Product Security Lead

Donaldson

Terrassa

Presencial

EUR 70.000 - 100.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Donaldson is seeking a Product Security Lead to establish and operate global product security incident management and vulnerability lifecycle capabilities across all product lines. You will coordinate cross-functional responses, drive SBOM governance, and ensure regulatory readiness for EU CRA and beyond.

The role requires leadership of PSIM, vulnerability management, and coordinated vulnerability disclosure, with collaboration across Legal, IT, and Engineering teams to secure products

Formación

  • Bachelor’s degree in Cybersecurity, Computer Science, Engineering, or related field (or equivalent experience).
  • 5+ years of experience in application security, product security, or quality assurance.
  • Experience managing vulnerability lifecycles, including triage, remediation, and disclosure.

Responsabilidades

  • Lead the end-to-end lifecycle of product security vulnerabilities, including identification, triage, remediation, and communication.
  • Establish and operate continuous vulnerability monitoring processes for digital products and components.
  • Maintain and govern a machine-readable SBOM for products and ensure SBOM accuracy.
  • Establish and manage external vulnerability disclosure channels and align disclosures with standards.
  • Oversee regulatory reporting and compliance, starting with EU CRA obligations and liaising with authorities.
  • Drive security maintenance integration into product roadmaps and lifecycle management.

Conocimientos

Application security
Vulnerability management
SBOM
Regulatory compliance
Cross-functional collaboration
Incident response

Educación

Bachelor's degree in CS/Cybersecurity/Engineering
Master's degree (preferred)

Herramientas

SBOM tooling

Descripción del empleo

Donaldson is committed to solving the world’s most complex filtration challenges. Together, we make cool things. As an established technology and innovation leader, we are continuously evolving to meet the filtration needs of our changing world. Join a culture of collaboration and innovation that matters and a chance to learn, effect change, and make meaningful contributions at work and in communities.We are looking for a Product Security Lead who will be responsible for establishing and operating Donaldson’s global product security incident management and vulnerability lifecycle capabilities across all product lines.This role serves as the single point of contact for product security incidents and vulnerability management, ensuring timely identification, remediation, disclosure, and reporting in alignment with regulatory requirements, including the EU Cyber Resilience Act (CRA).The position partners closely with Business Operations, Product Engineering, IT, Legal, Privacy, and regional stakeholders to enable secure product development, transparency of software components, and effective responses to vulnerabilities.The Product Security Lead serves as a trusted advisor to leadership on product security posture, vulnerability risk, and regulatory readiness.Key Responsibilities1. Product Security Incident Management (PSIM) & LeadershipServe as the designated PSIM for all product-related vulnerabilities and security incidentsLead the end-to-end lifecycle of product security vulnerabilities, including identification, triage, remediation, and communicationCoordinate cross-functional response efforts across Product, Corporate Engineering, Legal, and Communications teams2. Vulnerability Management & RemediationEstablish and operate continuous vulnerability monitoring processes for digital products and associated electronic componentsEnsure vulnerabilities are assessed, prioritized, and remediated without delay in alignment with regulatory expectationsOversee the development and secure distribution of patches and security updates to customers3. Software Quality Assurance & SBOM ManagementMaintain and govern a machine-readable Software Bill of Materials (SBOM) for productsCollaborate with the Application Security specialist in providing services for product teamsEnsure SBOM accuracy and completeness to support vulnerability tracking and regulatory transparency4. Coordinated Vulnerability Disclosure (CVD)Establish and manage external vulnerability disclosure channelsEnsure timely publication of vulnerability disclosures following remediationAlign disclosure practices with industry standards and regulatory requirements. Regulatory Reporting & ComplianceInitially focused on compliance with the EU CRA, executing regulatory reporting obligations, including mandated timelines for vulnerability and incident reportingServe as the primary liaison with external authorities (e.g., EU ENISA and other regulators)Maintain required technical documentation and compliance artifacts to support regulatory review5. Monitoring Lifecycle Security & Support ObligationsEnsure products are supported with security updates throughout their defined lifecyclePartner with Product and Corporate Engineering teams to integrate security maintenance into product roadmaps5. Enterprise Product Security Architecture AlignmentTranslate product security strategy and regulatory requirements into scalable processes, standards, and operating modelsPartner with Product, Engineering, and Architecture teams to embed secure-by-design principles across the development lifecycleContribute to the definition and adoption of enterprise capabilities, including SBOM standards, vulnerability management processes, and PSIRT operating proceduresEnsure alignment of product security practices with internal policies, ISMS requirements, and global regulatory frameworksIdentify gaps in product security capabilities and drive implementation of improvements to enhance consistency and scalability6. Documentation, Metrics & Continuous ImprovementDevelop and maintain metrics and reporting to track vulnerability management effectiveness and regulatory readinessImprove processes for vulnerability management, disclosure, and reportingEnsure documentation is maintained in support of auditability and complianceMinimum QualificationsBachelor’s degree in Cybersecurity, Computer Science, Engineering, or related field (or equivalent experience)Minimum 5+ years of experience in application security, product security, or quality assuranceExperience managing vulnerability lifecycles, including triage, remediation, and disclosureStrong understanding of secure software development and software supply chain risks (including SBOM)Ability to coordinate cross-functional teams and communicate risk to technical and non-technical stakeholdersPreferred QualificationsMaster’s degree in Cybersecurity, Computer Science, Engineering, or related field (or equivalent experience)Experience with EU CRA or similar regulatory requirementsExperience in vulnerability and incident response, or equivalent functionUnderstanding of secure-by-design concepts and best practicesFamiliarity with vulnerability disclosure frameworks and practicesExperience supporting regulatory reporting and auditsRelevant security professional certifications (CISSP, CISSP, CSSLP, CISM, or equivalent)Employment opportunities for positions in the United States may require use of information which is subject to the export control regulations of the United States. Hiring decisions for such positions are required by law to be made in compliance with these regulations. Applicants for employment opportunities in other countries must be able to meet the comparable export control requirements of that country and of the United States.Donaldson Company has been made aware that there are several recruiting scams that are targeting job seekers. These scams have attempted to solicit money for job applications and/or collect confidential information, Donaldson will never solicit money during the application or recruiting process. Donaldson only accepts online applications through our Careers | Donaldson Company, Inc. website and any communication from a Donaldson recruiter would be sent using a donaldson.com email address. If you have any questions about the legitimacy of an employment opportunity, please reach out to talentacquisition@donaldson.com to verify that the communication is from Donaldson.Our policy is to provide equal employment opportunities to all qualified persons without regard to race, gender, color, disability, national origin, age, religion, union affiliation, sexual orientation, veteran status, citizenship, gender identity and/or expression, or other status protected by law.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Product Security Lead
Product Security Lead

Barcelona, Spain Donaldson Ibèrica Soluciones • Barcelona

Presencial
EUR 110.000 - 160.000
Global Product Security Lead—Incidents & Vulnerabilities
Global Product Security Lead—Incidents & Vulnerabilities

Donaldson • Terrassa

Presencial
EUR 70.000 - 100.000
Inside Sales Representative (German)
Inside Sales Representative (German)

Donaldson • Terrassa

Híbrido
EUR 32.000 - 48.000
Meal allowance
Telework support
Health insurance
+3
Customer Service Representative (German)
Customer Service Representative (German)

Donaldson • Terrassa

Híbrido
EUR 28.000 - 32.000
Flexible schedule
Hybrid work model
Shuttle bus from city center to office
Export Customer Service (6-Month Contract)
Export Customer Service (6-Month Contract)

Donaldson Company • Barcelona

Híbrido
EUR 28.000 - 36.000
Flexible work schedule
Meal allowance
Telework expenses
+2
Global Product Security Lead — Incidents & Vulnerabilities
Global Product Security Lead — Incidents & Vulnerabilities

Barcelona, Spain Donaldson Ibèrica Soluciones • Barcelona

Presencial
EUR 110.000 - 160.000
Product Security Incident Response Engineer
Product Security Incident Response Engineer

Analog Devices • Valencia

Presencial
EUR 90.000 - 120.000
Global Procurement Audit Readiness & Compliance Specialist
Global Procurement Audit Readiness & Compliance Specialist

Tishman Speyer Properties • Bellprat

Híbrido
EUR 104.000 - 156.000
Health insurance
401(k) with company match
Paid vacation and holidays
Cyber Security Compliance Lead
Cyber Security Compliance Lead

Resideo Technologies Inc. • España

Presencial
EUR 52.000 - 76.000
Health insurance
Private illness insurance
Sports and recreation
+3
Director Corporate Security
Director Corporate Security

SYNNEX Corporation • Barcelona

Híbrido
EUR 120.000 - 180.000
Elective Benefits
Career growth programs
Life Empowerment Program
+1