13 ago
|
materialise
|
Barcelona
13 ago
materialise
Barcelona
Asthe Product Security Lead of Materialise Software, you will be accountable for the overall security posture and regulatory compliance of our products. You translate complex security regulations, customer expectations, and risk into clear decisions, priorities, and trade-offs, enabling product and engineering teams to deliver securely at scale. You own the security outcomes and risk decisions, not day-to-day security implementation.Key accountabilities and core responsibilitiesOverall product security posture across our portfolio(CO-AM Platform, Magics)Interpretation of security legislation, standards, and customer requirements(e.G., ISO 27001, NIS2, NIST-based frameworks)Definition of product securityobjectivesand non-functional requirementsExplicit risk acceptance and exception managementProduct security strategy, roadmap, and prioritizationExternal security posture towards customers, auditors, and regulatorsRegulation and riskAssess the applicability of security regulations and standardsDefine pragmatic compliance intent and scope Identify, document, and accept residual product securityrisks(Ensure risks and exceptions are explicit, time-bounded, and ownedStrategy and alignmentDefine andmaintaina product security strategy aligned with business goalsTranslate regulatory and risk drivers into a prioritized security roadmapAlign security priorities with product and engineering planning cyclesCross-functional leadershipPartnercloselywith the:Product Management Team on roadmap alignment and customer commitmentsEngineering Management Team on delivery realities and investment trade-offsDev Sec Ops Lead on platform-level security objectivesSecurity Architect on translating intent into secure designsCISO to align product security decisions with enterprise risk posture and regulatory obligations where applicableAct as an escalation point when security, product,
and delivery priorities conflictSupport the Engineering Delivery teams and Security Champions, such asimproving their understanding of the security checklistGovernance and external trustReview security metrics and evidence produced by security engineeringSupport audits, certifications, and customer security assessments Represent the company’s product security posture externally whenrequiredWhat this role does not doReview code or manage vulnerabilities day-to-dayDirectlymanagesecurity champions or software engineersYour profileRequired skills and experienceStrong understanding of product and cloud security in modern Dev Ops environmentsExperience working with security regulations and frameworks(ISO 27001, NIS2, SOC 2, NIST, Fed RAMP, or similar)Proven ability to make and defend risk-based decisionsCredibility with senior engineering and product stakeholdersClear written and verbal communication, especially around trade-offsExperience profile8+ years in software engineering, product security, or security leadership rolesExperience in product-centric, engineering-driven organizationsExposure to regulated environments is strongly preferredSuccess looks likeSecurity expectations are clear and predictable for product and engineeringRisk acceptance is explicit, documented, and rarely escalated lateEngineering teams ship securely by default using platform guardrailsAudits and customer security reviews are uneventful and well-preparedWhat we offerHealthy life-work balanceWhen creating a better and healthier world, a good place to start is with yourself. That's why we encourage our employees to prioritize their overall well-being, fostering physical fitness, mental resilience, and social connections through a range of workshops, sports activities, and other events and initiatives that contribute to a balanced and fulfilling work-life harmony.Hybrid working & flexibilityPersonal growth and career advancementTeam buildingInnovation is keyLocation and type of contractFull-timeHybridMid-senior level
📌 Product Security Lead (Barcelona)
🏢 materialise
📍 Barcelona