Technical Product Manager - Authorization Tooling - CTO Office
Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Communication @ 7
Distributed Systems
GDPR @ 4
Leadership @ 7
Observability
Security @ 7
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
The CTO Security Service Infrastructure group solves complex systems problems, enabling engineers to quickly ship products and prototype next-generation infrastructure security technologies. The team designs security controls, threat models distributed systems, and defines how Bloomberg secures its infrastructure.
As a product owner in the CTO’s Office, this role focuses on Bloomberg’s home-grown authorization tooling: the platforms and services that govern what people and systems are permitted to do after authentication. The role partners closely with engineering to maintain state-of-the-art tooling, evaluates in-house approaches against industry alternatives, anticipates emerging authorization needs, and defines how authorization is designed, delivered, and governed across the firm.
Responsibilities
- Partner with engineering counterparts to evolve home-grown authorization tooling alongside changing platforms, technologies, and security requirements.
- Evaluate build, buy, and reuse trade-offs against organizational needs and the state of the industry.
- Work with stakeholders across engineering, product, and business teams to anticipate future authorization needs.
- Own prioritization of development efforts while balancing security, usability, scalability, and delivery timelines.
- Lead the creation of roadmaps, metrics, and OKRs.
- Define and track metrics measuring the health, performance, and current state of authorization tooling.
- Contribute to the strategy and vision for authorization across the firm and translate it into implementation priorities.
- Establish an understanding of authorization workflows, dependencies, pain points, and future-state opportunities.
- Produce product requirements, architecture direction, implementation guidance, RFCs, and design rationale.
- Ensure appropriate auditing, reporting, and observability for authorization workflows and related controls.
- Assess risks and identify opportunities to strengthen authorization models and controls.
- Collaborate with vendors, consultants, and industry peers to stay informed about authorization and access management technologies.
Requirements
- 7+ years of experience building, maintaining, and managing security aspects of large-scale distributed infrastructure and applications.
- Strong experience with authorization and access control technologies, with an emphasis on security, integration, and automation.
- Sufficient technical depth to understand system interactions, different technologies and access models, and their implications for authorization tooling.
- Experience building collaborative relationships across functions and leading through influence to establish consensus and execute initiatives.
- Ability to collect and document detailed product requirements, including RFCs, design rationale, and decision-making.
- Experience determining when to build, buy, or reuse solutions.
- Deep knowledge of authorization and access control concepts and standards and their adoption in large enterprises.
- Strong written and oral communication skills, including presenting complex topics to senior leadership.
Preferred Qualifications
- Ability to build proof-of-concept solutions and prototype approaches and partner with engineering teams to drive adoption.
- Experience handling regulatory requirements such as GDPR, DORA, and HIPAA.
- Experience integrating with and securing a combination of in-house-developed and third-party solutions.
Compensation and Benefits
- Annual salary range: USD 240,000–330,000.
- Benefits and bonus are included in the total rewards offering.
- Benefits may include merit increases, incentive compensation for exempt roles, paid holidays, paid time off, medical, dental, vision, short- and long-term disability benefits, 401(k) matching, life insurance, and wellness programs.