Title: AI Product Owner
Location: Remote
Duration: 5+ Months contract
TECHNICAL SKILLS
Must Have
1+ year(s) of Gen AI related development
Agile Product Ownership
Nice To Have
AWS
DevOps practices and tools (Jenkins, Github, CI/CD, Terraform)
Job Profile Summary
The Senior Product Owner (Technical) will be responsible for defining, prioritizing, and driving the roadmap for an AI-driven code vulnerability detection and reporting capability. The product uses large language models and supporting automation to identify potential security weaknesses in source code, evaluate detection quality, and integrate actionable results into enterprise security and software development workflows.
This role will collaborate with Information Security, Technology, Application Development, Risk, Compliance, Architecture, Finance, and other key partners to translate business, security, operational, and regulatory requirements into product capabilities and measurable outcomes. The Senior Product Owner will guide a squad of engineers responsible for building, operating, and continuously improving the scanner, evaluation harness, integrations, and supporting telemetry.
Technical knowledge of application security, AI/LLM systems, cloud platforms, and software development practices is strongly preferred.
General Function
Responsible for defining, prioritizing, and managing the development and operation of an AI-driven security product that meets the needs of Information Security, application development teams, and other stakeholders.
Owns the product vision, roadmap, backlog, and prioritization process. Balances security risk reduction, product quality, operational stability, regulatory obligations, engineering capacity, and business value when determining priorities.
Supports implementation of roadmap deliverables, product capabilities, integrations, and adoption. Advocates for Agile and SAFe methodologies and ensures that the team backlog remains aligned with product strategy, customer needs, control requirements, and measurable outcomes.
Essential Duties & Responsibilities
- Define and communicate the product vision, strategy, objectives, and roadmap for the AI-driven code vulnerability detection capability.
- Own and prioritize the product backlog based on security risk, exploitability, regulatory impact, customer value, operational requirements, and engineering capacity.
- Translate business, security, technical, and regulatory needs into clear Features, Stories, acceptance criteria, and measurable outcomes.
- Partner with Information Security Engineering, Application Security, Technology, Architecture, Risk, Compliance, Legal, Finance, Operations, and Lines of Business to define and execute product strategy.
- Guide delivery of the scanner, evaluation harness, CI/CD integrations, reporting capabilities, operational telemetry, and supporting infrastructure.
- Establish product success measures covering detection effectiveness, precision, recall, reproducibility, coverage, adoption, operational reliability, cost, and delivery performance.
- Partner with engineering and security subject matter experts to define evaluation approaches, regression testing, ground-truth datasets, and release acceptance criteria.
- Ensure material changes to models, prompts, agents, detection logic, integrations, or evaluation methods are appropriately tested, documented, reviewed, and governed.
- Prioritize technical debt, reliability improvements, defects, security requirements, and operational enhancements alongside new product capabilities.
- Provide transparency and ongoing communication regarding roadmap priorities, delivery status, risks, dependencies, product performance, and key decisions.
- Collaborate with engineering throughout all phases of development, including analysis, design, implementation, testing, deployment, and ongoing support.
- Coordinate integration of the product with GitHub, CI/CD pipelines, enterprise reporting, security monitoring, and vulnerability management workflows.
- Partner with product consumers and application development teams to understand workflow requirements, validate usability, and improve adoption.
- Define the expected disposition and workflow for scanner outputs while maintaining clear accountability between product operations, finding triage, and remediation ownership.
- Maintain product documentation, operating procedures, control evidence, training materials, and stakeholder communications.
- Maintain a healthy product backlog and actively participate in planning, refinement, prioritization, demonstrations, retrospectives, and other team ceremonies.
- Communicate product capabilities, limitations, roadmap, and performance to technical teams, senior leadership, governance bodies, and other stakeholders.
- Maintain appropriate controls and documentation to support company, audit, regulatory, and Information Security requirements.
- Other duties as assigned.
Minimum Knowledge, Skills & Abilities Required
- 4+ years of related product ownership, product management, information security, software development, or technology delivery experience.
- Experience managing a technical product through design, implementation, deployment, adoption, and ongoing operation.
- Demonstrated ability to define product strategy, maintain a roadmap, manage a backlog, and make prioritization decisions across competing objectives.
- Experience translating technical, security, risk, and business requirements into actionable Features, Stories, acceptance criteria, and product outcomes.
- Working knowledge of software development lifecycles, Git-based development, CI/CD pipelines, APIs, cloud platforms, and production support practices.
- Understanding of application security concepts, common vulnerability classes, vulnerability management workflows, and software security testing.
- General understanding of artificial intelligence and large language model concepts, including model limitations, prompt or agent behavior, evaluation, and the importance of human review.
- Ability to interpret product metrics and evaluation results, including precision, recall, false-positive rates, false-negative rates, reproducibility, coverage, and operational reliability.
- Ability to evaluate tradeoffs among security risk reduction, customer experience, engineering effort, cost, operational support, and regulatory impact.
- Experience working in Agile or SAFe development environments.
- Strong written and verbal communication skills, with the ability to explain technical concepts, product decisions, risks, and limitations to different audiences.
- Ability to influence decisions and build alignment across engineering, security, risk, governance, and business stakeholders without direct authority.
- Strong analytical skills, intellectual curiosity, and structured problem-solving ability.
- Self-motivated and able to work independently and across multiple teams in a fast-paced, highly regulated environment.
- Eligible to work in the United States without the need for sponsorship now or in the future.
Preferred Knowledge, Skills & Abilities
- Product ownership experience for an application security, vulnerability management, developer security, cloud security, or AI-enabled product.
- Experience with SAST, SCA, software composition, or vulnerability detection capabilities.
- Familiarity with AWS hosted AI services or equivalent enterprise LLM platforms.
- Familiarity with GitHub, Jenkins, Infrastructure as Code, containerized workloads, and cloud-native architectures.
- Experience defining evaluation frameworks or quality measures for probabilistic or AI-enabled systems.
- Experience implementing products within a regulated financial services environment.
- Experience supporting audit, compliance, model governance, risk assessment, or control-evidence requirements.
- Relevant certifications in product management, Agile, SAFe, cloud technology, artificial intelligence, or information security.