08 ago
|
Materialise
|
Barcelona
08 ago
Materialise
Barcelona
As the Product Security Lead of Materialise Software, you will be accountable for the overall security posture and regulatory compliance of our products. You translate complex security regulations, customer expectations, and risk into clear decisions, priorities, and trade-offs, enabling product and engineering teams to deliver securely at scale. You own the security outcomes and risk decisions, not day‑day security implementation.What you will doKey Accountabilities And Core ResponsibilitiesOverall product security posture across our portfolio (CO-AM Platform, Magics)Interpretation of security legislation, standards, and customer requirements (e.G., ISO 27001, NIS2, NIST-based frameworks)Definition of product security objectives and non-functional requirementsExplicit risk acceptance and exception managementProduct security strategy, roadmap, and prioritizationExternal security posture towards customers, auditors, and regulatorsRegulation and riskAssess the applicability of security regulations and standardsDefine pragmatic compliance intent and scopeIdentify, document, and accept residual product security risksEnsure risks and exceptions are explicit, time-bounded, and ownedStrategy and alignmentDefine and maintain a product security strategy aligned with business goalsTranslate regulatory and risk drivers into a prioritized security roadmapAlign security priorities with product and engineering planning cyclesCross-functional leadershipPartner closely with the:Product Management Team on roadmap alignment and customer commitmentsEngineering Management Team on delivery realities and investment trade-offsDev Sec Ops Lead on platform-level security objectivesSecurity Architect on translating intent into secure designsCISO to align product security decisions with enterprise risk posture and regulatory obligations where applicableAct as an escalation point when security, product, and delivery priorities conflictSupport the Engineering Delivery teams and Security Champions, such as improving their understanding of the security checklistGovernance and external trustReview security metrics and evidence produced by security engineeringSupport audits, certifications, and customer security assessmentsRepresent the company’s product security posture externally when requiredWhat this role does not doDesign detailed system architecturesBuild or operate security toolingReview code or manage vulnerabilities day-to-dayDirectly manage security champions or software engineersYour profileRequired Skills And ExperienceStrong understanding of product and cloud security in modern Dev Ops environmentsExperience working with security regulations and frameworks (ISO 27001, NIS2, SOC 2, NIST, Fed RAMP, or similar)Proven ability to make and defend risk-based decisions Credibility with senior engineering and product stakeholdersClear written and verbal communication, especially around trade-offsExperience profile8+ years in software engineering, product security, or security leadership rolesExperience in product-centric, engineering-driven organizationsExposure to regulated environments is strongly preferredSuccess looks likeSecurity expectations are clear and predictable for product and engineeringRisk acceptance is explicit, documented, and rarely escalated lateEngineering teams ship securely by default using platform guardrailsAudits and customer security reviews are uneventful and well-prepared
📌 Product Security Lead (Barcelona)
🏢 Materialise
📍 Barcelona