Product Security Lead

Donaldson

Terrassa

Presencial

EUR 90.000 - 130.000

Jornada completa

Hace 9 días

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Donaldson is seeking a Product Security Lead to establish and operate the company’s global product security incident management and vulnerability lifecycle across all product lines.

You will serve as the single point of contact for product security incidents and vulnerability management, ensuring timely identification, remediation, disclosure, and reporting in alignment with regulatory requirements, including the EU CRA.

Formación

  • Bachelor’s degree in Cybersecurity, Computer Science, Engineering, or related field (or equivalent experience).
  • Minimum 5+ years of experience in application security, product security, or quality assurance.
  • Experience managing vulnerability lifecycles, including triage, remediation, and disclosure.
  • Strong understanding of secure software development and software supply chain risks (including SBOM).
  • Ability to coordinate cross-functional teams and communicate risk to technical and non-technical stakeholders.

Responsabilidades

  • Lead Product Security Incident Management (PSIM) & leadership for all product-related vulnerabilities and incidents.
  • Oversee end-to-end lifecycle of vulnerabilities: identification, triage, remediation, communication.
  • Coordinate cross-functional response efforts across Product, Corporate Engineering, Legal, and Communications teams.
  • Establish and operate continuous vulnerability monitoring processes for digital products and SBOM management.
  • Ensure SBOM accuracy and collaborate with Application Security to support product teams.

Conocimientos

Application security
Vulnerability management
Cross-functional collaboration
Regulatory understanding

Educación

Bachelor’s degree in Cybersecurity, Computer Science, Engineering, or related field
Master’s degree in Cybersecurity, Computer Science, Engineering, or related field

Descripción del empleo

Donaldson is committed to solving the world’s most complex filtration challenges. Together, we make cool things. As an established technology and innovation leader, we are continuously evolving to meet the filtration needs of our changing world. Join a culture of collaboration and innovation that matters and a chance to learn, effect change, and make meaningful contributions at work and in communities.

We are looking for a Product Security Lead who will be responsible for establishing and operating Donaldson’s global product security incident management and vulnerability lifecycle capabilities across all product lines.

This role serves as the single point of contact for product security incidents and vulnerability management, ensuring timely identification, remediation, disclosure, and reporting in alignment with regulatory requirements, including the EU Cyber Resilience Act (CRA).

The position partners closely with Business Operations, Product Engineering, IT, Legal, Privacy, and regional stakeholders to enable secure product development, transparency of software components, and effective responses to vulnerabilities.

The Product Security Lead serves as a trusted advisor to leadership on product security posture, vulnerability risk, and regulatory readiness.

Key Responsibilities
  • Product Security Incident Management (PSIM) & Leadership
  • Serve as the designated PSIM for all product-related vulnerabilities and security incidents
  • Lead the end-to-end lifecycle of product security vulnerabilities, including identification, triage, remediation, and communication
  • Coordinate cross-functional response efforts across Product, Corporate Engineering, Legal, and Communications teams
  • Vulnerability Management & Remediation
  • Establish and operate continuous vulnerability monitoring processes for digital products and associated electronic components
  • Ensure vulnerabilities are assessed, prioritized, and remediated without delay in alignment with regulatory expectations
  • Oversee the development and secure distribution of patches and security updates to customers
  • Software Quality Assurance & SBOM Management
  • Maintain and govern a machine-readable Software Bill of Materials (SBOM) for products
  • Collaborate with the Application Security specialist in providing services for product teams
  • Ensure SBOM accuracy and completeness to support vulnerability tracking and regulatory transparency
  • Coordinated Vulnerability Disclosure (CVD)
  • Establish and manage external vulnerability disclosure channels
  • Ensure timely publication of vulnerability disclosures following remediation
  • Align disclosure practices with industry standards and regulatory requirements. Regulatory Reporting & Compliance
  • Initially focused on compliance with the EU CRA, executing regulatory reporting obligations, including mandated timelines for vulnerability and incident reporting
  • Serve as the primary liaison with external authorities (e.g., EU ENISA and other regulators)
  • Maintain required technical documentation and compliance artifacts to support regulatory review
  • Monitoring Lifecycle Security & Support Obligations
  • Ensure products are supported with security updates throughout their defined lifecycle
  • Partner with Product and Corporate Engineering teams to integrate security maintenance into product roadmaps
  • Enterprise Product Security Architecture Alignment
  • Translate product security strategy and regulatory requirements into scalable processes, standards, and operating models
  • Partner with Product, Engineering, and Architecture teams to embed secure-by-design principles across the development lifecycle
  • Contribute to the definition and adoption of enterprise capabilities, including SBOM standards, vulnerability management processes, and PSIRT operating procedures
  • Ensure alignment of product security practices with internal policies, ISMS requirements, and global regulatory frameworks
  • Identify gaps in product security capabilities and drive implementation of improvements to enhance consistency and scalability
  • Documentation, Metrics & Continuous Improvement
  • Develop and maintain metrics and reporting to track vulnerability management effectiveness and regulatory readiness
  • Improve processes for vulnerability management, disclosure, and reporting
  • Ensure documentation is maintained in support of auditability and compliance
Minimum Qualifications
  • Bachelor’s degree in Cybersecurity, Computer Science, Engineering, or related field (or equivalent experience)
  • Minimum 5+ years of experience in application security, product security, or quality assurance
  • Experience managing vulnerability lifecycles, including triage, remediation, and disclosure
  • Strong understanding of secure software development and software supply chain risks (including SBOM)
  • Ability to coordinate cross-functional teams and communicate risk to technical and non-technical stakeholders
Preferred Qualifications
  • Master’s degree in Cybersecurity, Computer Science, Engineering, or related field (or equivalent experience)
  • Experience with EU CRA or similar regulatory requirements
  • Experience in vulnerability and incident response, or equivalent function
  • Understanding of secure-by-design concepts and best practices
  • Familiarity with vulnerability disclosure frameworks and practices
  • Experience supporting regulatory reporting and audits
  • Relevant security professional certifications (CISSP, CISSP, CSSLP, CISM, or equivalent)

Employment opportunities for positions in the United States may require use of information which is subject to the export control regulations of the United States. Hiring decisions for such positions are required by law to be made in compliance with these regulations. Applicants for employment opportunities in other countries must be able to meet the comparable export control requirements of that country and of the United States.

Our policy is to provide equal employment opportunities to all qualified persons without regard to race, gender, color, disability, national origin, age, religion, union affiliation, sexual orientation, veteran status, citizenship, gender identity and/or expression, or other status protected by law.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Global Product Security Lead: Incident & Compliance
Global Product Security Lead: Incident & Compliance

Donaldson • Terrassa

Presencial
EUR 90.000 - 130.000
Product Security Lead
Product Security Lead

Materialise NV • Barcelona

Híbrido
EUR 80.000 - 100.000
Healthy work-life balance
Personal growth and career advancement
Team building activities
+1
Cyber Security Compliance Lead
Cyber Security Compliance Lead

Resideo Technologies Inc. • España

Presencial
EUR 52.000 - 76.000
Health insurance
Private illness insurance
Sports and recreation
+3
Supervisor de Produccion
Supervisor de Produccion

Donaldson • León

Presencial
EUR 32.000 - 46.000
Product Security Incident Response Engineer
Product Security Incident Response Engineer

Analog Devices • Valencia

Presencial
EUR 90.000 - 120.000
Cyber Security Compliance Lead
Cyber Security Compliance Lead

ADI Global Distribution • Coslada

Híbrido
EUR 60.000 - 90.000
Health insurance
English classes during working hours
Employee referral bonus program
+1
Cyber Security Compliance Lead
Cyber Security Compliance Lead

ADI Global Distribution • Madrid

Híbrido
EUR 60.000 - 90.000
General health insurance
Serious illness insurance
Sports / recreation benefits
+3
Senior Product Security Engineer
Senior Product Security Engineer

Collibra • España

Presencial
EUR 70.000 - 110.000
IT Cybersecurity Engineer
IT Cybersecurity Engineer

Werfen • Barcelona

Presencial
EUR 70.000 - 100.000
Senior Security Analyst
Senior Security Analyst

Camlin Group • Málaga

Presencial
EUR 60.000 - 90.000