Job Summary
An experienced and delivery-focused Product Owner – Authentication & Secrets Security is required to lead the strategy, roadmap, and delivery of enterprise secrets management and authentication capabilities within a global organization.
This role sits within the Information & Cyber Security / Identity & Access Management (IAM) function and is responsible for advancing secure authentication practices and secrets lifecycle management across enterprise platforms, applications, and infrastructure.
The position focuses on securing human and non-human identities, ensuring proper governance of secrets, API keys, certificates, credentials, and vault technologies across hybrid cloud and on-premises environments.
The Product Owner will work closely with engineering teams, cybersecurity leaders, architects, compliance teams, and business stakeholders to deliver secure, scalable authentication services and modern secrets management solutions aligned with regulatory and enterprise security standards.
Product Strategy & Roadmap
- Define and drive the product vision, roadmap, and strategy for enterprise secrets management and authentication platforms.
- Own the lifecycle management of application and infrastructure secrets, including credentials, API keys, and certificates.
- Manage the product backlog for secrets security platforms such as vault technologies.
- Develop long-term roadmap initiatives to:
- Improve enterprise security posture
- Reduce manual credential handling
- Eliminate static secrets
- Enforce automated rotation and least-privilege access
- Align product initiatives with Zero Trust security principles and regulatory requirements.
- Evaluate emerging technologies such as:
- Passwordless authentication
- Passkeys
- Adaptive authentication
- Behavioral biometrics
- Bot authentication
- AI and digital asset security
- Track and monitor key metrics including reliability, adoption, latency, and credential exposure reduction.
- Own and manage the Agile product backlog, prioritizing features and improvements.
- Facilitate backlog grooming, sprint planning, and delivery planning sessions.
- Collaborate with engineering teams to deliver features aligned with roadmap commitments.
- Identify and mitigate delivery risks, dependencies, and operational issues.
- Ensure consistent delivery, health and achievement of defined OKRs.
- Translate complex technical requirements into business value propositions for leadership stakeholders.
- Align technology initiatives with broader business priorities and digital transformation goals.
- Partner with business owners to validate product outcomes and ensure benefits realization.
- Work with third-party vendors where applicable.
- Analyse and optimize end-to-end authentication and secrets management processes.
- Identify automation opportunities such as:
- Self-service capabilities
- Workflow automation
- Platform integrations
- Ensure transparency, accountability, and continuous improvement across delivery processes.
- Act as the primary liaison between business teams, cybersecurity teams, and engineering teams.
- Communicate product strategy, roadmap, and performance to senior leadership and governance forums.
- Foster cross-functional collaboration across product, architecture, engineering, and security teams.
- Support development teams by providing technical security direction in collaboration with security architects.
- Establish strong governance across delivery tracking, reporting, and escalation processes.
- Ensure compliance with enterprise cybersecurity standards, risk management practices, and regulatory expectations.
- Maintain audit readiness through centralized tracking of secrets access and rotation.
- Identify risks proactively and ensure mitigation plans are implemented.
- Identity & Access Management leadership
- Cybersecurity architecture and engineering teams
- Technology and platform engineering teams
- Product owners, program managers, and delivery leads
- Infrastructure, SRE, testing, and production support teams
- Risk, compliance, and internal audit teams
Required Experience
- 15+ years of overall experience in technology, cybersecurity, or enterprise platforms.
- 5+ years experience as a Product Owner, Technical Security Manager, or similar leadership role.
- Experience delivering both strategic initiatives and operational services.
- Strong understanding of Identity & Access Management (IAM) concepts:
- Authentication
- Authorization
- Identity lifecycle management
- Access control models
- Experience with secrets management and vault technologies such as:
- HashiCorp Vault
- Azure Key Vault
- CyberArk
- Familiarity with:
- Active Directory and enterprise identity platforms
- Cloud platforms (Azure / AWS)
- CI/CD pipelines and DevSecOps
- API-based authentication frameworks
- Knowledge of authentication technologies including Passwordless authentication and modern identity frameworks.
- Strong experience with Agile, Scrum, Waterfall, or hybrid delivery methodologies.
- Proven ability to manage complex enterprise programs and cross-functional teams.
- Experience interacting with senior leadership and technology executives.
- Excellent communication and stakeholder management skills
- Strong analytical and problem-solving capabilities
- Ability to influence without authority in large organizations
- Strong focus on governance, compliance, and risk management
- Bachelor’s or master’s degree in engineering, Computer Science, Information Security, or related field.
- Professional certifications preferred:
- CISSP
- CISM
- GIAC
- Certified Scrum Product Owner (CSPO)
