About the Role
This is not a traditional software PM role — it requires deep practitioner fluency across security operations, GRC, consulting delivery, and incident response. You will own the design, packaging, and continuous improvement of Vervation's service portfolio: defining what we offer, how it is scoped, how it is priced, and how it is delivered consistently at scale.
Requirements
Vervation LLC is seeking a Security Services Product Manager who has lived inside the disciplines they will now shape. This is not a traditional software PM role — it requires deep practitioner fluency across security operations, GRC, consulting delivery, and incident response. You will own the design, packaging, and continuous improvement of Vervation's service portfolio: defining what we offer, how it is scoped, how it is priced, and how it is delivered consistently at scale. You are the connective tissue between client-facing delivery, business development, and executive strategy — translating field experience into repeatable, differentiated services that win in a competitive market.
Service portfolio ownership
Define, scope, and maintain the full Vervation services catalog across all practice areas
Develop service packaging tiers (advisory, project, retainer) with clear deliverable definitions
Build and maintain service runbooks, delivery standards, and quality benchmarks
Identify gaps in portfolio against market demand and competitive landscape
SecOps service design
Package SOC advisory, threat detection program builds, and SIEM/EDR consulting services
Define detection engineering and threat hunting service tiers for SMB and enterprise clients
Develop managed security service adjuncts and third-party MSSP partnership models
Establish security monitoring KPIs and outcome metrics for client reporting
GRC service development
Own design of GRC assessment, policy, and compliance offerings (NIST, CIS, ISO 27001)
Integrate AI governance service lines aligned to NIST AI RMF and emerging regulation
Create maturity models and scoring frameworks that drive repeatable client outcomes
Translate framework changes (CSF 2.0, CMMC updates) into updated service offerings
Incident response offerings
Design IR retainer and break-glass engagement models with clear SLA structures
Build tabletop exercise and crisis simulation service packages
Develop post-incident review and lessons-learned advisory services
Align IR services to cyber insurance requirements and compliance mandates
Go-to-market & sales enablement
Produce capability decks, one-pagers, and pricing guides for BD and vCISO engagements
Define ideal client profiles and target verticals for each service line
Partner with BD to build qualifying criteria and proposal templates
Own competitive positioning and differentiation narrative across the portfolio
Delivery excellence & ops
Build scalable delivery processes, project templates, and consultant onboarding guides
Establish client satisfaction feedback loops and drive continuous service improvement
Manage subcontractor and partner service integration into the Vervation delivery model
Own service-level reporting, utilization tracking, and margin analysis
Ideal Candidate Background
Former SOC analyst, IR lead, or security engineer who moved into GRC or consulting — you've seen threats from the inside and translated that to governance
Consulting firm alumni (Big 4, boutique MSSP, or independent) who have scoped and priced security engagements and understand what makes a service profitable
Security program leads at mid-market or enterprise companies who built something from scratch and want to commercialize that operational knowledge
vCISO practitioners who want to move upstream — from delivering services to designing and scaling them across a growing firm
Candidates with cross-domain certs (CISSP + GCIH, or CISM + IR experience) signal the practitioner breadth this role demands
About the Company
Vervation LLC is seeking a Security Services Product Manager who has lived inside the disciplines they will now shape.
