Technical Program Manager – Product Security Engineering & Assurance

Sandisk · Milpitas, CA

Spotted 12h agofulltime
Job description

About this role

Sandisk understands how people and businesses consume data and we relentlessly innovate to deliver solutions that enable today’s needs and tomorrow’s next big ideas. With a rich history of groundbreaking innovations in Flash and advanced memory technologies, our solutions have become the beating heart of the digital world we’re living in and that we have the power to shape.

Sandisk meets people and businesses at the intersection of their aspirations and the moment, enabling them to keep moving and pushing possibility forward. We do this through the balance of our powerhouse manufacturing capabilities and our industry-leading portfolio of products that are recognized globally for innovation, performance and quality.

Sandisk has two facilities recognized by the World Economic Forum as part of the Global Lighthouse Network for advanced 4IR innovations. These facilities were also recognized as Sustainability Lighthouses for breakthroughs in efficient operations. With our global reach, we ensure the global supply chain has access to the Flash memory it needs to keep our world moving forward.

Description

Job Description Sandisk’s Product Security Engineering & Assurance (PSEA) organization is seeking an experienced Technical Program Manager (TPM) to help operate and scale product security programs across Sandisk’s portfolio of hardware, firmware, embedded, and storage products.

The TPM will work closely with Product Security Engineers, Security Architects, PSIRT, Adversarial Security Engineering, firmware and hardware engineering product teams, Legal, and other stakeholders to coordinate product security activities and improve the effectiveness and scalability of PSEA programs.

The ideal candidate combines strong technical program management capabilities with a working understanding of product security, embedded systems, and hardware/firmware development. The candidate should be comfortable engaging in technical discussions involving firmware, secure boot, hardware roots of trust, firmware updates, device interfaces, cryptography, debug capabilities, provisioning, and product lifecycle security.

This role is focused on enabling and scaling the Product Security Engineering & Assurance function, rather than managing product development schedules or engineering delivery. Essential Duties and Responsibilities Product Security Program Operations

  • Coordinate Product Security Engineering & Assurance activities across product and engineering organizations.
  • Establish and maintain operating mechanisms for PSEA programs, including security reviews, assessments, vulnerability management, assurance activities, and adversarial testing.
  • Coordinate engagement between Product Security Engineers, Product teams, Legal and other stake holders.
  • Maintain visibility into security assessments, findings, risk reviews, and other PSEA activities across the product portfolio.
  • Help improve consistency and scalability of product security processes, workflows, templates, and operating mechanisms.
  • Identify recurring operational challenges and opportunities to improve how PSEA engages with engineering organizations.
  • Maintain security program metrics and data needed to understand coverage, effectiveness, and areas requiring attention. Secure Development Lifecycle & Security Readiness
  • Coordinate execution of PSEA's Secure Development Lifecycle (SDL) and product security readiness processes.
  • Facilitate security architecture reviews, threat modeling, product security risk assessments, and security readiness activities.
  • Coordinate security engagement with firmware, hardware/ASIC, embedded software, validation, and product engineering teams.
  • Maintain visibility into security requirements, assessments, findings, exceptions, and residual product risks.
  • Coordinate collection and review of security evidence supporting product security assessments and readiness decisions.
  • Identify recurring gaps and opportunities to improve SDL processes, security guidance, tooling, and automation. Product Security Assurance
  • Coordinate security assurance activities across Sandisk product programs.
  • Support collection and organization of technical security evidence including:
  • threat models and architecture assessments,
  • static analysis and SAST results,
  • SBOM and dependency analysis,
  • firmware and binary analysis,
  • fuzzing and penetration testing,
  • vulnerability remediation evidence,
  • security validation results.
  • Coordinate customer product security inquiries, technical security questionnaires, and security assurance requests.
  • Support regulatory, certification, and industry product security initiatives in partnership with security engineering, Legal, Compliance, and product organizations.
  • Coordinate independent security assessments and external security testing engagements.
  • Maintain visibility into resulting findings and security commitments. PSIRT & Vulnerability Management
  • Support operation of the Product Security Incident Response Team (PSIRT) program.
  • Coordinate vulnerability intake, triage, technical investigation, risk assessment, remediation coordination, validation, and disclosure activities.
  • Facilitate engagement between PSIRT, Product Security Engineers, firmware/hardware engineering, product teams, Legal, and other stakeholders.
  • Maintain vulnerability records, decisions, technical evidence, remediation status, and disclosure information.
  • Coordinate activities associated with external researchers, customers, and third-party vulnerability reports.
  • Support security advisory and coordinated vulnerability disclosure processes.
  • Develop and maintain metrics for vulnerability trends, response effectiveness, remediation, and recurring security issues. Adversarial Security Engineering
  • Support operation and scaling of Adversarial Security Engineering (ASE) across Sandisk product families.
  • Coordinate adversarial assessments involving firmware analysis, reverse engineering, fuzzing, penetration testing, hardware security testing, and vulnerability research.
  • Work with security engineers and product teams to coordinate assessment scope, product access, test environments, hardware, technical information, and engineering engagement.
  • Coordinate external security researchers and independent security assessment partners.
  • Maintain visibility into adversarial findings, technical validation, remediation, and lessons learned.
  • Help develop repeatable ASE engagement models, assessment processes, and reusable playbooks. AI-Assisted Product Security
  • Support PSEA initiatives applying AI and agentic technologies to product security engineering.
  • Coordinate initiatives involving AI-assisted threat modeling, firmware analysis, vulnerability research, security testing, and adversarial engineering.
  • Help establish repeatable workflows for transitioning security engineering experiments into operational PSEA capabilities.
  • Support measurement of AI-assisted security capabilities, including improvements in analysis coverage, engineering efficiency, and vulnerability discovery. Product Security Metrics & Operational Excellence
  • Develop and maintain metrics and dashboards covering:
  • SDL and security assessment coverage,
  • security readiness,
  • vulnerability trends,
  • PSIRT operations,
  • adversarial security assessments,
  • security assurance activities,
  • remediation trends,
  • customer and regulatory security requests.
  • Analyze PSEA operational data to identify recurring security themes and opportunities for improvement.
  • Help automate manual security program workflows and reporting.
  • Improve PSEA processes, documentation, templates, and operating mechanisms to enable the organization to scale across a growing product portfolio.

Cross-Functional Coordination

Collaborate closely with:

  • Product Security Engineers and Platform Security Architects
  • Product Teams
  • Legal and Compliance
  • Customer-facing engineering organizations
  • Third Party Vendors
  • External security researchers and assessment partners Serve as a key coordination point between PSEA and these organizations while respecting existing product and engineering ownership structures.

Qualifications

Required

  • Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, Cybersecurity, Information Systems, or a related technical field, or equivalent practical experience.
  • 7+ years of experience in technical program management, cybersecurity program management, product security, engineering, or related technical disciplines.
  • Experience supporting technical programs involving hardware, firmware, embedded systems, or hardware/software integrated products.
  • Working knowledge of product security disciplines including:
  • Secure Development Lifecycle (SDL),
  • threat modeling,
  • security risk assessment,
  • vulnerability management,
  • product security testing,
  • security assurance,
  • incident and vulnerability response.
  • Working understanding of hardware/firmware security concepts including:
  • secure boot and roots of trust,
  • firmware authentication and updates,
  • cryptographic protections,
  • device identity and provisioning,
  • debug and manufacturing interfaces,
  • embedded product lifecycles.
  • Ability to engage effectively with Product Security Engineers, firmware engineers, hardware/ASIC engineers, validation teams, and product organizations.
  • Ability to understand complex technical security discussions and translate them into well-structured security processes, coordination, documentation, and follow-up.
  • Strong organizational and analytical skills with demonstrated ability to operate across multiple simultaneous technical security initiatives.
  • Strong written and verbal communication skills.
  • Ability to influence and coordinate effectively across organizations without direct authority. Preferred
  • Experience in a Product Security Engineering, Product Security Assurance, or PSIRT organization.
  • Experience with SSDs, NAND Flash, NVMe, PCIe, semiconductor products, embedded devices, or related hardware/firmware technologies.
  • Experience operating or supporting a Secure Development Lifecycle for hardware/firmware products.
  • Experience with PSIRT, coordinated vulnerability disclosure, CVSS, and vulnerability management.
  • Familiarity with hardware security concepts including roots of trust, secure boot, lifecycle security, anti-rollback, secure debug, and manufacturing controls.
  • Familiarity with FIPS 140, Common Criteria, EU Cyber Resilience Act (CRA), SBOM requirements, NIST guidance, and software supply-chain security.
  • Experience coordinating customer product security inquiries, certifications, regulatory initiatives, or independent security assessments.
  • Experience developing security metrics, dashboards, workflows, and operational reporting.
  • Experience with Jira, Confluence, or comparable engineering workflow platforms.
  • Familiarity with AI-assisted security engineering, LLMs, security automation, or agentic AI workflows. What We Are Looking For We are looking for a TPM who can help operate, connect, and scale the Product Security Engineering & Assurance organization. The successful candidate will not own product development schedules or engineering delivery. Instead, they will make PSEA more effective by ensuring security engagements are well coordinated, security information and evidence are organized, stakeholders remain connected, and PSEA's processes and capabilities scale across the product portfolio. They should understand hardware and firmware products well enough to engage credibly with technical teams while bringing the organizational discipline, communication, and operational thinking necessary to make a complex Product Security organization effective.

Additional Information

Sandisk is committed to providing equal opportunities to all applicants and employees and will not discriminate based on their race, color, ancestry, religion (including religious dress and grooming standards), sex (including pregnancy, childbirth or related medical conditions, breastfeeding or related medical conditions), gender (including a person’s gender identity, gender expression, and gender-related appearance and behavior, whether or not stereotypically associated with the person’s assigned sex at birth), age, national origin, sexual orientation, medical condition, marital status (including domestic partnership status), physical disability, mental disability, medical condition, genetic information, protected medical and family care leave, Civil Air Patrol status, military and veteran status, or other legally protected characteristics.

We also prohibit harassment of any individual on any of the characteristics listed above. Our non-discrimination policy applies to all aspects of employment. We comply with the laws and regulations set forth in the Equal Employment Opportunity is the Law poster.

Sandisk thrives on the power and potential of diversity. As a global company, we believe the most effective way to embrace the diversity of our customers and communities is to mirror it from within. We believe the fusion of various perspectives results in the best outcomes for our employees, our company, our customers, and the world around us.

We are committed to an inclusive environment where every individual can thrive through a sense of belonging, respect and contribution.

Sandisk is committed to offering opportunities to applicants with disabilities and ensuring all candidates can successfully navigate our careers website and our hiring process. Please contact us at jobs.accommodations@sandisk.com to advise us of your accommodation request.

In your email, please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.

Interested in this role?Continue on LinkedIn to apply.
Apply on LinkedIn