation to streamline access control, enforce real-time DLP, and proactively detect security risks. • Expand Dropbox’s impact in the market – Identify opportunities in the SMB and mid-market security space, craft a clear product vision, and accelerate adoption with a differentiated value proposition. • Deliver breakthrough product experiences – Partner with engineering and design to launch automated access reviews, AI-powered security insights, and compliance workflows that raise the bar on security. • Turn insights into action – Work directly with customers to uncover their toughest data governance and AI security challenges, and translate those needs into high-impact product features. • Drive seamless execution – Collaborate across engineering, security, compliance, and go-to-market teams to launch products that meet global standards (SOC 2, ISO 27001, GDPR, etc.) and delight customers.
Job Requirements
- Hands-on Security Product Expertise – 10+
- years of product management experience, including 3+
- years building solutions in Access Governance, DLP, DSPM, SSPM, or AI Security.
- BS/MS in Computer Science, Engineering, Business, Information Systems, Applied Math or Statistics, or relevant experience.
- Deep Domain Knowledge – Experience tackling data and IP protection challenges, especially in Access Management and DLP for Google Workspace, Microsoft OneDrive, Dropbox, Box, or similar SaaS platforms.
- Customer-First Mindset – Passion for solving real customer pain points, with a track record of shipping security products that are powerful yet simple to use.
- Proven 0 → 1 Builder – You’ve taken security products from idea to launch, driving adoption and impact in environments ranging from enterprise SaaS to fast-moving startups.
- AI + Security Innovation – Experience applying AI/ML to security challenges—automating access controls, detecting risks, and strengthening data protection.
- Cross-Functional Partner – Comfortable working side by side with engineering, security, GTM, and legal teams, blending technical know-how with product vision to ship great outcomes.
Benefits
- Health insurance
- 401(k) matching
- Flexible work hours
- Paid time off
- Remote work options
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Lead the security review of iOS application architecture and design, ensuring security is built-in from the ground up. • Conduct security-focused code reviews for the iOS application, and implement/manage static and dynamic application security testing (SAST/DAST) tools. • Oversee the identification, assessment, and remediation of vulnerabilities within the iOS application and its supporting infrastructure. • Perform threat modeling for new features and existing components of the iOS application and its backend services. • Drive the adoption and enforcement of secure development practices within the mobile engineering teams. • Ensure the security of APIs consumed and exposed by the iOS application. • Manage and refine cloud IAM roles and permissions for the mobile app's backend infrastructure to enforce the principle of least privilege and improve our cloud security posture. • Support incident response activities related to the iOS application, including investigation and remediation. • Evaluate, implement, and manage security tools relevant to mobile application security. • Provide guidance and training to mobile developers on secure coding practices. • Report directly to the Head of Information Security on the security posture of the iOS application and related infrastructure.
Senior Security Compliance Specialist – DoD
CloudflareAt Cloudflare, we have our eyes set on an ambitious goal — to help build a better Internet.
• Lead Cloudflare through the DoD IL4 Authorization process • Manage all aspects of the DoD IL4 assessment and authorization process and Authorization maintenance • Update and maintain the DoD IL4 requirements in Cloudflare’s Common Control Framework • Work cross-functionally with Engineering, Legal, Product, and operational teams to drive security control implementation for the organization • Improve the maturity of Cloudflare’s Security Compliance program • Help guide our overall security policy and governance architecture • Have input into the overall security compliance strategy
• Design and implement security controls across cloud infrastructure, endpoints, identity systems and applications • Harden GCP environments including compute, networking, GKE, IAM and logging configurations • Deploy, configure, and maintain security tooling including SIEM, vulnerability scanners, EDR, and secrets management • Build automation for security operations, evidence collection and compliance reporting using Python, Terraform, and CI/CD pipelines • Develop and maintain logging and monitoring architecture to support detection, response, and audit requirements • Implement and enforce identity and access management controls, including SSO, MFA and least privilege access • Conduct vulnerability assessments and drive remediation efforts across infrastructure and applications • Support incident response activities including investigation, containment, and root cause analysis • Collaborate with engineering teams to integrate security into development workflows and CI/CD pipelines • Document security configurations, architecture decisions, and runbooks • Support compliance efforts by implementing technical controls required for CMMC, FedRAMP, ITAR and DFARS
Cybersecurity GRC – Compliance Analyst
Trimble Inc.Trimble technology is transforming critical industries to power an interconnected world of work.
• Perform SOC 1 & 2, NIST 800-171, ISO 27001, ISO 27701 and ISO 42001 gap analysis and recommend process, procedural, documentation and tooling recommendations to remediate. • Improve Compliance and certification scope efficiency via review and enhancements of the Trimble Common Control Framework • Perform ISO 27001 & ISO27701 Internal Audits. • Perform SOC 1 & 2, NIST 800-171 Internal & External Audits • Contribute to annual policy revisions and maintenance of the IMS. • Constantly coordinate with key business stakeholders and the external auditor • Present metrics derived from the Integrated Management System, audit results, trends in risk, and corrective action plans to senior leadership. • Contribute to the creation of processes and procedures that increase efficiency of the overall compliance program across all standards and frameworks. • Collaborate with Cybersecurity team members, Trimble businesses across various geographies. • Contribute to risk management processes to ensure business risk posture is properly calculated and proactively managed. • Produce and analyze information that will accurately demonstrate the risk posture of each business and drive actions to reduce and manage technical risks. • Be able to understand and communicate technical risks to a broad set of stakeholders.




