Product Security Architect

Materialise

Vlaams-Brabant

Sur place

EUR 90 000 - 130 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Résumé du poste

Materialise is seeking a Product Security Architect to lead secure architecture across our products, including cloud-based platforms. You will drive security throughout the lifecycle, align with regulatory requirements, and collaborate with engineering, product, and DevOps to mitigate risks and ensure auditability.

The role emphasizes IAM, encryption, secrets management, and a security-first culture. You will shape the security roadmap and partner with teams to maintain compliance and resilience.

Qualifications

  • 8+ years of experience in software engineering, system architecture, or application security.
  • Experience leading architecture reviews and driving security decisions across teams.
  • Experience designing and implementing security controls (IAM, encryption, secrets management, network segmentation) in production environments.

Responsabilités

  • Define and review secure system architectures for applications, services, and platforms.
  • Design and guide the implementation of IAM, encryption, secrets management, and network segmentation.
  • Support secure CI/CD and software supply chain practices.
  • Embed security practices into SDLC and guide teams on secure coding standards.
  • Collaborate with engineering and product teams to clarify security requirements.
  • Ensure adherence to standards like ISO 27001 and regulations such as GDPR.

Connaissances

Security architecture
Threat modeling
Cloud security
IAM and encryption
DevSecOps

Outils

SAST
DAST
SCA
Container security

Description du poste

At Materialise Medical, we believe that better healthcare starts with solutions designed around the individual patient. If you’re passionate about bringing personalized care to every patient, you’ll love being a part of this team. Through the technology we develop, researchers, engineers, and clinicians are revolutionizing personalized treatment—helping improve and save lives daily.

Job Description

We are looking for a Product Security Architect to lead the design and implementation of secure architectures across our products, including Materialise Mimics Flow—a cloud‑based platform operating in a regulated medical device environment. This role ensures that security is embedded throughout the entire product lifecycle, from initial concept and design through development, deployment, and maintenance. Our platform leverages a cloud‑native architecture on AWS, with an increasing adoption of containerized workloads orchestrated by Kubernetes and supported by DevOps practices. We are actively progressing the migration of legacy applications and further strengthening our operational and architectural foundations to improve scalability, reliability, and maintainability over time. The platform processes sensitive medical data and operates under strict regulatory requirements, requiring compliance with recognized cybersecurity standards and medical device regulations. You will work closely with engineering, product, and DevOps teams to proactively identify risks, define security requirements, and implement best practices that protect our systems, data, and users. You will also play a key role in supporting audits and regulatory processes, contributing to required documentation, and ensuring that security controls are clearly defined, effectively implemented, and fully traceable.

What You Will Do
Secure architecture design
  • Define and review secure system architectures for applications, services, and platforms
  • Design and guide the implementation of:
    • Identity and access management (SSO, OIDC, SAML, authorization models)
    • Tenant isolation and access control
    • Data protection and privacy‑by‑design (encryption, key management, PII handling)
    • Secrets management and network segmentation
    • Logging, monitoring, and auditability aligned with compliance requirements
    • Secure CI/CD and software supply chain practices
Threat modeling and risk assessment
  • Conduct threat modeling sessions and train the teams to identify potential vulnerabilities early
  • Perform risk assessments and recommend mitigation strategies
Security integration in development
  • Embed security practices into SDLC (Secure SDLC)
  • Guide teams on secure coding standards and design patterns
  • Support the adoption of SAST, DAST, SCA, and other security tools
Engineering collaboration
  • Partner with engineering and product teams to ensure security requirements are clear and actionable
  • Participate in design reviews and architecture discussions
Compliance and standards
  • Ensure adherence to applicable standards (e.g., ISO 27001) and regulations (e.g., GDPR, data protection laws)
  • Contribute to internal security policies and guidelines
  • Align product security initiatives with the broader organizational security roadmap
Vulnerability management and incident support
  • Support vulnerability remediation and coordinate with teams on fixes
  • Assist in security incident analysis and response
Security strategy and roadmap
  • Define and drive a product security roadmap aligned with business goals
  • Promote a security‑first culture across teams
Your profile
  • 8+ years of experience in software engineering, system architecture, or application security, including hands‑on work in cloud or distributed systems
  • Experience leading architecture reviews and driving security decisions across teams
  • Experience designing and implementing security controls (e.g., IAM, encryption, secrets management, network segmentation) in production environments
Technical skills
  • Strong understanding of security principles (authentication, authorization, cryptography, secure APIs)
  • Conducted threat modeling using STRIDE, mapped threats to CAPEC and CWE, and applied CVSS scoring to prioritize remediation efforts
  • Familiarity with security tools (SAST, DAST, SCA, container security, etc.)
  • Knowledge of cloud security (AWS, Azure, or GCP)
Standards and frameworks
  • Strong stakeholder management skills, with the ability to influence engineering, product, and leadership without direct authority
  • Analytical thinking and problem‑solving mindset
  • Comfortable communicating security risks, decisions, and strategy to senior leadership
Will be a plus
  • Security certifications (e.g., CISSP, CISM, CSSLP)
  • Experience with medical device cybersecurity standards (e.g., IEC81001-5-1, MDCG 2019‑16, section 524B(b)(2) of the FDA act)
  • Experience with DevSecOps practices and CI/CD integration
  • Background in regulated industries (e.g., healthcare, finance)
  • Experience with penetration testing
Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Product Security Architect
Product Security Architect

Mondeadditif • Heverlee

Sur place
EUR 90 000 - 150 000
Product Security Architect
Product Security Architect

Materialise • Heverlee

Sur place
EUR 90 000 - 130 000
Product Security Lead
Product Security Lead

Mondeadditif • Heverlee

Sur place
EUR 90 000 - 140 000
Medical Platform Security Architect — Cloud & Compliance
Medical Platform Security Architect — Cloud & Compliance

Mondeadditif • Heverlee

Sur place
EUR 90 000 - 150 000
Cloud Product Security Architect — Medical Platform
Cloud Product Security Architect — Medical Platform

Materialise • Heverlee

Sur place
EUR 90 000 - 130 000
Cloud-Native Product Security Architect (Medical Devices)
Cloud-Native Product Security Architect (Medical Devices)

Materialise • Vlaams-Brabant

Sur place
EUR 90 000 - 130 000
Product Security Lead
Product Security Lead

Materialise • Heverlee

Sur place
EUR 100 000 - 140 000
Product Security Lead: Regulatory Risk & Strategy
Product Security Lead: Regulatory Risk & Strategy

Mondeadditif • Heverlee

Sur place
EUR 90 000 - 140 000
Product Security Lead: Strategy, Compliance & Risk
Product Security Lead: Strategy, Compliance & Risk

Materialise • Heverlee

Sur place
EUR 100 000 - 140 000
Product Cyber Security Engineer
Product Cyber Security Engineer

Niko • Antwerpen

Sur place
EUR 60 000 - 80 000
Competitive salary with comprehensive benefits
Opportunities for professional growth
Innovative and professional environment