---
title: Product Security Governance Principal at Fifththird
description: Fifththird is hiring for the Product Security Governance Principal role in Cincinnati,
  OH. Full-time role. See the full description and apply.
type: job
url: https://www.foundrole.com/jobs/product-security-governance-principal-at-fifththird-01a10f62-a719-74f5-a641-162f2ddba062
date: 2026-10-06T04:21:14Z
og_description: Join Fifththird as Product Security Governance Principal in Cincinnati, OH. Pays
  $96.5K–$207.5K per year. Full-time role.
og_image: https://www.foundrole.com/og/fgm4h1.png
breadcrumbs:
  - label: Home
    url: https://www.foundrole.com/
  - label: Search
    url: https://www.foundrole.com/jobs
---

| | |
|---|---|
| **Company** | Fifththird |
| **Location** | Cincinnati, OH |
| **Salary** | $96.5K/yr - $207.5K/yr |
| **Type** | Full Time |
| **Posted** | Oct 02, 2026 |
## Description

**Make banking a Fifth Third better®**  
We connect great people to great opportunities. Are you ready to take the next step? Discover a career in banking at Fifth Third Bank.

**Core Competencies**

- Governance leadership and sound risk judgment
- Evidence-based assurance and control evaluation
- Customer trust, readiness, and compliance coordination
- Clear executive, audit, business, and technical communication
- Cross-functional influence and constructive challenge
- Independent execution, accountability, and follow-through
- Scalable process design and continuous improvement

**Key Responsibilities**

**Product Security Governance**

- Lead and mature Product Security governance for internally developed customer-facing software, APIs, SDKs, integrations, and related services.
- Define product scope, engagement criteria, review expectations, decision authorities, escalation paths, and evidence standards.
- Develop and maintain standards, procedures, playbooks, templates, decision records, risk records, and supporting guidance.
- Facilitate risk-based decisions involving security requirements, control applicability, exceptions, compensating controls, and accountability.
- Align Product Security practices with established enterprise architecture, application security, vulnerability management, risk, compliance, audit, and engineering processes.

**Customer Assurance**

- Lead a scalable customer assurance model for applicable products and services.
- Coordinate accurate, reviewable security summaries, whitepapers, assessment responses, and supporting evidence.
- Evaluate customer-facing security statements for appropriate scope, context, qualifications, and evidence.
- Partner with Product, Engineering, Risk, Compliance, Legal, Audit, and customer-facing teams to support customer, deal, regulatory, and audit needs.
- Establish traceability between assurance statements, controls, evidence sources, and accountable owners while increasing consistency and response efficiency.

**SOC 2 and Readiness Coordination**

- Lead Product Security coordination for applicable SOC 2 and related readiness activities within established enterprise compliance and audit processes.
- Support system scoping, business-requirement validation, readiness evaluations, gap assessments, evidence coordination, and assessment-provider engagement.
- Partner with control owners to evaluate control design, evidence requirements, operating effectiveness, and improvement opportunities.
- Maintain readiness plans, evidence inventories, dependencies, decisions, and accountable action tracking.
- Translate assessment observations into sustainable improvements while preserving appropriate separation from independent audit or attestation responsibilities.

**Product Risk and Evidence**

- Define consistent expectations for product readiness assessments and product-level security evidence.
- Evaluate evidence from established activities such as threat modeling, penetration testing, security scanning, software supply chain practices, secure development, incident management, and remediation.
- Assess evidence for completeness, relevance, recency, traceability, and applicability, including the context and limitations of technical tools.
- Develop consolidated views of product security risk, control adoption, coverage, and assurance readiness.
- Establish meaningful indicators and reporting that demonstrate Product Security adoption, maturity, decisions, and accountable actions.

**Program Operations and Continuous Improvement**

- Lead governance forums, readiness reviews, working sessions, and decision meetings.
- Identify recurring themes and recommend scalable improvements to controls, evidence, processes, and stakeholder guidance.
- Provide concise updates and practical recommendations to technical teams, business stakeholders, and senior leaders.
- Contribute to Product Security strategy, planning, prioritization, and roadmap development.
- Promote shared accountability for secure and trusted customer-facing products.

**Required Qualifications**

- Seven or more years of progressively responsible experience in Product Security, security governance, cybersecurity assurance, IT risk, security compliance, technology audit, security architecture, or a related discipline.
- Demonstrated success leading security governance, assurance, readiness, control evaluation, gap analysis, or evidence-review practices in a complex organization.
- Proven ability to independently evaluate technical and nontechnical evidence, identify material concerns, exercise sound judgment, and recommend defensible decisions.
- Substantial experience translating security and compliance requirements into practical expectations for product and engineering teams.
- Demonstrated ability to influence senior stakeholders, facilitate constructive challenge, resolve ambiguity, and drive accountable outcomes across Product, Engineering, Information Security, Risk, Compliance, Audit, Legal, and business teams.
- Strong understanding of administrative, technical, and operational security controls and how they work together throughout the product lifecycle.
- Experience maintaining governance artifacts such as standards, procedures, control matrices, evidence inventories, decision records, risk records, and action plans.
- Strong executive, business, audit, and technical communication skills.
- Bachelor’s degree in cybersecurity, information technology, information systems, business, accounting, or a related field, or an equivalent combination of education and relevant experience.

**Preferred Qualifications**

- Experience building or maturing a Product Security program in financial services, another regulated industry, or a complex enterprise.
- Experience supporting SOC 2 readiness, including system scoping, Trust Services Criteria, evidence coordination, gap assessment, and action tracking.
- Experience with customer-facing software, APIs, SDKs, SaaS platforms, cloud-native services, or distributed products.
- Familiarity with ISO/IEC 27001, NIST CSF, PCI DSS, cloud shared-responsibility models, and modern software-development practices.
- Experience developing customer assurance materials, product security summaries, security whitepapers, or similar artifacts.
- Experience with governance, risk, compliance, workflow, evidence-management, or reporting platforms.
- Relevant credentials such as CISSP, CISA, CISM, CRISC, CCSP, or ISO 27001 Lead Implementer or Auditor.

**Position not eligible for immigration sponsorship.**

Product Security Governance Principal

Total Base Pay Range 96,500.00 - 207,500.00 USD Annual

At Fifth Third, we understand the importance of recognizing our employees for the role they play in improving the lives of our customers, communities and each other. Our Total Rewards include comprehensive benefits and differentiated compensation offerings to give each employee the opportunity to be their best every day.

The base salary for this position is reflective of the range of salary levels for all roles within this pay grade across the U.S. Individual salaries within this range will vary based on factors such as role, relevant skillset, relevant experience, education and geographic location. In addition to the base salary, this role is eligible to participate in an incentive compensation plan, with any such payment based upon company, line of business and/or individual performance.

Our extensive benefits programs are designed to support the individual needs of our employees and their families, encompassing physical, financial, emotional and social well-being. You can learn more about those programs on our 53.com Careers page at: <https://www.53.com/content/fifth-third/en/careers/benefits.html> or by consulting with your talent acquisition partner.

LOCATION -- Virtual, Ohio 00000

Attention search firms and staffing agencies: do not submit unsolicited resumes for this posting. Fifth Third does not accept resumes from any agency that does not have an active agreement with Fifth Third. Any unsolicited resumes – no matter how they are submitted – will be considered the property of Fifth Third and Fifth Third will not be responsible for any associated fee.

Fifth Third Bank, National Association is proud to have an engaged and inclusive culture and to promote and ensure equal employment opportunity in all employment decisions regardless of race, color, gender, national origin, religion, age, disability, sexual orientation, gender identity, military status, veteran status or any other legally protected status.
## Skills

- Cloud Computing
- Cyber Security
- Influencing
- ISO/IEC 27001 Lead Implementer
- Enterprise Architecture
- Application Security
- Information Technology
- Penetration Testing
- SOC 2 Compliance
- IT Risk Management
- Certified Information System Auditor (Cisa)
- Certification in Risk and Information Systems Control
- PCI DSS
- Cloud-Native Computing
- Process Design
- Evidence Management
- Planning
- Prioritization
- ISO/IEC 27002
- Certified Information Security Manager
- Certified Information Systems Security Professional
- Product Security
- Security Compliance
- Continuous Improvement Process
- Software Development
- Information Systems
- Gap Analysis
- Vulnerability Scanning
- Financial Services
- NIST Cybersecurity Framework
- Supply Chain
- Auditing
- Coordinating
- Software Development Kit (Sdk)
- Assertiveness
- Leadership
- Inventory Management
- Operations Security
- Incident Management
- Software as a Service (SaaS)
- Product Roadmaps
- Vulnerability Management
- Provider Engagement
- Communication
- Governance
- Equities
- Threat Modeling
- White Paper Writing
- IT Security Architecture

## Related

- [Technology & Software jobs](https://www.foundrole.com/careers/technology-and-software?utm_source=ai_markdown)- [Cybersecurity jobs](https://www.foundrole.com/careers/technology-and-software/cybersecurity?utm_source=ai_markdown)- [Security Compliance / GRC Analyst jobs](https://www.foundrole.com/careers/technology-and-software/cybersecurity/security-compliance-grc-analyst?utm_source=ai_markdown)- [Browse all companies](https://www.foundrole.com/companies?utm_source=ai_markdown)

## Explore this job market

- [Banking](https://www.foundrole.com/sectors/financial-services/banking?utm_source=ai_markdown) — 103507 jobs
- [Ohio](https://www.foundrole.com/locations/us/ohio?utm_source=ai_markdown) — 103051 jobs
- [Cincinnati, OH](https://www.foundrole.com/locations/us/ohio/cincinnati?utm_source=ai_markdown) — 9306 jobs

## Related pages

- [Banking](https://www.foundrole.com/sectors/financial-services/banking?utm_source=ai_markdown) — 103507 jobs
- [Ohio](https://www.foundrole.com/locations/us/ohio?utm_source=ai_markdown) — 103051 jobs
- [Cincinnati, OH](https://www.foundrole.com/locations/us/ohio/cincinnati?utm_source=ai_markdown) — 9306 jobs

## Browse

- [Companies](https://www.foundrole.com/companies?utm_source=ai_markdown)
- [Jobs by country](https://www.foundrole.com/locations?utm_source=ai_markdown)
- [Jobs in the United States by state and city](https://www.foundrole.com/locations/us?utm_source=ai_markdown)
- [H1B sponsors by location](https://www.foundrole.com/h1b-sponsors?utm_source=ai_markdown)
- [H1B salaries](https://www.foundrole.com/h1b-salaries?utm_source=ai_markdown)
- [Sectors and industries](https://www.foundrole.com/sectors?utm_source=ai_markdown)
- [Jobs by career field](https://www.foundrole.com/careers?utm_source=ai_markdown)
- [Latest jobs](https://www.foundrole.com/jobs/latest?utm_source=ai_markdown)