Product Security Lead
On-siteTerrassa, Catalonia, Spain
Job Summary
Lead global product security incident management and vulnerability lifecycle operations across all product lines. Serve as the single point of contact for security incidents, coordinating cross-functional response efforts with Product, Engineering, Legal, and Communications teams. Establish continuous vulnerability monitoring processes, assess and prioritize risks, and oversee secure patch distribution. Maintain and govern Software Bills of Materials (SBOM) while managing external vulnerability disclosure channels in alignment with industry standards. Execute regulatory reporting obligations under the EU Cyber Resilience Act, acting as the primary liaison with external authorities. Translate security strategy into scalable operating models and embed secure-by-design principles into the development lifecycle. Develop metrics to track effectiveness and drive continuous improvement in disclosure and reporting processes.
Required Qualifications
- Bachelor's degree in Cybersecurity, Computer Science, Engineering, or related field (or equivalent experience)
- Minimum 5+ years of experience in application security, product security, or quality assurance
- Experience managing vulnerability lifecycles, including triage, remediation, and disclosure
- Strong understanding of secure software development and software supply chain risks (including SBOM)
- Ability to coordinate cross-functional teams and communicate risk to technical and non-technical stakeholders
Desired Qualifications
- Master's degree in Cybersecurity, Computer Science, Engineering, or related field (or equivalent experience)
- Experience with EU CRA or similar regulatory requirements
- Experience in vulnerability and incident response, or equivalent function
- Understanding of secure-by-design concepts and best practices
- Familiarity with vulnerability disclosure frameworks and practices
- Experience supporting regulatory reporting and audits
- Relevant security professional certifications (CISSP, CISSP, CSSLP, CISM, or equivalent)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.