Principal Product Security Architect & Engagement Lead

Zappsec Inc.
  • Tewksbury, MA
  • Autofill and Review
23 days ago

Job Description

Principal Product Security Architect & Engagement Lead

Role Summary

  • Lead and govern the end-to-end product lifecycle cybersecurity assessment engagement for the customer product including:
  • CRA-aligned security evaluation, architecture assessment, threat modelling, technical oversight, evidence traceability, and executive reporting. 
  • Accountable for leading all the discussions during the assessment including product applicability, intended use analysis, classification, Risk-based decisions, test-plan quality, change control, customer workshops, executive reporting, and escalation of material risks. 
  • Serve as the primary customer interface and ensure all assessment activities are executed in compliance with export-control requirements.

Key Responsibilities

  • Lead overall engagement delivery, governance, and customer coordination, including multidisciplinary team leadership, workstream ownership, estimation, change control, customer workshops, executive reporting, and difficult-risk communication
  • Conduct product security architecture assessments and threat modelling activities, including attack-tree, abuse-case, misuse-case, secure-update, rollback, recovery and safe-state architecture analysis
  • Perform trust boundary analysis and review data flows across product components and external integrations
  • Oversee CRA-aligned assessment methodology, compliance traceability, and lifecycle security evaluation, including CRA product scope, applicability and classification analysis, essential-requirement interpretation, conformity-assessment strategy, technical-documentation readiness, and compliance-evidence readiness
  • Evaluate operational resilience, recovery considerations, and lifecycle security controls across deployed product environments
  • Review secure-by-design implementation and product security governance practices
  • Guide technical testing activities and validate risk prioritization and exploitability context
  • Review security findings and ensure consistency across technical and compliance outputs
  • Lead executive reporting, release readiness assessment, and remediation discussions
  • Ensure evidence collection and assessment outputs align to CRA requirements, with control traceability, findings calibration, residual-risk governance, release-readiness conclusions, and defensible evidence mapping
  • Review lifecycle security considerations including secure decommissioning and data disposal practices
  • Assess security support-period commitments, update strategy, coordinated vulnerability disclosure, post-market vulnerability handling, incident-reporting readiness, and product logging, monitoring and auditability architecture
  • Evaluate connected-system and ecosystem-impact considerations, data minimization, sensitive-data handling, security-control design, and control effectiveness across product environments
  • Enforce export-control compliant handling of personnel, systems, and data
  • Provide final quality assurance and assessment signoff oversight

Required Skills & Experience

Mandatory:

  • Strong experience in product cybersecurity and secure-by-design principles, including product security architecture, secure-by-design governance, security-control design and effectiveness evaluation
  • Expertise in threat modelling, architecture review, and trust boundary analysis, including attack-tree, abuse-case, misuse-case, data-flow, data-minimization and sensitive-data analysis
  • Strong understanding of product lifecycle security and operational resilience concepts
  • Familiarity with secure SDLC, SBOM governance, and vulnerability management practices
  • Strong executive communication and stakeholder management capability
  • Control traceability, evidence management, release readiness, residual-risk assessment, findings calibration, negotiation, executive escalation, and material-risk communication
  • CRA product scope, applicability and classification analysis; CRA essential-requirement interpretation; conformity-assessment strategy and readiness; technical-documentation and compliance-evidence readiness
  • PSIRT and vulnerability handling processes, coordinated vulnerability disclosure, security support-period and update-strategy assessment, post-market vulnerability and incident-reporting readiness
  • NIST SSDF OR IEC 62443-4-1/4-2 frameworks; compliance and regulatory security assessments; product cybersecurity risk assessment; connected-device, embedded, IoT or regulated-product environments
  • Experience across both offensive security and security architecture domains
  • US Citizen or Green Card holder (US Person)

Good to have:

  • Experience leading CRA, regulated product security, or compliance-driven cybersecurity assessments
  • Experience leading engagement in export-controlled environments
  • FedRAMP or regulated environment experience preferred

Preferred Certifications

IEC 62443 (OT Security) or Certified DevSecOps Professional or any other relevant product-security credentials

Years of Required Experience

  • 12+ years in Product Security Architecture
  • 5+ years in complex customer assessment and regulatory assessment engagements
  • Five years leading complex customer security and regulatory assessment engagements
  • Demonstrated leadership of multidisciplinary product-security teams; experience defining assessment scope, effort estimates, workstream ownership and experience approving security reports

Powered by JazzHR

Numbers & Facts

LocationTewksbury, MA

Skills

  • Analysis Skillsunmatched
  • Architectural Analysisunmatched
  • Calibrationunmatched
  • Change Controlunmatched
  • Communication Skillsunmatched
  • Computer Securityunmatched
  • Cross-Functionalunmatched
  • Customer Relationsunmatched
  • Data Analysisunmatched
  • Ecosystemsunmatched
  • Embedded Systemsunmatched
  • Establish Prioritiesunmatched
  • Import/Export Complianceunmatched
  • Incident Responseunmatched
  • Information/Data Security (InfoSec)unmatched
  • International Electro-Technical Commission (IEC)unmatched
  • Internet Securityunmatched
  • Internet of Thingsunmatched
  • Leadershipunmatched
  • Maintain Complianceunmatched
  • Model Reviewunmatched
  • Negotiation Skillsunmatched
  • Operational Auditunmatched
  • Product Designunmatched
  • Product Lifecycleunmatched
  • Quality Assuranceunmatched
  • Quality Controlunmatched
  • Regulationsunmatched
  • Regulatory Complianceunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Security Analysisunmatched
  • Security Architectureunmatched
  • Security Complianceunmatched
  • Security Designunmatched
  • Software Development Lifecycle (SDLC)unmatched
  • Strategic Analysisunmatched
  • Team Lead/Managerunmatched
  • Technical Strategyunmatched
  • Technical Writingunmatched
  • Testingunmatched
  • Threat Modelingunmatched
  • Traceabilityunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • United States Citizenunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder