Product Security and Privacy Architect

Job not on LinkedIn

🕒 April 30

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of ASSA ABLOY Opening Solutions

ASSA ABLOY Opening Solutions

10,000+ employees

🔐 Security

🔧 Hardware

🤝 B2B

Security • Hardware • B2B

ASSA ABLOY Opening Solutions is a leading provider of security technology, specializing in the development and production of mechanical and electromechanical locking systems, access control solutions, and locking systems for various residential, commercial, and public buildings. The company is known for its innovative products that ensure safety and comfort, catering to diverse environments from healthcare facilities to educational institutions. With a comprehensive range of solutions, ASSA ABLOY enables secure and smooth movement of people, goods, and information across multiple sectors.

📋 Description

• Leading day-to-day security/privacy architecture governance • Defining corporate wide security and privacy requirements, controls, and standards • Defining corporate wide Secure Coding, third-party, deployment policies & other architecture-related standards • Defining required training content • Defining paved roads/security and privacy-by-design patterns and libraries • Leading development of AI-enabled PSP Architecture capabilities • Owning the threat modeling framework and quality bars • Running/approving security & privacy architecture reviews • Leading audit/assessment planning, evidence of expectations, and defensibility • Being responsible for tooling selection and integration related to security & privacy architecture domain • Architecting compliance, analyzing new regulations and standards to identify gaps in the platform's capabilities, standards, and controls • Assessing New Acquisitions Architecture and contributing to due diligence on a needed basis • Providing recommendations for risk acceptance and exception requests • Providing input on tooling strategy and integration guidance for non-architecture related domains • Providing guidance on security requirements for supply chain tooling, pipeline architecture, and associated standards • Validating that platform architecture enables enforcement of PSP security controls • Providing expert input on exploitability, attack paths, and mitigation options during Incident handling process • Providing guidance on true risk vs noise for security tool outputs and penetration tests.

🎯 Requirements

• Master's Degree in computer science or similar qualifications • At least 3 years in software/product security, application security, or security architecture • At least 7 years of hands-on software engineering / QA / DevOps earlier in career • At least one security or privacy certification (CISSP, CIPT, CSSLP, CEH, ...) is a plus • Proven ownership of at least one of: threat modeling program, secure design review governance, audit evidence management, security tooling strategy, penetration testing program or similar • Experience contributing to at least one Secure Software Development Lifecycle (SSDL) program • Working knowledge of general principles of application security • Working knowledge of threat modeling principles • Working Knowledge of security standards (OWASP, ISO, NIST, ...) • Knowledge of security regulations, such as the Radio Equipment Directive (RED), Cyber Resilience Act (CRA), Federal Information Processing Standards (FIPS), and Common Criteria (CC) or equivalent • Good understanding of cryptographic principles, including algorithms, key management, and protocols • Experience using security tools (SAST, DAST, SCA, Vulnerability Scanners, Secret Scanners) • Hands-on experience in at least one, preferably more, of these application domains: Embedded device Security, Mobile security, Web & API security, Desktop security • Experience with Agile/SAFe Methodology is preferred • Experience with usage of AI tools in the context of a security program is preferred • Cloud infrastructure, Supply Chain, and deployment Security is preferred.

🏖️ Benefits

• Competitive salary and rewards package • Competitive benefits and annual leave offering • A vibrant, welcoming & inclusive culture • Extensive career development opportunities and resources

Apply Now

Similar Jobs

🕒 April 30

Red Cup IT

11 - 50

🔒 Cybersecurity

☁️ SaaS

Senior Staff Security Engineer architecting scalable security solutions for diverse clients. Leading technical strategy and compliance across multi-tenant environments while mentoring senior engineers.

Ansible

AWS

Azure

Python

Splunk

Terraform

🕒 April 30

Virta Health

201 - 500

⚕️ Healthcare Insurance

🧘 Wellness

Cloud Security Engineer securing applications for Virta Health, reversing metabolic diseases. Leading application security initiatives and collaborating across teams for secure development practices.

Cloud

Google Cloud Platform

Kubernetes

Python

Terraform

Go

🕒 April 29

Optiv

1001 - 5000

Account Executive focusing on selling Optiv security services to key strategic accounts. Leading cross-functional teams and developing multi-year strategic account management plans in a remote setting.

Cyber Security

🕒 April 29

DoorDash

10,000+ employees

🛍️ eCommerce

🚗 Transport

Sr. Security Compliance Specialist leading audits and compliance programs for DoorDash's logistics engine. Ensuring security and readiness across a global infrastructure system.

🕒 April 29

Nelnet

5001 - 10000

📚 Education

💸 Finance

⚡ Energy

Security Advisor consulting on information security and compliance for higher education institutions. Assessing customer environments and providing recommendations for improvement.