Sandisk
Product Security Assurance Architect
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About Sandisk
SanDisk is a leading American technology company based in Milpitas, California, focused on designing and manufacturing flash memory storage products. Founded in 1988, the company has a rich history of innovation, including the development of the first flash-based SSD in 1991 and the co-invention of the SD card. SanDisk operates globally, with manufacturing facilities in China and offices in over a dozen countries. The company offers a diverse range of products, including memory cards, USB flash drives, and solid-state drives (SSDs). Their memory cards include CompactFlash and SD cards, while their USB drives feature rugged models used in various applications. SanDisk also provides enterprise SSDs and embedded flash solutions for mobile devices and other electronics. Their products are available through multiple channels, including direct sales, OEMs, and retail locations worldwide.
Security at Sandisk
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Protecting data is critical to users.
- SanDisk's PSIRT mission is to protect the security of end users.
- Philosophy emphasizes following and promoting a secure design mindset from conception to productization.
- Risk management focuses on driving threat modeling and reference embedded security architectures for product lines.
Security Team
Org Structure & Reporting Line: Information not publicly available regarding specific internal reporting lines beyond the CISO. Key Public-Facing Leaders: Phil Malatras, Chief Information Security Officer (CISO). Team Size Estimate: ~10-20 (Estimated based on Western Digital parent org integration). Active AppSec Job Postings: 2. Common Skill/Tool Patterns: Threat modeling, embedded security architectures, and Information Security Governance.
Key Initiatives
- Shift Left: Follow and promote a secure design mindset from conception to productization.
- Vulnerability Management Process: Reports sent to PSIRT@sandisk.com with acknowledgment within 3 business days and remediation within 90 days.
- Secure SDLC Artifacts: Drive threat modeling and reference embedded security architectures.
- Note: SanDisk explicitly states they do not have a standing bug bounty program.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.