VP, Product Security
Listed on 2026-01-12
-
IT/Tech
Cybersecurity, Systems Engineer, IT Consultant, Data Security
Overview
Warner Bros. Discovery (WBD) seeks a visionary Vice President, Product & Application Security to lead the security strategy and execution for its Direct-to-Consumer (DTC) portfolio, including HBOMax, Discovery+, CNN streaming, and other flagship digital products.
This executive will be accountable for protecting millions of global customers’ data, securing complex application architectures, and ensuring the resilience of revenue-generating systems in a rapid, high-scale environment. The ideal candidate will have deep expertise in application security, secure software development practices, threat modeling, code analysis, and vulnerability management across large-scale distributed systems.
You will collaborate with engineering, product, and business executives to embed security into every phase of development—from concept and architecture through deployment and operations—and drive a security-first culture across global teams.
Responsibilities
- Product Security Strategy & Execution
- Define and lead the global product security strategy across Discovery+, CNN, and other DTC platforms.
- Translate cybersecurity requirements into scalable, business-aligned solutions.
- Prioritize investments and roadmap initiatives based on risk and business impact.
- Secure Architecture & Engineering Enablement
- Champion secure-by-design and secure-by-default principles across the development lifecycle.
- Collaborate with engineering to design secure architectures and protect consumer-facing technologies at scale.
- Drive adoption of threat modeling, secure coding, code reviews, and secure deployment practices.
- Automate security testing and vulnerability management within CI/CD pipelines.
- Risk Management, Compliance & Incident Response
- Oversee design reviews, architecture assessments, penetration testing, vulnerability management, monitoring, and 24x7 incident response for all DTC platforms.
- Ensure visibility into API security, identity management, and data protection.
- Partner with Privacy, Legal, and Compliance to adhere to GDPR, CCPA, and other global data protection regulations.
- Provide executive-level reporting on security posture and risk management metrics.
- Executive Influence & Cross-Functional Collaboration
- Serve as a security thought leader to Product, Engineering, and DTC executives.
- Represent Product & Application Security in governance forums and board discussions.
- Advocate for security as a business enabler to support customer trust, brand reputation, and revenue growth.
- Partner with Dev Ops, Cloud, and Infrastructure leaders for end-to-end security coverage from applications to platform layers.
- Build and mentor a global team of security engineers, architects, and product security leaders.
- Foster a culture of innovation, accountability, and continuous improvement within the function.
- Lead workforce planning to scale with evolving architectures and threats; promote cross-functional training and career growth.
Qualifications & Experiences
- Deep DTC and Application Security Expertise: Proven success securing large-scale, consumer-facing platforms with millions of global users.
- Product Security Leadership: 15+ years of cybersecurity experience, including 7+ years leading product security for high-growth DTC, OTT, or digital media products.
- Cloud & Platform Mastery: Expertise in cloud-native security (AWS/GCP/Azure), API security, CI/CD protection, and DRM/content protection.
- Customer Trust Mindset: Strong understanding of data privacy and compliance frameworks and embedding them in product design.
- Innovation & Agility: Ability to balance security with rapid product development and time-to-market.
- Executive Presence: Able to influence C-suite stakeholders and present security risks in business terms.
- Team Builder: Proven success building and scaling global security engineering teams.
If you:
- Are excited to work in an international, fast-paced, multi-faceted media company.
- Are capable of timely escalation, responsiveness, and follow-through to meet deadlines.
- Understand risk-based business impact approaches to cybersecurity.
- Question and influence actions needed to attain goals and targets.
- Are comfortable driving progress without direct control…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).