"Head of Product" sounds like a product manager, it doesn't even sound like an engineer at all - this makes it even less surprising that these pathetic security holes existed.
Just to be clear, that means my assumptions you lambasted were generous. Not folly.