ACV is a technology company that has revolutionized how dealers buy and sell cars online. We are transforming the automotive industry. ACV Auctions Inc. (ACV) has applied innovation and user-designed, data-driven applications and solutions. We are building the most trusted and efficient digital marketplace with data solutions for sourcing, selling, and managing used vehicles with transparency and comprehensive insights that were once unimaginable. We are disruptors of the industry and we want you to join us on our journey.
Director, Product Security
Location
United States
Posted
71 days ago
Salary
$178K - $220K / year
Seniority
Lead
Job Description
Director, Product Security
ACV
If you are looking for a career at a dynamic company with a people-first mindset and a deep culture of growth and autonomy, ACV is the right place for you! Competitive compensation packages and learning and development opportunities, ACV has what you need to advance to the next level in your career. We will continue to raise the bar every day by investing in our people and technology to help our customers succeed. We hire people who share our passion, bring innovative ideas to the table, and enjoy a collaborative atmosphere. Who we are: ACV is a technology company that has revolutionized how dealers buy and sell cars online. We are transforming the automotive industry. ACV Auctions Inc. (ACV), has applied innovation and user-designed, data driven applications and solutions. We are building the most trusted and efficient digital marketplace with data solutions for sourcing, selling and managing used vehicles with transparency and comprehensive insights that were once unimaginable. We are disruptors of the industry and we want you to join us on our journey. Our network of brands include ACV Auctions, ACV Transportation, ClearCar, MAX Digital and ACV Capital within its Marketplace Products, as well as, True360 and Data Services. At ACV we focus on the Health, Physical, Financial, Social and Emotional Wellness of our Teammates and, to support this, we offer: - Multiple medical plans including a high deductible, low cost health plan - Company-sponsored (paid) Short-Term Disability, Long-Term Disability, and Life Insurance - Comprehensive optional benefits such as Dental, Vision, Supplemental Life/AD&D, Legal/ID Protection, and Accident and Critical Illness Insurance - Generous paid time off options, including uncapped vacation days, the greater of 3 paid sick days or in accordance with the applicable state or local paid sick leave law, 6 paid company holidays, 2 floating holidays, parental leave, bereavement leave, jury duty leave, voting leave, and other forms of paid leave as required by applicable law or regulation - Employee Stock Purchase Program with additional opportunities to earn stock in the Company - Retirement planning through the Company’s 401(k) Who we are looking for: The Director of Product Security is a critical leadership role responsible for the overall security posture of ACV’s software applications and platforms. Reporting directly to the CISO, this individual will own and mature the entire Product and Application Security program, integrating security practices throughout the Secure Software Development Lifecycle (SSDLC). This position requires a self-motivated and highly organized leader with excellent communication and technical skills. The Director will ensure the confidentiality, integrity, and availability of ACV’s product-related data and systems by mitigating code-based risks within a fast-paced, technology-driven environment. You will build and lead a high-performing team, driving continuous improvement and ensuring ACV remains a secure and trusted platform for dealers and buyers nationwide. What you will do: - Design, implement, and manage the end-to-end Product Security program, focusing on securing ACV's proprietary applications and code base. - Lead the adoption of DevSecOps practices, automating security tools and gates within the Continuous Integration/Continuous Deployment (CI/CD) pipelines to prevent security defects from reaching production. - Establish and enforce Secure Software Development Lifecycle (SSDLC) requirements, including security training for engineering teams and defining secure coding standards. - Build, mentor, and manage a team of Product Security Engineers responsible for application vulnerability management, security testing, and architectural review. - Understand and protect against the risks that AI brings without becoming the team that puts the No in Innovation. Proactively identify and establish security guardrails for AM/ML model development and usage to ensure safe innovation and high engineering velocity. - Oversee the deployment, tuning, and management of application security testing tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA) to identify and remediate code-based vulnerabilities. - Lead vulnerability remediation efforts for all ACV products, working closely with engineering and product teams to prioritize and track fixes based on risk. - Perform and oversee deep-dive security architecture and design reviews for all new products, features, and core application services, ensuring security is "baked in" from conception. - Define and manage secure configuration standards for containerized applications, microservices, APIs, and their supporting cloud infrastructure (AWS and GCP). - Manage and coordinate external penetration testing and bug bounty programs focused on ACV’s applications and APIs. - Design, maintain, and measure processes to prevent vulnerabilities from reaching production in a true Shift Left fashion. - Work with Technical Program Management to create appropriate key performance indicators to show success and improvement points in the program. - Contribute to ACV’s overall Governance, Risk, and Compliance (GRC) program by ensuring applications meet required internal security policies and external regulatory standards (e.g., SOC2, GDPR, CCPA). - Lead security risk assessments, threat modeling, and tabletop exercises specific to product features and application architecture, identifying and prioritizing technical vulnerabilities and developing mitigation strategies. - Ensure protection of sensitive data, including PII and financial information, within the application environment in compliance with relevant regulations. Validate that products conform to ACV’s data classification policies and other relevant documents and oversee processes to measure and enforce this before deployment. - Serve as the primary security advisor to Product and Engineering leadership and stakeholders on all matters related to application and product security. - Collaborate effectively with IT, Engineering, and Product teams to integrate security into their processes, fostering a strong security-conscious culture across development teams. - Maintain strong communication channels with remote team members, ensuring alignment and fostering a cohesive team environment. - Create a culture of communication, where collaboration and a sense of partnership with the remainder of the organization is evident and valued. - Create and maintain executive dashboards to increase security visibility throughout the organization and identify opportunities for improvement. - Perform additional duties as assigned. What you will need: - 10+ years experience in Information Security, with at least 5+ years directly focused on Product Security or Application Security in a leadership role. - Proven experience building and leading a centralized Product Security/AppSec program within a technology-driven, cloud-based SaaS company. - Deep, hands-on knowledge of the Secure Software Development Lifecycle (SSDLC), CI/CD, and DevSecOps principles, including automating security tooling. - Strong understanding of security frameworks and best practices (NIST CSF, ISO 27001, CIS Controls). - Extensive experience with cloud security, with a strong focus on securing applications deployed in AWS and/or GCP environments. Experience with Fintech companies is desirable. - Experience with modern software development including Agentic and Generative AI techniques. - Expertise with multiple application security tools, including SAST, DAST, MAST, SCA, API security platforms, and Web Application Firewalls (WAF). - Excellent communication, interpersonal, and leadership skills, with an ability to translate complex technical risks into business context for executive leadership and stakeholders. - Ability to work effectively in a remote environment and manage geographically dispersed teams. #LI-AM1 Our Values Trust & Transparency | People First | Positive Experiences | Calm Persistence | Never Settling At ACV, we are committed to an inclusive culture in which every individual is welcomed and empowered to celebrate their true selves. We achieve this by fostering a work environment of acceptance and understanding that is free from discrimination. ACV is committed to being an equal opportunity employer regardless of sex, race, creed, color, religion, marital status, national origin, age, pregnancy, sexual orientation, gender, gender identity, gender expression, genetic information, disability, military status, status as a veteran, or any other protected characteristic. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires reasonable accommodation, please let us know. For information on our collection and use of your personal information, please see our Privacy Notice. No immigration or work visa sponsorship provided for this position. Compensation: The compensation range for this position is listed in the "Job Details" section at the bottom of this posting. Please note that final compensation will be determined based upon the applicant's relevant experience, skill set, location, business needs, market demands, and other factors as permitted by law.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Surveillance Investigator II
Command Investigations, LLCCommand Investigations, founded in 2012, is a nationally recognized investigations firm offering surveillance, remote investigations, desktop intelligence, and specialty services to the insurance defense industry. Grounded in core values of integrity, service, and results, we deliver fast, reliable outcomes and treat every client like they are our only client. Our team leverages cutting-edge technology to stay at the forefront of the industry. With headquarters in Lake Mary, Florida, our experts provide services across the U.S. on a national scale.
Description Command Investigations, LLC is looking for Surveillance Investigators to become part of a dynamic team. This is a great opportunity for individuals with prior investigative experience who demonstrate integrity, independence, and a drive to succeed in a fast-paced investigative environment. Why You Will Love Working with Command Investigations, LLC? At Command Investigations, we are invested in YOU! We know, together, we can Lead with Excellence to provide top tier Service with Integrity that drives Results! Pay: $25-$30 per hour (depending on state) Schedule: This is not a standard 9-5 role. Workdays and hours vary based on business needs and there is no set or recurring schedule. Weekends, overtime, and holidays are typically required. Start times may be as early as 3:00 AM but 6:00 AM is common. Standard shifts are 8 hours but may extend up to 16 hours as needed. NOTE: Due to the nature of this role, there is no guarantee of hours or case assignments; however, we pride ourselves on distributing available cases fairly. Schedules are flexible with advanced discussion and notification. Location: On the Road with potential overnight stays when necessary Growth Opportunities: Our employees have opportunities to grow within a nationally recognized organization in an exciting and evolving industry. How We Take Care of You (Full Time Benefits): - Accrued Paid Time Off - Medical, Dental, Vision, and Life Insurance - 401(k) Plan - Employee Referral Program - Paid Travel Time - Daily Vehicle Allowance - Reimbursement for case related expenses - Overnight Pay - Additional performance incentives – Monthly Hot Shot bonus along with Monthly Tiered bonus program based on performance. At Command, we take care of our own. Our benefits plan helps keep you and your family healthy, happy, and secure. What You will Do: In this role, you will conduct field surveillance investigations by observing, tracking, and documenting subjects’ activities, capturing detailed video evidence, and preparing comprehensive reports for client review. - Conduct surveillance by monitoring, tracking, and recording subjects during daily activities - Perform both vehicular and on-foot surveillance while maintaining complete cover and discretion - Develop and execute pre-surveillance planning tailored to each location and case - Record and document investigative findings through video and detailed written reports - Capture subjects in a variety of environments, such as public spaces, events, and workplaces - Submit comprehensive reports and video evidence within required timeframes - Communicate consistently with team leaders regarding positions, observations, and tactical strategy - Utilize digital surveillance equipment, web-based technology, and investigative software - Maintain confidentiality and professionalism while representing Command Investigations - Uphold safety standards and adhere to all legal and ethical requirements during surveillance operations Requirements Required equipment, including but not limited to: - Reliable vehicle with legal dark tint - Smartphone - Laptop with Microsoft Word - Digital camcorder with date/time stamp and upload capability - Covert camera of choice - Tripod/monopod - SD cards if applicable What We are Looking For: - Highly observant and detail-oriented individuals - Strong sense of integrity, independence, and reliability - Excellent judgment and situational awareness - Adaptability to changing environments and case demands - Self-motivated professionals who can work autonomously - Strong written and verbal communication skills - Professional demeanor with a commitment to discretion and client confidentiality - Eagerness to learn and grow within the investigative industry What You Will Bring: - 1+ years (minimum 2,000 hours) of demonstrated Private Investigator experience, not including law enforcement, military, etc.) - Must be 21 years of age or older - Valid driver’s license with clean DMV record - High school diploma or equivalent required - College degree preferred - Computer skills including the ability to upload video and still images from a camera into an electronic system - Must carry personal auto insurance with liability limits of 100k/300k/100k - Proficient reading skills and ability to follow directions required - Must be able to work independently, provide excellent customer service, and demonstrate strong interpersonal, organizational, and multi-tasking skills. Flexibility and effective time management are required - Ability to work holidays, weekends, and overtime required - Regular, predictable, and full attendance, as assigned, is an essential function of the job - Willingness to travel and work the required schedule, starting as early as 3:00 AM - Complete a Command Investigations, LLC employment application, ability to pass a background check and submit to other pre-employment tasks as required for employment Physical Requirements: The physical and mental demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. - The employee will be required to remember and understand certain instructions, guidelines, or other information. - The employee should have the ability to lift up to and including 25lbs/11.34kg on occasion. - The employee will be required to sit, stand, and/or walk for long periods at a time. - The employee will be required to enter text or data into a computer or other machine by means of a traditional keyboard. Traditional Keyboard refers to a panel of keys used as the primary input device on a computer, typographic machine, or 10-Key numeric keypad. - Specific vision abilities required for this position include close vision, distance vision, peripheral vision, depth perception, and the ability to adjust focus. The associate must be able to hear, understand, and distinguish speech and surrounding sounds, such as traffic, environmental noises, or standard office activity. About Command Investigations Command Investigations, founded in 2012, is a nationally recognized investigations firm offering surveillance, remote investigations, desktop intelligence, and specialty services to the insurance defense industry. Grounded in core values of integrity, service, and results, we deliver fast, reliable outcomes and treat every client like they are our only client. Our team leverages cutting-edge technology to stay at the forefront of the industry. With headquarters in Lake Mary, Florida, our experts provide services across the U.S. on a national scale. Command Investigations, LLC is an Equal Opportunity Employer.
Senior DLP Engineer
Fidelity National FinancialFidelity National Financial (FNF) is a leading provider of title insurance and transaction services in the United States, dedicated to facilitating real estate
Overview POSITION OVERIVEW FNF is seeking a Senior Engineer of Data Loss Prevention (DLP) to join the Information Security Office (ISO) in either Jacksonville, FL office or be fully remote. This position will report to the Data Protection Lead. The Senior Engineer will support FNF’s DLP toolsets, Investigation, Secure Data Transmission, and Cloud Data Protection initiatives. An ideal candidate must be fluent in DLP technologies and methodologies, root cause analysis and risks management, security best practices standards, and audit and regulatory frameworks. Zscaler experience required. LOCATION - This role can sit 100% remote. DUTIES & RESPONSIBILITIES - Develop, deploy, and manage target state DLP technologies, integrations, and policies. - Manage full lifecycle of design and support evolution of engineering, system administration and daily operations of DLP technologies and services with a focus on continuous service improvement. - Manage and mature DLP program-related controls, documentation, testing and alignment with risk management framework. - Assess business requirements of the various lines of business and align solutions to balance enablement of the business with appropriate security controls. - Collaborate with other security groups to ensure alignment of strategies and ensure control coverage. - Support creation and documentation of business process aspects of the DLP initiative including process and procedure manuals, training, employee communication, workshops, business unit orientation and on-boarding, and team meetings. - Work with DLP Response team to deliver measurable metrics reporting, Key Risk Indicators (KRI’s) and Key Performance Indicators (KPI’s) that will be used for reporting to stakeholders and board of directors and continuous improvements for the program. - Work with various Audit, Compliance and Assessment teams and programs to identify, assess and mitigate operational risks, evaluating the adequacy and effectiveness of the platform, standards, procedures, processes, and internal controls. - Support adherence to applicable Security Controls, Policies, and Standards; partner with business owners and technology groups to synchronize plans to remediate gaps. - Participate in afterhours activities, as necessary, such as an on-call rotation and critical incident investigations. MINIMUM REQUIREMENTS - BS/MS in Computer Science or Business with emphasis in IT or the equivalent combination of education, training, and work experience . - 6+ years of Cybersecurity, Security Engineering and/or Governance Risk and Compliance related experiences. - Experience with Enterprise DLP, UBA, UEBA, CASB, DAR software solutions, design, and implementation. - Zscaler experience on web policies, PAC files, DLP Engines, etc. - Familiarity with Proofpoint, Microsoft Security Tools, and/or Varonis. - Experience building and maintaining custom DLP detection and prevention policies. - Experience successfully working within a globally distributed/remote organization of team members and key program stakeholders. - Experience gathering, developing, and documenting business/technical requirements. - Experience developing and maintaining a DLP development/test lab environment. - Familiarity with regulatory standards such as PCI, NYDFS, GDPR and/or CCPA. - Experience taking requirements and translating them to technology through evaluation and implementation. - Experience analyzing and quickly identifying important DLP events to investigate/remediate. - Experience writing, reviewing, and maintaining technical program documentation - Experience mentoring and training peers and junior level resources. - Experience interfacing with Sr. leadership to present both situation reports and business proposals for strategic change/improvements. PREFERRED EXPERIENCE - Relevant cyber security certifications, such as CISSP or CISM - Experience with SOAR technologies. - Experience with ServiceNow Security Incident Management. - Experience writing and maintaining script COMPENSATION & BENEFITS This position has the potential to earn compensation in the range of $120,000 - $160,000 annually based on location and job-related factors such as skillset and experience. Actual rate may vary within the range provided, depending on a number of factors, including skillset, experience and location. The base compensation is one component of the total rewards package offered to our employees, including optional health and welfare insurance (medical/dental/vision/life/disability); paid holidays, vacation, and sick time off; and matching 401(k) plan and matching employee stock purchase plan.
Description WHO WE ARE ZBeta is a world-class physical security design, consulting, and managed services firm that partners with some of the most dynamic, high-profile organizations and individuals in the world. We leverage a Data Driven, Technology Led, Human Centered approach in order to help our clients architect and engineer superior physical security solutions, implement them seamlessly, and operate them at peak efficiency. ZBeta prides itself on its level of technical expertise but remains independent and product-agnostic. Our highly experienced team brings decades of security expertise, diverse organizational perspectives, and proven best practices to every project and customer. It is our meticulous attention to detail, and our ability to deliver at scale that positions us to deliver an exceptional customer experience. Our primary goal is to redefine the standards of professional security, equipping our clients with innovative tools to master today’s challenges and fortify against tomorrow's risks. By consistently delivering exceptional solutions and pioneering advancements in the security field, we can exceed expectations and set new standards of excellence in pursuing our vision. Find out more about us here. WHO YOU ARE You are a forward-thinking strategic partner with a passion for enhancing security measures and fostering community resilience. You excel in fast-paced settings where your leadership abilities can catalyze meaningful transformation. You thrive in a workplace culture that is: - Innovative - Strives for Excellence - Reliable - Detail Oriented - Adaptable - Highly Organized - Client Obsessed - Curious - Resilient Does this sound like you? If so, join us in our mission to redefine security standards and make a lasting difference in our community. WHAT YOU'LL DO As a Project Manager, you will support security design and installation projects throughout North America. The Project Manager is responsible for managing all aspects of the project from initial engagement through project completion, including managing multiple projects and scopes of work. You are a resourceful, knowledgeable, and self-motivated security professional who thrives in a collaborative and supportive environment. CORE COMPETENCIES - Growth Minded: Strong self-awareness of strengths and development areas with a curiosity and appetite for change and innovation - Data-Driven: Strong analytical skills with critical thinking driven by data - Collaborative: Ability to solicit and understand multiple perspectives - Evaluative: Ability to evaluate outputs rigorously to ensure consistent excellence in delivery - Strategic Thinker: Ability to think proactively about the future of the business and relate current business activities to desired outcomes POSITION RESPONSIBILITIES The essential duties and responsibilities include, but are not limited to the following: Project Management - Identify project schedule, scope parameters, and oversee security design and implementation per client design requirements and standards. - Manage early project initiation activities and develop project security scope, schedule, critical deliverables, and requirements. - Manage scheduling, status, and tracking of critical project tasks, issues, and deliverables. - Prepare, issue, and manage Request for Proposal (RFP) documents for security systems installation scope. - Evaluate RFP responses and prepare evaluation reports, to include evaluation criteria, scoring, and recommendation details. Design - Perform security site evaluations of potential client properties and review proposed design concepts. - Apply client system design standards to in-progress site design, collaborate with client owner and user group stakeholders to define use cases and verify functional requirements, and produce a security functional specification for the project. - Review all security system design documentation for compliance with published security requirements, technical standards, and installation standards. - Redline documentation with corrections and log issues, as required. Client Relationship - Accountable for keeping clients informed of project status, including budget, schedule, issues, etc., and managing the client's expectations around the project design through individual and project team member communication. Collaborate - Serve as a primary security point of contact for project teams and stakeholders. - Attend regular project design, project management, Owner/Architect/Contractor (OAC), and construction meetings. - Manage site activation activities for physical security amongst project parties and stakeholders to drive schedule, quality, and cost. - Coordinate with ZBeta design resources to develop the complete scope of work documents for security systems procurement and installation. Documentation - Produce project status and issues reports and meet with client stakeholders weekly to review and resolve high-priority project issues. - Log all instances of issue resolutions that constitute exceptions to the published client security requirements to facilitate effective requirements exceptions reporting and/or requirement document updates. Quality Control - Conduct on-site inspections during construction and installation and final acceptance testing of completed systems installation. - Manage project lessons learned, site metrics evaluation, and contractor performance evaluations. - Review all security system design documentation produced by the system designer for compliance with published security requirements, technical standards, and installation standards. - Oversee the delivery of all shop drawings and close-out documentation required from the integrator/contractor. Requirements WHAT YOU'LL NEED - Experience: - 3+ years of project management experience, preferably in consulting with external clients on complex, aggressively scheduled data center projects - Education: Bachelor’s degree or equivalent work experience - Knowledge: - Working familiarity with low-voltage and physical security technology and design concepts - Skills: - Highly proficient in the use of Microsoft Office software - Proficiency in Studio and Bluebeam is a plus - Proficiency in project management tools, such as MS Project, SharePoint, and QuickBase - Abilities - Demonstrated excellence in communicating and presenting complex information to technical and non-technical stakeholders, both verbally and in written form - Demonstrated ability to identify critical path activities, prioritize tasks and deliverables, and realize consistent progress WHAT WE OFFER - Competitive salary based on job-related skills, experience, and qualifications - ZBeta is a remote-first company with a distributed team. This role is open to individuals based in the United States. - Our excellent benefits package includes 100% paid premiums on health, dental, vision, and life insurance, a 401k retirement plan, and significant work schedule and workplace flexibility. - Diverse and supportive culture WHAT'S IMPORTANT TO KNOW - We are open to hiring candidates located in or near Milwaukee, WI - This position requires the ability to travel up to 20% - This position is not eligible for visa sponsorship - Candidates must be able to meet client and/or government security screening requirements for the role - This position requires verification of U.S. citizenship due to citizenship-based legal restrictions. As a condition of employment, the successful candidate will be required to provide proof of citizenship. - The successful completion of a background check is required upon hire and every two years thereafter We look forward to connecting with individuals who are passionate about our mission and can bring diverse contributions to our team — not just those who check all the boxes. We are committed to creating a supportive, encouraging environment where everyone can fully express their diverse perspectives, showcase their talents, and grow their knowledge, skills, and abilities. The base pay offered will depend on factors, including but not limited to job-related knowledge, skills, experience, and internal equity. At ZBeta, new hires are rarely placed at the top of the pay range; compensation is determined by the specific circumstances of each position and candidate. A note to third-party recruiters - we do not accept unsolicited agency resumes, and we are not responsible for any fees related to unsolicited resumes.
Regional Sales Leader – Security
CiscoCisco is a publicly-traded, award-winning global technology solutions firm. Established in 1984 by a group of Stanford University computer scientists, Cisco has
• develop and execute sales strategies and tactics • responsible for accurate forecasting and regular deal reviews • lead account executives in development and expansion of opportunities • engage in deal inspection and drive accountability • build and maintain strong executive-level relationships


