Skip to content

Open nowPosted 71 days ago

Senior Product Owner App Security (m/w/d)

myra16 open roles

Where
München
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Product Owner App Security (m/w/d)myra · München
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on myra's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 71 days ago

The posting

Job Description

At Myra, we develop and operate a certified Security-as-a-Service platform designed to protect digital business processes. Our technology monitors, analyzes, and filters malicious internet traffic before cyberattacks can cause actual damage.

The Senior Product Owner (m/f/d) Application Security is not a typical PO role. While most product roles focus on building and shipping features, you own both the security effectiveness and the day-to-day experience of four products - WAF, Bot Management, Captcha, and API Protection - that sit at the core of what Myra does. You are the closest person in the product organization to how security practitioners actually experience protection under real-world attack conditions - and your job is to make sure that both the outcomes delivered and the experience of operating these products are excellent.

Your Responsibilities

  • Product vision and roadmap across WAF, Bot Management, Captcha, and API Protection - four products with a shared threat-model domain and a shared enterprise customer base.
  • Security effectiveness and usability in equal measure: the product must protect customers and be intuitive to configure, monitor, and operate. These are not competing priorities - they are both non-negotiable.
  • The end-to-end customer experience within each product: onboarding, configuration workflows, dashboards and reporting, alert management, and the operational interfaces that security teams use every day. Friction in any of these is a product problem you own.
  • Threat landscape tracking: new attack vectors, evasion techniques, OWASP updates, and CVE patterns relevant to application-layer security - translated into product decisions, not just awareness.
  • Competitive positioning across all four products - where Myra leads, where competitors have pulled ahead, and where market expectations are shifting.
  • Direct customer relationships with the security practitioners who use these products: engineers and architects making technical decisions, not mediated through sales.
  • Outcome Briefs for the engineering team: the customer problem, the measurable outcome, and the evidence that makes prioritisation defensible. You own the what. Engineering owns the how.

Your Qualifications

  • Deep Security Domain Expertise - Genuine, hands-on expertise in at least one of the four product areas: WAF, Bot Management, API Protection, or Captcha - with working fluency across the others.
  • Application Security Fundamentals - Strong understanding of how web application attacks work at a technical level, including OWASP Top 10, the HTTP request lifecycle, and application-layer defence mechanisms.
  • B2B SaaS Product Management Experience - Full product lifecycle ownership experience - writing Outcome Briefs, running evidence-based prioritisation, and measuring success through customer outcomes.
  • Usability Ownership in a Security Context - Proven experience owning not just the effectiveness of a security product but its operational experience - reducing friction for security teams without compromising protection.
  • Enterprise Security Buyer Understanding - Ability to navigate conversations with both CISOs and security engineers, including compliance frameworks such as PCI DSS, SOC 2, and ISO 27001 - without needing support from a solutions engineer.
  • Adversarial Thinking - Ability to evaluate every product decision through an attacker's lens - understanding how threat actors adapt and how that should shape roadmap and detection strategy.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against myra's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on myra's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    myra's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.