Principal Product Security Program Leader

Amd

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
San Jose, CA
Salary
$240,000–$360,000 / yr
Posted
25 days ago
Freshness
Confirmed live yesterday
Closes
Aug 17, 2027

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $197k
This role $300k
$117k most similar roles pay here $386k

This role pays more than 96% of similar roles. Most pay $168,500–$225,800 — the shaded band above. At the midpoint, this role pays about $300k versus about $197k for comparable roles.

Based on 239 similar postings.

Employer

About Amd

AMD (Advanced Micro Devices) is a semiconductor company that develops high-performance processors, graphics cards, and adaptive computing solutions for gaming, data centers, and embedded markets. Industry: Semiconductors

Amd currently has 367 open roles on FindRole.

Listed pay typically runs $166,400–$249,600 across 367 roles with salary data.

Most-posted roles

View all roles at Amd

At a glance

TL;DR · Principal Product Security Program Leader

The Principal Product Security Program Leader serves as the primary point of accountability for product security within the Adaptive & Embedded Computing business unit. This role manages end-to-end coordination of vulnerability response, secure development lifecycle governance, and regulatory compliance for adaptive and embedded computing product lines. The individual will manage triage and resolution of reports from researchers and customers while maintaining security threat models for design tools. Key responsibilities include facilitating customer-facing assessments, managing high-severity incidents, and ensuring alignment with the EU Cyber Resilience Act and GDPR. Required skills include expertise in PSIRT programs, CVSS scoring, and CVE assignment. Technical competencies include SAST tools like Coverity and CodeQL, SCA/SBOM tools such as Black Duck or SPDX, and frameworks including ISO/SAE 21434 and NIST SSDF. The role addresses security for silicon, firmware, and software tooling.

What you'll do

  • Manage product security governance and serve as the primary interface with the Product Security Office.
  • Coordinate vulnerability triage and remediation across silicon, firmware, and software tooling teams.
  • Maintain and evolve security threat models for adaptive-computing design tools.
  • Ensure compliance with regulations like the EU Cyber Resilience Act and GDPR through SBOM and disclosure management.
  • Lead incident response for high-severity vulnerabilities and manage coordinated disclosures with partners and customers.
  • Facilitate customer-facing security assessments and due-diligence requests.
  • Brief executive leadership on security posture, material incidents, and program health.

What we're looking for

  • Expert level experience in product security, PSIRT, or Security Design Lifecycle leadership within the semiconductor, EDA software, or embedded systems industries.
  • Demonstrated leadership of a PSIRT or coordinated vulnerability disclosure program including triage, CVSS scoring, and CVE assignment.
  • Working expertise with SAST tooling, SCA/SBOM tooling, threat modeling methodologies, and secure SDLC frameworks like ISO/SAE 21434 or NIST SSDF.
  • Familiarity with the EU Cyber Resilience Act (CRA), GDPR, and other global cybersecurity regulations to translate requirements into engineering tasks.
  • Experience partnering with Legal, Corporate Communications, and Compliance teams on regulated disclosures and customer-facing security assessments.
  • Strong executive communication skills to report status, brief senior leadership, and translate technical findings into business impact.
  • Preferred experience with FPGA design tool flows, embedded software stacks, and information security management standards like ISO/IEC 27001.
  • Relevant industry certifications such as CISSP, CISM, or CSSLP are preferred.

More like this

Similar roles

Manager, Product Security

Chime

San Francisco, CA 130 days ago
Application Security AI Security AWS GCP Infrastructure as Code SAST DAST SCA WAF CNAPP Secure SDLC Vulnerability Management Encryption
5+ yrs exp

Principal Product Security Engineer

Johnson & Johnson

Remote (Santa Clara, CA) 23 days ago $118,000$203,550
Threat Modeling Vulnerability Management Penetration Testing CVSS SBOM Cloud Security AWS Azure C C++ C# Java Python Cryptography Secure Boot ISO 14971 AAMI TIR57 IEC 62304 IEC 81001-5-1 HIPAA GDPR HITRUST ISO 27001 OWASP Top 10 SOC 2 FedRAMP
8+ yrs exp Remote

Head of Application Security

Analog Devices

Wilmington, MA 18 days ago $219,200$301,400
DevSecOps SAST SCA DAST CI/CD SBOM LLM NIST AI RMF ISO/IEC 42001 OWASP LLM Top 10 MITRE ATLAS PSIRT CVE CVSS IEC 62443 ISO/SAE 21434 ISO 26262 IEC 62304 CMMC ITAR EAR
10+ yrs exp

Director, Product Security

Green Dot Corp

GA 17 days ago
Application Security SAST DAST CI/CD Mobile Security Security Architecture DevOps Product Security Cybersecurity
8+ yrs exp

Principal Product Manager, Agentic Security

Microsoft

6 days ago $142,800$274,800
Artificial Intelligence Cybersecurity Cloud Services Knowledge Graphs Distributed Systems Release Governance Incident Management Service Health Reviews Data Science
8+ yrs exp Hybrid

VP, Product Security Architecture

Synchrony

Stamford, CT 3 days ago $155,000$260,000
Application Security Threat Modeling API Security SAML OIDC mTLS DevSecOps CI/CD SAST DAST SCA Secrets Management PCI-DSS GDPR SOC 2 OWASP Top 10 Service Mesh Software Supply Chain Security
10+ yrs exp