Principal Product Security Architect & Engagement Lead

Tewksbury, MA
Full Time
Experienced
 

Principal Product Security Architect & Engagement Lead

 

Role Summary

  • Lead and govern the end-to-end product lifecycle cybersecurity assessment engagement for the customer product including:
  • CRA-aligned security evaluation, architecture assessment, threat modelling, technical oversight, evidence traceability, and executive reporting. 
  • Accountable for leading all the discussions during the assessment including product applicability, intended use analysis, classification, Risk-based decisions, test-plan quality, change control, customer workshops, executive reporting, and escalation of material risks. 
  • Serve as the primary customer interface and ensure all assessment activities are executed in compliance with export-control requirements.

 

Key Responsibilities

  • Lead overall engagement delivery, governance, and customer coordination, including multidisciplinary team leadership, workstream ownership, estimation, change control, customer workshops, executive reporting, and difficult-risk communication
  • Conduct product security architecture assessments and threat modelling activities, including attack-tree, abuse-case, misuse-case, secure-update, rollback, recovery and safe-state architecture analysis
  • Perform trust boundary analysis and review data flows across product components and external integrations
  • Oversee CRA-aligned assessment methodology, compliance traceability, and lifecycle security evaluation, including CRA product scope, applicability and classification analysis, essential-requirement interpretation, conformity-assessment strategy, technical-documentation readiness, and compliance-evidence readiness
  • Evaluate operational resilience, recovery considerations, and lifecycle security controls across deployed product environments
  • Review secure-by-design implementation and product security governance practices
  • Guide technical testing activities and validate risk prioritization and exploitability context
  • Review security findings and ensure consistency across technical and compliance outputs
  • Lead executive reporting, release readiness assessment, and remediation discussions
  • Ensure evidence collection and assessment outputs align to CRA requirements, with control traceability, findings calibration, residual-risk governance, release-readiness conclusions, and defensible evidence mapping
  • Review lifecycle security considerations including secure decommissioning and data disposal practices
  • Assess security support-period commitments, update strategy, coordinated vulnerability disclosure, post-market vulnerability handling, incident-reporting readiness, and product logging, monitoring and auditability architecture
  • Evaluate connected-system and ecosystem-impact considerations, data minimization, sensitive-data handling, security-control design, and control effectiveness across product environments
  • Enforce export-control compliant handling of personnel, systems, and data
  • Provide final quality assurance and assessment signoff oversight

 

Required Skills & Experience

Mandatory:

  • Strong experience in product cybersecurity and secure-by-design principles, including product security architecture, secure-by-design governance, security-control design and effectiveness evaluation
  • Expertise in threat modelling, architecture review, and trust boundary analysis, including attack-tree, abuse-case, misuse-case, data-flow, data-minimization and sensitive-data analysis
  • Strong understanding of product lifecycle security and operational resilience concepts
  • Familiarity with secure SDLC, SBOM governance, and vulnerability management practices
  • Strong executive communication and stakeholder management capability
  • Control traceability, evidence management, release readiness, residual-risk assessment, findings calibration, negotiation, executive escalation, and material-risk communication
  • CRA product scope, applicability and classification analysis; CRA essential-requirement interpretation; conformity-assessment strategy and readiness; technical-documentation and compliance-evidence readiness
  • PSIRT and vulnerability handling processes, coordinated vulnerability disclosure, security support-period and update-strategy assessment, post-market vulnerability and incident-reporting readiness
  • NIST SSDF OR IEC 62443-4-1/4-2 frameworks; compliance and regulatory security assessments; product cybersecurity risk assessment; connected-device, embedded, IoT or regulated-product environments
  • Experience across both offensive security and security architecture domains
  • US Citizen or Green Card holder (US Person)

 

Good to have:

  • Experience leading CRA, regulated product security, or compliance-driven cybersecurity assessments
  • Experience leading engagement in export-controlled environments
  • FedRAMP or regulated environment experience preferred



 

 

Preferred Certifications

IEC 62443 (OT Security) or Certified DevSecOps Professional or any other relevant product-security credentials

 

Years of Required Experience

  • 12+ years in Product Security Architecture
  • 5+ years in complex customer assessment and regulatory assessment engagements
  • Five years leading complex customer security and regulatory assessment engagements
  • Demonstrated leadership of multidisciplinary product-security teams; experience defining assessment scope, effort estimates, workstream ownership and experience approving security reports

 

 


 
Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

Human Check*