Interim Product Security Manager

Interim Product Security Manager in Barneveld for an international technology organization, focusing on CRA, embedded systems and industrial cybersecurity.

Locatie
Barneveld

Geen duidelijke warme-stoelaanwijzingen in de beschikbare beoordeling.

Bekijk en reageer bij TrueTalent V.O.F. (externe link)

Eisen

  • Understanding of industrial automation and the cybersecurity challenges of connected machines and OT environments
  • Effective communication with engineering, IT and business stakeholders and the ability to balance security, compliance and time-to-market
  • At least 5 years of relevant cybersecurity experience, preferably in product security, embedded systems or industrial environments
  • Solid knowledge of the EU Cyber Resilience Act (CRA) and the ability to translate regulatory requirements into practical actions for engineering teams
  • Bachelor’s degree in Cybersecurity, IT, Engineering or a related field, or equivalent practical experience
  • Experience with SBOMs, vulnerability management, CVD/PSIRT processes and product security risk assessments

Wensen

  • Experience with IEC 62443, NIST CSF or relevant security certifications
Volledige omschrijving

Are you an experienced Product Security Manager with a strong background in the Cyber Resilience Act (CRA), embedded systems and industrial cybersecurity? This international technology organization is looking for a product security specialist who can combine cybersecurity, engineering and regulatory compliance and translate them into a practical security approach throughout the entire product lifecycle. You will have the opportunity to shape product security from the ground up and make a lasting impact on connected machines and digital products.

As a Product Security Manager, you are responsible for cybersecurity throughout the full lifecycle of connected machines, embedded systems and digital products. You develop the product security framework and translate requirements from the EU Cyber Resilience Act (CRA) into practical policies, standards and secure-by-design principles. Working closely with R&D, engineering, IT and QA, you make sure security is embedded in product development from the start.

You define requirements for secure software development, security testing, SBOMs, technical documentation and secure IT/OT architecture. You also take the lead in product risk and vulnerability management, including vulnerability assessments, the Coordinated Vulnerability Disclosure (CVD) process and PSIRT. When vulnerabilities or incidents occur, you coordinate the response and ensure security updates, reporting and regulatory requirements are handled correctly.

In addition, you oversee product cybersecurity compliance with regulations and standards such as the CRA, Machinery Regulation, NIS2 and IEC 62443. You work with suppliers, commercial teams and customers to clarify cybersecurity requirements and responsibilities. This puts you in a key position between engineering, cybersecurity, compliance and the business, with a direct impact on the security and regulatory readiness of the organization's products.

The ideal candidate has a Bachelor’s degree in Cybersecurity, IT, Engineering or a related field, or equivalent practical experience; at least 5 years of relevant cybersecurity experience, preferably in product security, embedded systems or industrial environments; solid knowledge of the EU Cyber Resilience Act (CRA) and the ability to translate regulatory requirements into practical actions for engineering teams; experience with SBOMs, vulnerability management, CVD/PSIRT processes and product security risk assessments; understanding of industrial automation and the cybersecurity challenges of connected machines and OT environments; and effective communication with engineering, IT and business stakeholders, balancing security, compliance and time-to-market.

Experience with IEC 62443, NIST CSF or relevant security certifications is a plus. The position is open to professionals looking for either an interim assignment or a permanent role. It offers a key role in shaping and further developing product security within an international technology environment, the opportunity to build expertise in product cybersecurity, the Cyber Resilience Act (CRA) and secure-by-design, close collaboration with experienced professionals across R&D, engineering, IT, QA and commercial teams, and a role with significant ownership and the opportunity to influence how cybersecurity is embedded throughout the product lifecycle.

Our client is an international technology organization that develops advanced machines, automation solutions and digital products for industrial environments. With its headquarters in the Netherlands and locations worldwide, the organization combines engineering, technology and customer service to support customers across international markets. Innovation and continuous product development play an important role within the organization. As machines and digital solutions become increasingly connected, cybersecurity is becoming a key part of product development and the entire product lifecycle.

This creates an important role for the Product Security Manager in further developing and embedding product security across the organization.

Je CV en reacties