Nvidia - Santa Clara, CA

posted 5 months ago

Full-time - Mid Level
Santa Clara, CA
Computer and Electronic Product Manufacturing

About the position

NVIDIA's Product Security Incident Response Team (PSIRT) is seeking a passionate and innovative Technical Program Manager (TPM) to enhance our vulnerability management and incident response capabilities. The TPM will play a crucial role in managing vulnerabilities across NVIDIA's diverse product lines, which include GPUs, cloud software, AI/ML, enterprise servers, automotive components, and embedded devices. The ideal candidate will be responsible for improving internal software security response procedures, prioritizing both public and internal vulnerability remediation, and collaborating with engineering teams to ensure the effective resolution of security issues. In this role, the TPM will craft and implement processes and program improvements to elevate NVIDIA's vulnerability handling and incident response capabilities. This includes managing the receipt, resolution, and disclosure of security vulnerabilities, engaging directly with virtual security teams, engineering partners, and internal support teams to drive issues to long-term resolution. The TPM will also communicate the status of PSIRT involvement at all levels of management, draft publications for security vulnerability disclosures, and champion continuous improvement efforts related to security activities across NVIDIA. Additionally, the TPM will engage with the broader industry security community to stay at the forefront of security trends and requirements. As an NVIDIAN, you will be immersed in a diverse and supportive environment where everyone is encouraged to do their life's work. This position offers the opportunity to make a lasting impact on the world through innovative security practices and collaboration with talented professionals.

Responsibilities

  • Craft and implement PSIRT processes and program improvements to elevate NVIDIA's vulnerability handling and incident response capabilities.
  • Handle the receipt, resolution, and disclosure of security vulnerabilities across NVIDIA product lines.
  • Engage directly with virtual security teams, engineering partners, and internal support teams to drive issues to long-term resolution.
  • Communicate status of PSIRT involvement at all levels of management, both internal and external.
  • Draft publications for the security vulnerability disclosures as well as lower-severity security-impacting defects.
  • Champion continuous improvement efforts related to security activities across NVIDIA.
  • Engage with the broader industry security community and stay at the forefront of industry security trends and requirements.

Requirements

  • Quickly scale knowledge while being mentored by leaders.
  • Ability to understand technical issues at a high level on a wide range of topics.
  • Leadership skills to step up and identify resolutions that are best for NVIDIA and its customers, even if that means going beyond the initial ask.
  • Effective written and verbal communication regardless of audience or issue complexity.
  • Ability to work cross-functionally and remotely with other teams to accomplish sophisticated goals.
  • Experience with some of the following standards or processes: CVSS, CWE, SDLC, SBOM, VEX, CSAF, threat modeling.
  • Knowledge of industry practices for responsible disclosure of security threats and product vulnerabilities.
  • BS/BA degree or equivalent experience.
  • 5+ years in a Program or Project Management field.
  • 8+ years of relevant security experience.

Nice-to-haves

  • Proven experience driving customer-facing issues (security preferred) effectively and efficiently.
  • Experience in a previous PSIRT, security development lifecycle (SDL), or bug bounty management role.
  • Understanding of software release processes, e.g. Agile, Unit Testing, etc.
  • Ability to write SQL scripts, experience with REST APIs, or build reporting dashboards.

Benefits

  • Equity options
  • Comprehensive health benefits
  • Flexible work environment
  • Diversity and inclusion programs
  • Ongoing learning and development opportunities
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service