AMD
Principal Product Security Program Leader
AMD logo AMD 1130 open jobs

Principal Product Security Program Leader

San Jose, CA, USA · Senior (5+ years) · Full Time ·


ADVANCE YOUR CAREER. ADVANCE THE WORLD.

At AMD, we believe technology can change lives for the better. It can heal us, entertain us, and make us more connected, productive, and understanding of the world around us. And we’re looking for talent who feel the same: people who want to leave the planet better than they found it, those who don’t shy away from humanity’s challenges but are determined to help solve them.

AMD is powering the next generation of supercomputing, high-performance computing, cloud, and AI. Whether you’re designing next-gen processors, enabling AI breakthroughs, or creating go-to-market plans, every role at AMD contributes to something bigger — technology that moves the world forward.




About the Role

AMD is seeking an experienced Product Security Leader to serve as the primary point of accountability for product security across the Adaptive & Embedded Computing (AECG) business unit. This role owns end-to-end coordination of vulnerability response, secure development lifecycle (SDL) governance, and regulatory compliance for AMD's Adaptive and Embedded Computing product lines. The successful candidate will partner closely with AMD's Product Security Office (PSO), Corporate Legal and business-unit security subject matter experts across hardware, firmware, and software tooling teams.

This is a high-visibility role that is critical to meeting AMD's security commitments to its customers, including the EU Cyber Resilience Act (CRA), GDPR, and contractual security obligations with hyperscale and OEM partners.

Key Responsibilities
  • Own product security governance for the business unit — primary interface with AMD's Product Security Office on vulnerability management, SDL health, and remediation progress.
  • Coordinate response across embedded security experts spanning silicon, firmware, and software tooling to triage and resolve vulnerability reports from researchers, internal teams, and customers.
  • Maintain and evolve the security threat model for AMD's adaptive-computing design tools.
  • Partner with Legal and Compliance to align the business unit with the EU Cyber Resilience Act, GDPR, and related regulatory requirements, including SBOM and vulnerability disclosure obligations.
  • Facilitate customer-facing security assessments and due-diligence requests.
  • Serve as incident lead for high-severity vulnerabilities and active exploit reports, driving timely resolution and coordinated disclosure with partners and customers.
  • Brief business-unit and executive leadership on security posture, material incidents, and program health.
Required Qualifications
  • Expert level of product security, PSIRT, or Security Design Lifecycle leadership experience in semiconductor, EDA software, embedded systems, or a comparable industry; FPGA / adaptive computing experience is a strong plus.
  • Demonstrated leadership with a PSIRT or product coordinated vulnerability disclosure (CVD) program, including triage, CVSS scoring, CVE assignment, security bulletin/advisory authoring, and coordinated disclosure with hyperscalers, OEMs, and independent security researchers.
  • Working expertise with SAST tooling (e.g., Coverity, CodeQL), SCA/SBOM tooling (e.g., Black Duck, SPDX, CycloneDX), threat modeling methodologies, and secure SDLC frameworks (eg, ISO/SAE 21434, NIST SSDF).
  • Demonstrated familiarity with the EU Cyber Resilience Act (CRA), GDPR, and adjacent global cybersecurity regulations, with the ability to translate regulatory text into engineering requirements.
  • Track record partnering with Legal, Corporate Communications, and Compliance teams on regulated disclosures and customer-facing security assessments.
  • Strong executive communication skills: able to produce concise status reporting, brief senior leadership, and translate technical findings into business and customer impact.
Preferred Qualifications
  • Experience with FPGA design tool flows (e.g., Vivado, Vitis, Vitis HLS) and embedded software stacks (e.g., PetaLinux, Yocto, Xen).
  • Familiarity with information security management standards such as ISO/IEC 27001, in addition to product-security-specific frameworks.
  • Active participation in industry security groups such as the FIRST PSIRT SIG, OpenSSF working groups, OCP Security, or PSIRT Services Framework contributors.
  • Familiarity with bug bounty platform operations, including researcher engagement and reputation management.
  • Experience contributing to or interpreting regulator guidance (e.g., ENISA, national cybersecurity agencies) and participation in relevant standards bodies (e.g., TCG, IETF, IEEE).
  • Relevant industry certifications a plus: CISSP, CISM, CSSLP, or equivalent.

This role is not eligible for visa sponsorship.

#LI-BW2

#LI-HYBRID




Benefits offered are described:  AMD benefits at a glance.

AMD does not accept unsolicited resumes from headhunters, recruitment agencies, or fee-based recruitment services. AMD and its subsidiaries are equal opportunity, inclusive employers and will consider all applicants without regard to age, ancestry, color, marital status, medical condition, mental or physical disability, national origin, race, religion, political and/or third-party affiliation, sex, pregnancy, sexual orientation, gender identity, military or veteran status, or any other characteristic protected by law.   We encourage applications from all qualified candidates and will accommodate applicants’ needs under the respective laws throughout all stages of the recruitment and selection process.

AMD may use Artificial Intelligence to help screen, assess or select applicants for this position.  AMD’s “Responsible AI Policy” is available here.

This posting is for an existing vacancy.