Job Description
APPLICATION DEADLINE: We encourage you to apply soon if interested, this role will be taken offline based on applicant volume.
Who We Are
M-Files is redefining how work gets done. Our context-first document management system offers purpose-built business use cases—spanning universal and industry-specific workflows—to enable secure collaboration, automate processes, and ensure governance.
Unlike traditional systems, M-Files organizes content around the context of your business, connecting documents to related people, projects, and transactions. With our unique metadata-driven architecture, organizations can model content in line with their business processes, unify information across silos, and apply AI at scale. The result is greater productivity, reduced risk, and smarter, faster decisions for over 6,000 customers in 100+ countries.
To learn more about us we encourage you to visit http://www.m-files.com/
The Product Security Manager leads M-Files' Product Security team and is the technical security authority for M-Files products and the M-Files Cloud service, including our growing AI-native capabilities. This role combines hands-on technical work with team leadership. You will set the Product Security strategy and roadmap, prioritize the team's work, and help make product security a strength our customers can rely on.
You will work closely with Information Security & Compliance, Product Engineering, Cloud Operations, and external auditors to keep M-Files secure by design, audit-ready, and trusted by our customers.
What you will be doing / Key responsibilities and duties
As Product Security Manager, you lead the Product Security team and contribute hands-on across the technical areas below, working alongside your team members.
Team Leadership
- Lead and prioritize the work of the Product Security team, collaborating with team members to identify and resolve security problems.
- Own the Product Security strategy and roadmap and represent Product Security in the wider Product organization's planning.
- Coach developers and Security Champions; raise the technical security baseline company-wide.
- Build a strong, technically credible team that keeps up with M-Files' growth.
- Drive AI adoption in the team's own work to improve efficiency and coverage of security activities.
Secure Development Lifecycle
- Work with engineering leadership to embed the secure development lifecycle across the product organization.
- Lead threat modeling with Product Engineering, security assessments, secure coding guidance, and AI-assisted and manual code reviews on higher-risk changes.
- Ensure security testing tools (SAST, DAST, SCA, container scanning) are effectively integrated into CI/CD pipelines.
- Own software supply chain security, including SBOM generation and dependency monitoring.
- Maintain security-related policies, SOPs, and guidelines for the product organization, aligned with our certifications (ISO/IEC 27001, ISAE 3000 / SOC 2, ISO 9001).
Vulnerability Management & Advisory Process
- Lead the design and implementation of the vulnerability advisory process.
- Establish vulnerability disclosure policies and coordinate responsible disclosure programs.
- Support incident response efforts for product security vulnerabilities.
- Develop metrics and reporting frameworks for vulnerability management effectiveness.
- Run the external penetration testing program end to end, feeding findings into the vulnerability management workflow.
Cloud Security
- Participate in cloud security planning across M-Files, working with the cloud and engineering teams responsible for building and operating cloud services.
- Take ownership of cloud security posture management, driving Microsoft Defender for Cloud recommendations to closure across Azure environment.
- Contribute to cloud security monitoring and incident response, working with the Microsoft security stack (Defender, Sentinel).
Customer, Legal & Compliance
- Support customer-facing security work and internal collaboration with Legal, Privacy, and Compliance on regulatory and certification matters (e.g. GDPR, SOC 2, ISO/IEC 27001).
Requirements
Qualifications and Skills
- Bachelor's or Master's degree in Computer Science, Information Security or a related technical field.
- 5+ years of hands-on experience in product security or application security, with a track record of implementing security programs at enterprise scale and readiness to lead or mentor a technical team.
- Strong understanding of cloud-native architectures, including AKS / Kubernetes, container security, and cloud security posture management.
- Deep knowledge of the secure development lifecycle: threat modeling, security architecture review, secure coding standards (OWASP ASVS / Top 10), SAST/DAST/SCA tooling, and interpreting penetration testing findings.
- Practical experience with vulnerability management, CVSS scoring, prioritization across multiple product lines, and driving remediation through engineering teams.
- Experience or strong interest in using AI tools to make security work more efficient (e.g. AI-assisted code review, threat modeling, or reporting).
- Working knowledge of security and compliance frameworks and regulations (e.g. SOC 2, ISO/IEC 27001, GDPR, NIS 2, CRA).
- Excellent written and verbal communication skills, with the ability to translate technical security concepts for non-technical and executive audiences.
- Relevant security certifications are appreciated — for example, Microsoft security certifications (SC-100, AZ-500), OSCP, or CSSLP.
- Please note: This role is based in Finland. We do not offer relocation support or visa sponsorship for this position. Applicants must already have valid residency and work authorization in Finland
Benefits
What We Offer
- A dynamic, supportive, and international team culture where your ideas matter.
- Clear career progression and personal development opportunities.
- Access to world-class sales and marketing technology.
- Competitive salary and uncapped commission structure.
- Flexible remote work, with opportunities to travel for team meetings and events.
- The chance to make a real impact at a fast-growing, innovative company.
Does this sound exciting to you?
If this sounds exciting to you, apply soon, but the latest by October 11th, 2026.
Note: Applications are reviewed on a rolling basis and the position will be filled as soon as we find the right candidate.
We are not sponsoring relocation for this role and will only consider applicants based in Finland (Valid residency and work authorization required)