Back to Jobs
Head of Product, Cyber

Head of Product, Cyber

Full-time
Hybrid - Ho Chi Minh City, Vietnam
Reports to: CEO

About the Position

CloudThinker Cyber is an autonomous offensive security platform. Agents attack your applications and APIs the way a real adversary would, prove every finding with a reproducible exploit, then open the merge request that closes it. As Head of Product, Cyber you own that product end to end: the strategy, the roadmap, the pricing, and the standard of proof it ships against. You sit between offensive security reality and the agent platform that automates it, and you are accountable for one thing above all: whether security teams trust what the agents put in their queue.

What You'll Do

  • Own the Cyber product strategy and roadmap end to end, from attack surface mapping through proof of exploit, drafted patch, and automatic retest
  • Set the standard of proof: define what qualifies as a finding, what the validator must reproduce before anything reaches a customer queue, and what gets dropped in silence
  • Own rules of engagement as product surface: scoping, production excluded by default, rate limiting, non-destructive validation, and the exportable audit log
  • Decide where agents act autonomously and where a human approves, then move that line with evidence rather than opinion
  • Work directly with AppSec engineers, security leads, and CISOs, and turn their triage reality into the roadmap
  • Partner with engineering on coverage, depth, and false-positive rate, and treat precision as the product metric that matters most
  • Own the compliance-facing output: OWASP API Top 10 coverage and evidence auditors accept for SOC 2, ISO 27001, and PCI DSS
  • Position Cyber against scanners, DAST, and point-in-time pentesting, including pricing, packaging, and the story that makes the difference obvious in one slide
  • Run the launch loop with marketing and sales: messaging, demos, design partners, and the reference customers who prove it works

Requirements

  • 5+ years in product management with real depth in security tooling: AppSec, offensive security, DAST/SAST, cloud security, or a security platform practitioners used daily
  • Hands-on offensive security understanding: you can read an attack path, judge whether an exploit actually proves the finding, and tell a real chain from a scanner's guess
  • You have shipped a product security engineers used daily, and you know why they ignore most of what lands in their queue
  • Track record owning a product line end to end: strategy, roadmap, pricing, launch, and the number it moved
  • Comfortable building on agents and LLMs, with a clear view of where autonomy earns trust and where it destroys it
  • You drive AI agents (CloudThinker, Claude Code, Codex) as your primary leverage: specify, delegate, review, correct
  • Customer-facing range: discovery with a security engineer in the morning, a CISO briefing in the afternoon, in Vietnamese and English
  • Strong written communication, because most of the decisions you make will be read rather than presented
  • Nice to have: OSCP or an equivalent hands-on offensive credential, bug bounty history, or time on an internal red team
  • Nice to have: experience selling into regulated industries, or building compliance evidence products

What We Offer

  • Own a product line at founding stage, with the engineering team one desk away
  • Direct line to the founding team and real ownership of where Cyber goes
  • High ownership, real impact, and minimal bureaucracy
  • Competitive compensation and a hybrid working model with flexibility to work from home
  • Learning and development budget
  • Long-term growth opportunities as the team scales

What Success Looks Like

First 90 days

You know the queue. Design partners onboarded, their triage workflow mapped end to end, and a roadmap that names the false-positive rate and the coverage gaps you are attacking first.

First 6 months

Cyber shipping on a predictable cadence against a defined standard of proof. Rules of engagement, scoping, and audit output good enough that a security team hands you production scope on purpose. Pricing and packaging live.

First year

Named reference customers who closed real vulnerabilities through merge requests the agents opened. Cyber sold as its own product with its own pipeline, and a product team hired under you.

Interested in this position?

apply --role "Head of Product, Cyber"

$ ./apply.sh

We don't screen resumes for keywords. Answer a few quick prompts and we'll read every word.

step 1 / 3

Prefer plain email? Write to careers@cloudthinker.io

Why Join CloudThinker?

Innovative Work

Work on cutting-edge AI technology that's transforming cloud operations

Flexible Environment

Modern office space in Vinhomes Grand Park with a collaborative work environment

Growth Opportunities

Long-term career development in a creative and empowering environment