Principal Product Security Architect & Engagement Lead

Zappsec Inc.

  • Tewksbury, MA
  • 4 days ago

    Highlights

    Oversee CRA-aligned assessment methodology, compliance traceability, and lifecycle security evaluation, including CRA product scope, applicability and classification analysis, essential-requirement interpretation, conformity-assessment strategy, technical-documentation readiness, and compliance-evidence readiness. Lead and govern the end-to-end product lifecycle cybersecurity assessment engagement for the customer product including: CRA-aligned security evaluation, architecture assessment, threat modelling, technical oversight, evidence traceability, and executive reporting.

    Numbers & Facts

    LocationTewksbury, MA

    Description

    Principal Product Security Architect & Engagement Lead

    Role Summary

    • Lead and govern the end-to-end product lifecycle cybersecurity assessment engagement for the customer product including:
    • CRA-aligned security evaluation, architecture assessment, threat modelling, technical oversight, evidence traceability, and executive reporting. 
    • Accountable for leading all the discussions during the assessment including product applicability, intended use analysis, classification, Risk-based decisions, test-plan quality, change control, customer workshops, executive reporting, and escalation of material risks. 
    • Serve as the primary customer interface and ensure all assessment activities are executed in compliance with export-control requirements.

    Key Responsibilities

    • Lead overall engagement delivery, governance, and customer coordination, including multidisciplinary team leadership, workstream ownership, estimation, change control, customer workshops, executive reporting, and difficult-risk communication
    • Conduct product security architecture assessments and threat modelling activities, including attack-tree, abuse-case, misuse-case, secure-update, rollback, recovery and safe-state architecture analysis
    • Perform trust boundary analysis and review data flows across product components and external integrations
    • Oversee CRA-aligned assessment methodology, compliance traceability, and lifecycle security evaluation, including CRA product scope, applicability and classification analysis, essential-requirement interpretation, conformity-assessment strategy, technical-documentation readiness, and compliance-evidence readiness
    • Evaluate operational resilience, recovery considerations, and lifecycle security controls across deployed product environments
    • Review secure-by-design implementation and product security governance practices
    • Guide technical testing activities and validate risk prioritization and exploitability context
    • Review security findings and ensure consistency across technical and compliance outputs
    • Lead executive reporting, release readiness assessment, and remediation discussions
    • Ensure evidence collection and assessment outputs align to CRA requirements, with control traceability, findings calibration, residual-risk governance, release-readiness conclusions, and defensible evidence mapping
    • Review lifecycle security considerations including secure decommissioning and data disposal practices
    • Assess security support-period commitments, update strategy, coordinated vulnerability disclosure, post-market vulnerability handling, incident-reporting readiness, and product logging, monitoring and auditability architecture
    • Evaluate connected-system and ecosystem-impact considerations, data minimization, sensitive-data handling, security-control design, and control effectiveness across product environments
    • Enforce export-control compliant handling of personnel, systems, and data
    • Provide final quality assurance and assessment signoff oversight

    Required Skills & Experience

    Mandatory:

    • Strong experience in product cybersecurity and secure-by-design principles, including product security architecture, secure-by-design governance, security-control design and effectiveness evaluation
    • Expertise in threat modelling, architecture review, and trust boundary analysis, including attack-tree, abuse-case, misuse-case, data-flow, data-minimization and sensitive-data analysis
    • Strong understanding of product lifecycle security and operational resilience concepts
    • Familiarity with secure SDLC, SBOM governance, and vulnerability management practices
    • Strong executive communication and stakeholder management capability
    • Control traceability, evidence management, release readiness, residual-risk assessment, findings calibration, negotiation, executive escalation, and material-risk communication
    • CRA product scope, applicability and classification analysis; CRA essential-requirement interpretation; conformity-assessment strategy and readiness; technical-documentation and compliance-evidence readiness
    • PSIRT and vulnerability handling processes, coordinated vulnerability disclosure, security support-period and update-strategy assessment, post-market vulnerability and incident-reporting readiness
    • NIST SSDF OR IEC 62443-4-1/4-2 frameworks; compliance and regulatory security assessments; product cybersecurity risk assessment; connected-device, embedded, IoT or regulated-product environments
    • Experience across both offensive security and security architecture domains
    • US Citizen or Green Card holder (US Person)

    Good to have:

    • Experience leading CRA, regulated product security, or compliance-driven cybersecurity assessments
    • Experience leading engagement in export-controlled environments
    • FedRAMP or regulated environment experience preferred

    Preferred Certifications

    IEC 62443 (OT Security) or Certified DevSecOps Professional or any other relevant product-security credentials

    Years of Required Experience

    • 12+ years in Product Security Architecture
    • 5+ years in complex customer assessment and regulatory assessment engagements
    • Five years leading complex customer security and regulatory assessment engagements
    • Demonstrated leadership of multidisciplinary product-security teams; experience defining assessment scope, effort estimates, workstream ownership and experience approving security reports

    Powered by JazzHR

    Similar Jobs