Senior Product Owner App Security (m/w/d)

At Myra, we develop and operate a certified Security-as-a-Service platform designed to protect digital business processes. Our technology monitors, analyzes, and filters malicious internet traffic before cyberattacks can cause actual damage.

The Senior Product Owner (m/f/d) Application Security is not a typical PO role. While most product roles focus on building and shipping features, you own both the security effectiveness and the day-to-day experience of four products - WAF, Bot Management, Captcha, and API Protection - that sit at the core of what Myra does. You are the closest person in the product organization to how security practitioners actually experience protection under real-world attack conditions - and your job is to make sure that both the outcomes delivered and the experience of operating these products are excellent.
  • Product vision and roadmap across WAF, Bot Management, Captcha, and API Protection - four products with a shared threat-model domain and a shared enterprise customer base.
  • Security effectiveness and usability in equal measure: the product must protect customers and be intuitive to configure, monitor, and operate. These are not competing priorities - they are both non-negotiable.
  • The end-to-end customer experience within each product: onboarding, configuration workflows, dashboards and reporting, alert management, and the operational interfaces that security teams use every day. Friction in any of these is a product problem you own.
  • Threat landscape tracking: new attack vectors, evasion techniques, OWASP updates, and CVE patterns relevant to application-layer security - translated into product decisions, not just awareness.
  • Competitive positioning across all four products - where Myra leads, where competitors have pulled ahead, and where market expectations are shifting.
  • Direct customer relationships with the security practitioners who use these products: engineers and architects making technical decisions, not mediated through sales.
  • Outcome Briefs for the engineering team: the customer problem, the measurable outcome, and the evidence that makes prioritisation defensible. You own the what. Engineering owns the how.
  • Deep Security Domain Expertise - Genuine, hands-on expertise in at least one of the four product areas: WAF, Bot Management, API Protection, or Captcha - with working fluency across the others.
  • Application Security Fundamentals - Strong understanding of how web application attacks work at a technical level, including OWASP Top 10, the HTTP request lifecycle, and application-layer defence mechanisms.
  • B2B SaaS Product Management Experience - Full product lifecycle ownership experience - writing Outcome Briefs, running evidence-based prioritisation, and measuring success through customer outcomes.
  • Usability Ownership in a Security Context - Proven experience owning not just the effectiveness of a security product but its operational experience - reducing friction for security teams without compromising protection.
  • Enterprise Security Buyer Understanding - Ability to navigate conversations with both CISOs and security engineers, including compliance frameworks such as PCI DSS, SOC 2, and ISO 27001 - without needing support from a solutions engineer.
  • Adversarial Thinking - Ability to evaluate every product decision through an attacker's lens - understanding how threat actors adapt and how that should shape roadmap and detection strategy.

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available