Donaldson logo
DonaldsonPosted 2 weeks ago

Product Security Lead

On-siteTerrassa, Catalonia, Spain

Full TimeSenior LevelEnterprise

Job Summary

Lead global product security incident management and vulnerability lifecycle operations across all product lines. Serve as the single point of contact for security incidents, coordinating cross-functional response efforts with Product, Engineering, Legal, and Communications teams. Establish continuous vulnerability monitoring processes, assess and prioritize risks, and oversee secure patch distribution. Maintain and govern Software Bills of Materials (SBOM) while managing external vulnerability disclosure channels in alignment with industry standards. Execute regulatory reporting obligations under the EU Cyber Resilience Act, acting as the primary liaison with external authorities. Translate security strategy into scalable operating models and embed secure-by-design principles into the development lifecycle. Develop metrics to track effectiveness and drive continuous improvement in disclosure and reporting processes.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Engineering, or related field (or equivalent experience)
  • Minimum 5+ years of experience in application security, product security, or quality assurance
  • Experience managing vulnerability lifecycles, including triage, remediation, and disclosure
  • Strong understanding of secure software development and software supply chain risks (including SBOM)
  • Ability to coordinate cross-functional teams and communicate risk to technical and non-technical stakeholders

Desired Qualifications

  • Master's degree in Cybersecurity, Computer Science, Engineering, or related field (or equivalent experience)
  • Experience with EU CRA or similar regulatory requirements
  • Experience in vulnerability and incident response, or equivalent function
  • Understanding of secure-by-design concepts and best practices
  • Familiarity with vulnerability disclosure frameworks and practices
  • Experience supporting regulatory reporting and audits
  • Relevant security professional certifications (CISSP, CISSP, CSSLP, CISM, or equivalent)

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce