Insight Global logo

Remote PSIRT Commander - INTL India

Insight Global

Remote · USJob$20–28/hrSeen 1 day agoSeen in employer's feed 1 day ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$20–28/hr
Location
Remote · US
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

The PSIRT Commander coordinates and leads the organization’s response to product cybersecurity vulnerabilities, incidents, and regulatory reporting, acting as the central point of contact among R&D, security, compliance, legal, and executive teams while supporting compliance initiatives and governance activities.

Skills & qualifications

RequiredNice to have

Skills

Security Incident ResponseProduct SecuritySoftware DevelopmentHardware DevelopmentSecure Software Development LifecycleVulnerability ManagementSecurity EngineeringSecurity Testing MethodologiesCVEs and CVSS ScoringSecure Development PracticesCloud PlatformsDevSecOpsEmbedded SystemsRegulatory ComplianceAudit ReadinessCommunicationPresentation

Qualifications

Bachelor's Degree in Computer Science Cybersecurity Information Technology or Equivalent4-5 Years Experience in Security Incident Response Product Security Software or Hardware Development Secure Software Development Lifecycle Vulnerability Management Security Engineering

Full job description

Job Description

The PSIRT Commander is responsible for coordinating and leading the organization's response to product cybersecurity vulnerabilities, security incidents, and regulatory reporting obligations. This role serves as the central point of coordination between R&D, Product Security, Compliance, Legal, Customer Communications, and Executive Leadership to ensure the timely assessment, remediation, communication, and closure of product security issues. In addition to incident management responsibilities, the PSIRT Commander supports product security compliance initiatives, including regulatory readiness activities such as the EU Cyber Resilience Act (CRA), CISA Secure Software Development Attestation, product security assessments, audit preparation, and cybersecurity governance activities. This will be a fully remote position in India, offering between $20-28/hour USD depending on experience.

Key Responsibilities Product Security Incident Response

  • Drive and coordinate the end-to-end response to reported product security vulnerabilities and cybersecurity incidents.
  • Perform initial intake, triage, and severity assessment of security reports.
  • Organize and facilitate incident response meetings with technical and business stakeholders.
  • Drive decision-making regarding escalation paths, remediation priorities, customer communications, and regulatory reporting obligations.
  • Track incident timelines, actions, evidence, and closure activities.
  • Coordinate vulnerability disclosures, security advisories, and stakeholder communications.
  • Support crisis-level response activities, provide coverage and executive reporting when required.

Secondary Responsibilities:

  • Perform regulatory assessments
  • Audit support and preparation
  • Assessment reporting/tracking
  • User documentation
  • Confluence updates
  • Mailbox monitoring

Cross-Functional Collaboration

  • Coordinate activities across Product Security, Governance & Compliance, Legal, Customer Support, Quality, and Engineering organizations.
  • Facilitate alignment between technical teams and business stakeholders during security events.
  • Present incident status, risk assessments, and compliance updates to leadership.
  • Drive continuous improvement of PSIRT processes, workflows, and reporting capabilities.
  • Partner with R&D, Product Management, Security Champions, and Security teams to assess vulnerabilities and remediation plans.
  • Provide guidance on risk evaluation, exploitability, customer impact, and remediation strategies.

Regulatory Compliance and Governance

  • Support implementation and operationalization of product security regulations and frameworks, including: o EU Cyber Resilience Act (CRA) o CISA Secure Software Development Attestation o Vulnerability Disclosure and Coordinated Vulnerability Disclosure (CVD) requirements

  • Assist with product security compliance assessments and audit readiness activities.

  • Support crisis-level response activities, including on-call coverage and executive reporting during major incidents.

  • Contribute to compliance dashboards, metrics, and process improvement initiatives.

Skills and Requirements

  • Bachelor’s degree in computer science, Cybersecurity, Information Technology, or equivalent experience.

  • 4-5 years of experience in one or more of the following: o Security incident response o Product security o Software or hardware development o Secure software development lifecycle (SSDLC) o Vulnerability management o Security engineering

  • Experience working directly with technical engineering teams.

  • Understanding of common security concepts including: o Security testing methodologies o CVEs and CVSS scoring o Secure development practices

  • Self-motivated and proactive, with a positive attitude and willingness to take ownership of problems through resolution.

  • Flexible and adaptable, with the ability to support a variety of product security activities beyond incident response, including compliance assessments, audit readiness activities, regulatory initiatives, and policy development.

  • Ability to prioritize competing demands and remain effective in fast-paced or time-sensitive situations.

  • Excellent written and presentation communication skills, including the ability to communicate effectively with both technical and non-technical audiences.

  • Strong documentation skills, including development of reports, incident records, compliance evidence, and executive summaries.

  • Experience participating in or leading a PSIRT, CSIRT, SOC, Security Engineering, Product Security, or Incident Response team.

  • Familiarity with product security regulations and standards such as CRA, NIST SSDF, IEC 62443, ISO 27001, or CISA guidance.

  • Experience supporting compliance assessments, audits, attestations, or cybersecurity governance programs.

  • Knowledge of software development, DevSecOps, cloud platforms, embedded systems, or hardware development environments.

  • Experience with vulnerability disclosure programs and external security researchers.

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to [email protected].

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.