This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are looking for a motivated Product & Information Security Architect to strengthen the security of our products and internal information assets. This role focuses on hands-on product security, working closely with development and enterprise security teams in a global environment. You will design and implement robust security controls, promote secure development practices, and lead risk assessments, vulnerability management, compliance readiness, and type approval activities to protect our platforms and services.
Job Responsibility:
Own and improve product security across the lifecycle (design, implementation, testing, and deployment including security standards, directions)
Design security architecture to address increasing security threats and global regulations and compliance requirements
Assess and advise on network architecture risks, encryption choices, and secure protocol selection in collaboration with development teams
Perform and support security risk assessments, threat modelling, and security reviews for products
Support vulnerability management: identify, analyze, and track remediation of vulnerabilities, follow up on verification and closure
Understand security requirements from external partners and customers, translate them into concrete actions, and help prioritize them based on risk and business impact
Lead and coordinate Cyber Resilience Act (CRA) readiness and compliance activities for relevant products and services
Contribute to and improve information security policies, standards, and guidelines collaborating with Business Area’s stakeholders to drive information security adaptation
Lead type approval activities for relevant products
Requirements:
Bachelor's degree or higher in Computer Science, Information Technology, Information Security, or a related field, or equivalent practical experience in software/IT and security
10+ years of experience in a security-related or software/IT engineering role, with practical exposure to product and application security, such as: Handling security requirements from customers and partners
Supporting security design, review, or validation for software products or platforms
Contributing to Enterprise information security and cyber security
Good understanding of network, system, and application security fundamentals including: Vulnerability types and mitigation approaches
Network configuration and related security risks
Encryption, key management, and secure protocol usage
Good understanding of major security and privacy regulations (e.g., GDPR, CCPA, HIPAA or similar) and how they influence product and information security
Intermediate or higher level of English, both written and spoken
Nice to have:
Experience with secure software development lifecycle (SSDLC) or similar frameworks
Practical experience in one or more of the following: Vulnerability assessment / penetration testing
Cloud security (e.g., UCaaS, CCaaS)
Container / microservices security
Experience contributing to security certification or compliance projects, such as: ISO27001, ISMS, CRA or similar security frameworks
Internal or external security audit, or customer security assessments
One or more IT security certification (e.g., CISSP, CISM, CISA, CEH, Security+, GSEC, OSCP, or equivalent)
Basic understanding of hacking techniques, attack vectors, and common exploitation methods, and how to mitigate them