Posted 05 August, 2026
Security Program Owner (Product Security)
Haumaru Whānau
Auckland, AUK, NZ
Full Time
Reference: cbc73647662fa0ec
Job Description
Security Program Owner (Product Security) Auckland, New Zealand Full-time Senior Lead the delivery and governance of product security across Haumaru’s platforms, ensuring security requirements are effectively defined, prioritized, and implemented through Agile and DevSecOps practices. This role focuses on program ownership, delivery execution, and security assurance, rather than hands-on engineering. About This Role Haumaru Technologies Limited is seeking a highly experienced Security Program Owner (Product Security) to lead the planning, prioritization, and delivery of security across our product ecosystem, including our AI Threat Analyst platform (Tāne) and enterprise cybersecurity solutions. This role is responsible for owning the security program lifecycle, ensuring that all security requirements are clearly defined, embedded into Agile delivery processes, and successfully implemented by engineering teams. You will act as the bridge between security, engineering, and business, translating security standards, risks, and compliance obligations into actionable deliverables, while driving execution through Scrum, DevSecOps, and structured program management. Responsibilities Act as the Security Program Owner, defining and prioritizing security initiatives across all products and platforms Own and manage the security backlog, ensuring alignment with product roadmaps, business priorities, and regulatory requirements Translate security standards, risks, and compliance requirements into user stories, acceptance criteria, and deliverables Lead and participate in Agile/Scrum ceremonies (sprint planning, backlog grooming, reviews) to ensure security requirements are delivered Drive end-to-end delivery of security programs, ensuring timelines, scope, and quality objectives are met Ensure engineering and DevOps teams implement security requirements effectively and consistently Define and track security KPIs, delivery metrics, and risk indicators Ensure DevSecOps practices are embedded, with security controls integrated into CI/CD pipelines Oversee threat modeling and architecture review outputs, ensuring findings are converted into actionable tasks Validate that key security controls (authentication, authorization, data protection, API security) are properly implemented by delivery teams Act as the primary liaison between security, engineering, and business stakeholders Ensure compliance requirements (ISO 27001, NIST, PDPL/GDPR) are translated into implementable controls and delivered Support release governance, ensuring security requirements are met prior to production deployment Drive vulnerability remediation programs, ensuring findings are tracked, prioritized, and resolved Continuously improve secure delivery processes, Agile maturity, and DevSecOps integration Requirements 8+ years of experience in product security, application security, or security program management Proven experience in program ownership, delivery management, or product ownership roles Strong experience working in Agile/Scrum environments Solid understanding of DevSecOps and CI/CD security integration Strong knowledge of web, API, and cloud security (Azure/GCP preferred) Experience translating security requirements into delivery artifacts (user stories, backlog items) Familiarity with threat modeling methodologies (STRIDE, attack trees) Understanding of IAM and modern authentication protocols (OAuth2, JWT, OpenID Connect) Familiarity with compliance frameworks (ISO 27001, NIST, PDPL, GDPR) Strong stakeholder management and communication skills #J-18808-Ljbffr