Senior Director Product Management, Security, Compliance and Risk

GEICO GEICO · Insurance · Palo Alto, CA · Remote

Senior Director of Product Management, Security, Compliance and Risk. This role focuses on integrating security, compliance, and risk management into enterprise products and platforms, ensuring alignment with legal, privacy, cybersecurity, and audit requirements. The position involves defining strategy, creating roadmaps, translating requirements into technical expectations, and partnering with technology teams to embed these principles into development processes, including CI/CD pipelines. While the role mentions "AI Security" and "building AI tools and/or agents" as a required qualification, the core function is product management for security and compliance across the enterprise, not direct AI/ML model development or research.

What you'd actually do

  1. Define long-term product security, compliance & risk enablement strategy aligned with enterprise technology and business objectives; develop and communicate product risk vision and communicate to internal stakeholders
  2. Serve as the single technology intake point for compliance, security and risk requirements impacting products and technology platforms
  3. Create and maintain product security, compliance & risk enablement roadmap with clear prioritization criteria, balancing regulatory and security requirements against business impact, delivery capacity and technical feasibility
  4. Translate requirements into implementation ready technical expectations, including documentation and user stores, based on requirements defined by Legal, Privacy, Cyber and Risk
  5. Ensure security, compliance & risk driven work is planned intentionally and embedded into roadmaps, rather than introduced as late stage delivery interruptions

Skills

Required

  • Bachelor’s degree in Computer Science, Information Systems, Engineering or a related field technical required
  • 12-15 years in senior technology leadership, product governance, platform enablement, or large-scale delivery oversight
  • Demonstrated experience translating security, privacy, legal and regulatory requirements into prioritized technology work.
  • FedRamp, FISMA, GDPR and Cybersecurity and Compliance, Vulnerability Management, Red Team, AI Security, Pen Testing, SOC\SOX, Identity Management
  • Proven experience in driving prioritization and roadmap alignment across multiple product and engineering teams
  • Experience building AI tools and/or agents, including embedding AI experiences into existing products
  • Strong understanding of secure by design and compliant by design principles within CI/CD pipelines, modern SDLCs and platform environments
  • Ability to influence without authority in complex, matrixed organization
  • Executive level communications and stakeholder management skills

Nice to have

  • Formal training in product management, enterprise architecture or technology governance a plus.

What the JD emphasized

  • FedRamp
  • FISMA
  • GDPR
  • Cybersecurity and Compliance
  • Vulnerability Management
  • Red Team
  • AI Security
  • Pen Testing
  • SOC\SOX
  • Identity Management
  • secure by design
  • compliant by design