Principal Product Security Architect & Engagement Lead
Tewksbury, MA
Full Time
Experienced
Principal Product Security Architect & Engagement Lead
Role Summary
- Lead and govern the end-to-end product lifecycle cybersecurity assessment engagement for the customer product including:
- CRA-aligned security evaluation, architecture assessment, threat modelling, technical oversight, evidence traceability, and executive reporting.
- Accountable for leading all the discussions during the assessment including product applicability, intended use analysis, classification, Risk-based decisions, test-plan quality, change control, customer workshops, executive reporting, and escalation of material risks.
- Serve as the primary customer interface and ensure all assessment activities are executed in compliance with export-control requirements.
Key Responsibilities
- Lead overall engagement delivery, governance, and customer coordination, including multidisciplinary team leadership, workstream ownership, estimation, change control, customer workshops, executive reporting, and difficult-risk communication
- Conduct product security architecture assessments and threat modelling activities, including attack-tree, abuse-case, misuse-case, secure-update, rollback, recovery and safe-state architecture analysis
- Perform trust boundary analysis and review data flows across product components and external integrations
- Oversee CRA-aligned assessment methodology, compliance traceability, and lifecycle security evaluation, including CRA product scope, applicability and classification analysis, essential-requirement interpretation, conformity-assessment strategy, technical-documentation readiness, and compliance-evidence readiness
- Evaluate operational resilience, recovery considerations, and lifecycle security controls across deployed product environments
- Review secure-by-design implementation and product security governance practices
- Guide technical testing activities and validate risk prioritization and exploitability context
- Review security findings and ensure consistency across technical and compliance outputs
- Lead executive reporting, release readiness assessment, and remediation discussions
- Ensure evidence collection and assessment outputs align to CRA requirements, with control traceability, findings calibration, residual-risk governance, release-readiness conclusions, and defensible evidence mapping
- Review lifecycle security considerations including secure decommissioning and data disposal practices
- Assess security support-period commitments, update strategy, coordinated vulnerability disclosure, post-market vulnerability handling, incident-reporting readiness, and product logging, monitoring and auditability architecture
- Evaluate connected-system and ecosystem-impact considerations, data minimization, sensitive-data handling, security-control design, and control effectiveness across product environments
- Enforce export-control compliant handling of personnel, systems, and data
- Provide final quality assurance and assessment signoff oversight
Required Skills & Experience
Mandatory:
- Strong experience in product cybersecurity and secure-by-design principles, including product security architecture, secure-by-design governance, security-control design and effectiveness evaluation
- Expertise in threat modelling, architecture review, and trust boundary analysis, including attack-tree, abuse-case, misuse-case, data-flow, data-minimization and sensitive-data analysis
- Strong understanding of product lifecycle security and operational resilience concepts
- Familiarity with secure SDLC, SBOM governance, and vulnerability management practices
- Strong executive communication and stakeholder management capability
- Control traceability, evidence management, release readiness, residual-risk assessment, findings calibration, negotiation, executive escalation, and material-risk communication
- CRA product scope, applicability and classification analysis; CRA essential-requirement interpretation; conformity-assessment strategy and readiness; technical-documentation and compliance-evidence readiness
- PSIRT and vulnerability handling processes, coordinated vulnerability disclosure, security support-period and update-strategy assessment, post-market vulnerability and incident-reporting readiness
- NIST SSDF OR IEC 62443-4-1/4-2 frameworks; compliance and regulatory security assessments; product cybersecurity risk assessment; connected-device, embedded, IoT or regulated-product environments
- Experience across both offensive security and security architecture domains
- US Citizen or Green Card holder (US Person)
Good to have:
- Experience leading CRA, regulated product security, or compliance-driven cybersecurity assessments
- Experience leading engagement in export-controlled environments
- FedRAMP or regulated environment experience preferred
Preferred Certifications
IEC 62443 (OT Security) or Certified DevSecOps Professional or any other relevant product-security credentials
Years of Required Experience
- 12+ years in Product Security Architecture
- 5+ years in complex customer assessment and regulatory assessment engagements
- Five years leading complex customer security and regulatory assessment engagements
- Demonstrated leadership of multidisciplinary product-security teams; experience defining assessment scope, effort estimates, workstream ownership and experience approving security reports
Apply for this position
Required*