Interim Product Security Manager

Interim Product Security Manager voor internationale technologieorganisatie in Utrecht, gericht op CRA, embedded systems en industriële cybersecurity.

Locatie
Utrecht

Geen duidelijke warme-stoelaanwijzingen in de beschikbare beoordeling.

Bekijk en reageer bij TrueTalent V.O.F. (externe link)

Eisen

  • Bachelor’s degree in Cybersecurity, IT, Engineering or a related field, or equivalent practical experience
  • Effective communication with engineering, IT and business stakeholders and ability to balance security, compliance and time-to-market
  • Understanding of industrial automation and the cybersecurity challenges of connected machines and OT environments
  • Experience with SBOMs, vulnerability management, CVD/PSIRT processes and product security risk assessments
  • Solid knowledge of the EU Cyber Resilience Act (CRA) and can translate regulatory requirements into practical actions for engineering teams
  • At least 5 years of relevant cybersecurity experience, preferably in product security, embedded systems or industrial environments

Wensen

  • Experience with IEC 62443, NIST CSF or relevant security certifications
Volledige omschrijving

Are you an experienced Product Security Manager with a strong background in the Cyber Resilience Act (CRA), embedded systems and industrial cybersecurity? This international technology organization is looking for a product security specialist who can combine cybersecurity, engineering and regulatory compliance and translate them into a practical security approach throughout the entire product lifecycle. You will have the opportunity to shape product security from the ground up and make a lasting impact on connected machines and digital products.

Read on to learn more. As a Product Security Manager, you are responsible for cybersecurity throughout the full lifecycle of connected machines, embedded systems and digital products. You develop the product security framework and translate requirements from the EU Cyber Resilience Act (CRA) into practical policies, standards and secure-by-design principles. Working closely with R&D, engineering, IT and QA, you make sure security is embedded in product development from the start.

You define requirements for secure software development, security testing, SBOMs, technical documentation and secure IT/OT architecture. You also take the lead in product risk and vulnerability management, including vulnerability assessments, the Coordinated Vulnerability Disclosure (CVD) process and PSIRT. When vulnerabilities or incidents occur, you coordinate the response and ensure security updates, reporting and regulatory requirements are handled correctly.

In addition, you oversee product cybersecurity compliance with regulations and standards such as the CRA, Machinery Regulation, NIS2 and IEC 62443. You work with suppliers, commercial teams and customers to clarify cybersecurity requirements and responsibilities. This puts you in a key position between engineering, cybersecurity, compliance and the business, with a direct impact on the security and regulatory readiness of the organization's products.

What you will bring: You have a Bachelor’s degree in Cybersecurity, IT, Engineering or a related field, or equivalent practical experience. You have at least 5 years of relevant cybersecurity experience, preferably in product security, embedded systems or industrial environments. You have solid knowledge of the EU Cyber Resilience Act (CRA) and can translate regulatory requirements into practical actions for engineering teams. You have experience with SBOMs, vulnerability management, CVD/PSIRT processes and product security risk assessments.

You understand industrial automation and the cybersecurity challenges of connected machines and OT environments. You communicate effectively with engineering, IT and business stakeholders and know how to balance security, compliance and time-to-market. Experience with IEC 62443, NIST CSF or relevant security certifications is a plus.

What our client offers: The position is open to professionals looking for either an interim assignment or a permanent role. A key role in shaping and further developing product security within an international technology environment. The opportunity to build your expertise in product cybersecurity, the Cyber Resilience Act (CRA) and secure-by-design. Close collaboration with experienced professionals across R&D, engineering, IT, QA and commercial teams.

A role with significant ownership and the opportunity to influence how cybersecurity is embedded throughout the product lifecycle.

About our client: Our client is an international technology organization that develops advanced machines, automation solutions and digital products for industrial environments. With its headquarters in the Netherlands and locations worldwide, the organization combines engineering, technology and customer service to support customers across international markets. Innovation and continuous product development play an important role within the organization.

As machines and digital solutions become increasingly connected, cybersecurity is becoming a key part of product development and the entire product lifecycle. This creates an important role for the Product Security Manager in further developing and embedding product security across the organization. Interested? Are you interested in this position? Apply directly using the form below. If you would like more information about the position, the organization or if you have other questions, please contact [naam] el Berrah using the contact details below.

Je CV en reacties