Product Security Manager - FINLAND
APPLICATION DEADLINE: We encourage you to apply soon if interested, this role will be taken offline based on applicant volume. Who We AreM-Files is redefining how work gets done. Our context-first document management system offers purpose-built business use cases—spanning universal and industry-specific workflows—to enable secure collaboration, automate processes, and ensure governance.Unlike traditional systems, M-Files organizes content around the context of your business, connecting documents to related people, projects, and transactions. With our unique metadata-driven architecture, organizations can model content in line with their business processes, unify information across silos, and apply AI at scale. The result is greater productivity, reduced risk, and smarter, faster decisions for over 6,000 customers in 100+ countries. To learn more about us we encourage you to visit http://www.m-files.com/
The Product Security Manager leads M-Files' Product Security team and is the technical security authority for M-Files products and the M-Files Cloud service, including our growing AI-native capabilities. This role combines hands-on technical work with team leadership. You will set the Product Security strategy and roadmap, prioritize the team's work, and help make product security a strength our customers can rely on.You will work closely with Information Security & Compliance, Product Engineering, Cloud Operations, and external auditors to keep M-Files secure by design, audit-ready, and trusted by our customers.What you will be doing / Key responsibilities and dutiesAs Product Security Manager, you lead the Product Security team and contribute hands-on across the technical areas below, working alongside your team members.Team LeadershipLead and prioritize the work of the Product Security team, collaborating with team members to identify and resolve security problemsOwn the Product Security strategy and roadmap and represent Product Security in the wider Product organization's planningCoach developers and Security Champions; raise the technical security baseline company-wideBuild a strong, technically credible team that keeps up with M-Files' growthDrive AI adoption in the team's own work to improve efficiency and coverage of security activitiesSecure Development LifecycleWork with engineering leadership to embed the secure development lifecycle across the product organizationLead threat modeling with Product Engineering, security assessments, secure coding guidance, and AI-assisted and manual code reviews on higher-risk changesEnsure security testing tools (SAST, DAST, SCA, container scanning) are effectively integrated into CI/CD pipelinesOwn software supply chain security, including SBOM generation and dependency monitoringMaintain security-related policies, SOPs, and guidelines for the product organization, aligned with our certifications (ISO/IEC 27001, ISAE 3000 / SOC 2, ISO 9001)Vulnerability Management & Advisory ProcessLead the design and implementation of the vulnerability advisory process. Establish vulnerability disclosure policies and coordinate responsible disclosure programsSupport incident response efforts for product security vulnerabilitiesDevelop metrics and reporting frameworks for vulnerability management effectivenessRun the external penetration testing program end to end, feeding findings into the vulnerability management workflowCloud SecurityParticipate in cloud security planning across M-Files, working with the cloud and engineering teams responsible for building and operating cloud servicesTake ownership of cloud security posture management, driving Microsoft Defender for Cloud recommendations to closure across Azure environmentContribute to cloud security monitoring and incident response, working with the Microsoft security stack (Defender, Sentinel)Customer, Legal & ComplianceSupport customer-facing security work and internal collaboration with Legal, Privacy, and Compliance on regulatory and certification matters (e.g. GDPR, SOC 2, ISO/IEC 27001)
Requirements
Qualifications and SkillsBachelor's or Master's degree in Computer Science, Information Security or a related technical field5+ years of hands-on experience in product security or application security, with a track record of implementing security programs at enterprise scale and readiness to lead or mentor a technical teamStrong understanding of cloud-native architectures, including AKS / Kubernetes, container security, and cloud security posture managementDeep knowledge of the secure development lifecycle: threat modeling, security architecture review, secure coding standards (OWASP ASVS / Top 10), SAST/DAST/SCA tooling, and interpreting penetration testing findingsPractical experience with vulnerability management, CVSS scoring, prioritization across multiple product lines, and driving remediation through engineering teamsExperience or strong interest in using AI tools to make security work more efficient (e.g. AI-assisted code review, threat modeling, or reporting)Working knowledge of security and compliance frameworks and regulations (e.g. SOC 2, ISO/IEC 27001, GDPR, NIS 2, CRA). Excellent written and verbal communication skills, with the ability to translate technical security concepts for non-technical and executive audiences. Relevant security certifications are appreciated — for example, Microsoft security certifications (SC-100, AZ-500), OSCP, or CSSLP. Please note: This role is based in Finland. We do not offer relocation support or visa sponsorship for this position. Applicants must already have valid residency and work authorization in Finland
Benefits
What We OfferA dynamic, supportive, and international team culture where your ideas matterClear career progression and personal development opportunitiesAccess to world-class sales and marketing technologyCompetitive salary and uncapped commission structureFlexible remote work, with opportunities to travel for team meetings and eventsThe chance to make a real impact at a fast-growing, innovative company
Does this sound exciting to you? If this sounds exciting to you, apply soon, but the latest by October 11th, 2026.
Note: Applications are reviewed on a rolling basis and the position will be filled as soon as we find the right candidate.
We are not sponsoring relocation for this role and will only consider applicants based in Finland (Valid residency and work authorization required)
