Github
### Who you are - 8+ years experience in product/service/project/program management, software development, product design, or related field - OR Bachelor's Degree in related field AND 6+ years experience in product/service/project/program management, software development, product design, or related field - OR equivalent experience - 2+ years in developing deep expertise in developer tools, developer platforms, or security products, enabling clear translation of developer requirements into roadmap-ready features - 3+ years people management experience - Experience owning a product area end to end as an individual contributor, and experience leading or developing other product managers - Hands-on experience with software supply chain security: SCA and dependency management, package registries and ecosystem tooling, SBOMs, provenance and attestations, or malware detection in open source packages - Experience directly managing product managers, including hiring, coaching across experience levels, and performance management - Track record of building a coherent product line out of separately managed capabilities, including the hard consolidation and deprecation calls - Experience with packaging, pricing, or consumption-based commercial model decisions - Proven cross-functional collaboration: You bring a history of success partnering with Engineering, Design, Sales, and Customer Success to deliver projects that involve complex technical problems ### What the job involves - We're looking for a Director of Product Management to own that portfolio and build the platform, so customers can answer one question: can I trust this software, and can I prove it? This is a player-coach role. You'll lead a PM team and carry direct product ownership of the hardest problems in the segment - One platform, not a set of tools. GitHub's supply chain capabilities are strong individually and don't yet add up to an experience a customer can reason about. You'll set the vision that unifies dependency security, artifact trust and provenance, and package governance, and make the branding, packaging, and unification calls that follow - The application graph. The real risk of a vulnerability, and what it takes to fix it, depends on how code, repos, artifacts, and applications connect. You'll build that connective tissue, turCan yning isolated findings into a clear picture of what's affected and what remediation requires - Risk that actually matters. Security teams are measured on what they fix, not what they find. You'll define how GitHub surfaces the risk worth acting on and carries a fix through to done, at a scale and ecosystem breadth no point solution can match - Trust as a default of shipping software. Verifiable provenance is still an expert workflow. You'll make it a normal property of building on GitHub, generated as software is created rather than reconstructed afterward, and applied to what developers and coding agents pull in alike - Analysis of Customer & Market Signals: - Prioritize customer needs through direct engagement with enterprise security teams, platform engineering leaders, and the open source community - Seek the truth in the usage data. Nobody has more of it than GitHub. Let evidence overrule assumptions about how the product is really performing - Turn the competitive landscape into roadmap decisions, not feature parity checklists - Product/Service Definition: - Own the vision and multi-year strategy for supply chain security, including what we build, what we bring together, what we retire, and where we don't play - Carry direct product ownership of the most strategically important problems in the segment - Define the metrics that show whether the portfolio is working, and hold the team to them - Team Leadership: - Lead and develop a team of product managers at varying seniority levels. Set the performance bar, coach, and own career development - Partner closely with your engineering and design leadership counterpart on staffing, delivery, and how the business operates - Go-To-Market & Delivery: - Own the partnership with Microsoft Security. Microsoft brings world-class security research, threat intelligence, and enterprise reach that we put to work in the developer and security workflows where fixes actually land - Shape packaging and pricing direction for the segment, and own its adoption and revenue outcomes - Carry the product vision to executive briefings, analysts, and the developer community, and provide thought leadership across GitHub and Microsoft ### Benefits - Flexible time away to support balance in your work and life - Clear diversity, inclusion, and anti-discrimination policies backed by business practices and company culture - 100% of medical, dental, and vision insurance premiums covered by GitHub for you + your dependents. (Includes gender-affirming benefits) - Five months of paid family leave to all new parents with the option to use it all at once or throughout the child’s first year - Family forming benefits that cover fertility, infertility, adoption, and surrogacy costs and support - Mental health benefits that offer resources and support and cover therapy and coaching sessions for you and your dependents - Generous 401(k) matching with 50% match up to the IRS 402(g) limit (US; competitive non-US pension options internationally) - Employee stock purchase plan that lets you purchase Microsoft stock at a discount. (Microsoft is our parent company.)
Company size reports differ between sources.
Company data includes TheirStack, LinkedIn observations · last observed Sep 23, 2026.
Work at github.com? Sign in to claim this org and manage its profile.