Senior Product Owner App Security (m/w/d)
At Myra, we develop and operate a certified Security-as-a-Service platform designed to protect digital business processes. Our technology monitors, analyzes, and filters malicious internet traffic before cyberattacks can cause actual damage.
The Senior Product Owner (m/f/d) Application Security is not a typical PO role. While most product roles focus on building and shipping features, you own both the security effectiveness and the day-to-day experience of four products - WAF, Bot Management, Captcha, and API Protection - that sit at the core of what Myra does. You are the closest person in the product organization to how security practitioners actually experience protection under real-world attack conditions - and your job is to make sure that both the outcomes delivered and the experience of operating these products are excellent.
The Senior Product Owner (m/f/d) Application Security is not a typical PO role. While most product roles focus on building and shipping features, you own both the security effectiveness and the day-to-day experience of four products - WAF, Bot Management, Captcha, and API Protection - that sit at the core of what Myra does. You are the closest person in the product organization to how security practitioners actually experience protection under real-world attack conditions - and your job is to make sure that both the outcomes delivered and the experience of operating these products are excellent.
- Product vision and roadmap across WAF, Bot Management, Captcha, and API Protection - four products with a shared threat-model domain and a shared enterprise customer base.
- Security effectiveness and usability in equal measure: the product must protect customers and be intuitive to configure, monitor, and operate. These are not competing priorities - they are both non-negotiable.
- The end-to-end customer experience within each product: onboarding, configuration workflows, dashboards and reporting, alert management, and the operational interfaces that security teams use every day. Friction in any of these is a product problem you own.
- Threat landscape tracking: new attack vectors, evasion techniques, OWASP updates, and CVE patterns relevant to application-layer security - translated into product decisions, not just awareness.
- Competitive positioning across all four products - where Myra leads, where competitors have pulled ahead, and where market expectations are shifting.
- Direct customer relationships with the security practitioners who use these products: engineers and architects making technical decisions, not mediated through sales.
- Outcome Briefs for the engineering team: the customer problem, the measurable outcome, and the evidence that makes prioritisation defensible. You own the what. Engineering owns the how.
- Deep Security Domain Expertise - Genuine, hands-on expertise in at least one of the four product areas: WAF, Bot Management, API Protection, or Captcha - with working fluency across the others.
- Application Security Fundamentals - Strong understanding of how web application attacks work at a technical level, including OWASP Top 10, the HTTP request lifecycle, and application-layer defence mechanisms.
- B2B SaaS Product Management Experience - Full product lifecycle ownership experience - writing Outcome Briefs, running evidence-based prioritisation, and measuring success through customer outcomes.
- Usability Ownership in a Security Context - Proven experience owning not just the effectiveness of a security product but its operational experience - reducing friction for security teams without compromising protection.
- Enterprise Security Buyer Understanding - Ability to navigate conversations with both CISOs and security engineers, including compliance frameworks such as PCI DSS, SOC 2, and ISO 27001 - without needing support from a solutions engineer.
- Adversarial Thinking - Ability to evaluate every product decision through an attacker's lens - understanding how threat actors adapt and how that should shape roadmap and detection strategy.