Product Owner Cybersecurity Testing & Exposure Management
Function
We’re looking for an experienced Product Owner – Cybersecurity Testing & Exposure Management to join our client’s cybersecurity organization and take ownership of the continued development, management, and professionalization of its security testing and exposure management services. This is a unique opportunity combining product ownership, strategic vision, stakeholder management, and hands-on cybersecurity expertise. You will translate business and security needs into a clear product vision, roadmap, and scalable service offering, while working closely with internal teams and external partners to ensure high-quality and sustainable delivery.
Responsibilities
- Own and further develop services covering penetration testing, vulnerability disclosure, bug bounty programs, vulnerability management, attack surface management (ASM), and related exposure management activities.
- Translate stakeholder requirements into a clear product vision, roadmap, priorities, processes, methodologies, and supporting tooling.
- Coordinate and continuously improve the quality, scalability, and effectiveness of the services and their delivered results.
- Take an active role in complex cybersecurity cases, providing subject-matter expertise and supporting or coordinating operational activities.
- Analyse, optimise, and document security processes, governance models, methodologies, and ways of working.
- Work closely with internal teams, security specialists, and external partners to ensure effective service delivery.
- Build and retain organisational expertise through knowledge sharing, documentation, standards, and best practices, while helping develop internal capabilities.
- Monitor developments in cybersecurity testing and exposure management and translate relevant trends into improvements in services, processes, methodologies, and tooling.
- Contribute to RFI/RFP processes, including requirements definition, evaluation criteria, offer assessment, and selection recommendations.
- Define and monitor SLAs/KPIs, conduct service reviews, manage escalations, and drive continuous improvement.
Profile
You are a senior cybersecurity professional with a strong combination of product ownership and information security expertise. You bring proven experience as a Product Owner or in a comparable role, alongside a solid background as a Security Consultant within areas such as data, infrastructure, or applications. You have hands-on knowledge of exposure management solutions, vulnerability scanning, attack surface management, and penetration testing, as well as experience analysing and improving security processes and governance.
Must-have experience
- 5+ years of experience as a Product Owner or in a comparable role.
- 5+ years of experience as a Security Consultant in data, infrastructure, application, or comparable environments.
- 5+ years of experience with exposure management solutions, including vulnerability scanners and/or ASM.
- 5+ years of experience performing and/or coordinating penetration tests.
- Proven expertise in a specific information security domain.
- Proven experience analysing, optimising, and documenting security processes and governance.
- Knowledge of recognised security frameworks and methodologies.
Nice to have
- 3+ years of experience with RFI/RFP processes, including requirements, evaluation criteria, offer assessment, and selection advice.
- 3+ years of experience with at least two recognised penetration-testing standards or methodologies, such as OWASP, NIST, OSSTMM, or PTES.
- 5+ years of experience with security management frameworks such as ISO/IEC 27000, COBIT for Security, NIST, OWASP, or CIS Critical