
Exploring the Existence of Pure Product Security Governance Roles in Cybersecurity
product_securitygovernancecybersecurityGRCAppSecthreat_modelingsecure_SDLCjob_roles
The poster is transitioning from cybersecurity GRC to Product Security with experience in threat modeling, secure-by-design reviews, security risk, ISO 27001/42001, and collaborating with engineering teams. They observe that most Product Security roles seem to combine governance with hands-on AppSec engineering but are uncertain if purely governance-focused roles exist. The post seeks insights on whether companies value professionals who drive Secure SDLC, security requirements, threat modeling, security champions, and product security governance, as well as guidance on relevant job titles to target.