Point your AI agent at freehire and let it find you a job.

Get the CLI →

Principal Product Security Architect & Engagement Lead

NewBe an early applicant

Principal Product Security Architect & Engagement Lead

Role Summary

  • Lead and govern the end-to-end product lifecycle cybersecurity assessment engagement for the customer product including:
  • CRA-aligned security evaluation, architecture assessment, threat modelling, technical oversight, evidence traceability, and executive reporting.
  • Accountable for leading all the discussions during the assessment including product applicability, intended use analysis, classification, Risk-based decisions, test-plan quality, change control, customer workshops, executive reporting, and escalation of material risks.
  • Serve as the primary customer interface and ensure all assessment activities are executed in compliance with export-control requirements.

Key Responsibilities

  • Lead overall engagement delivery, governance, and customer coordination, including multidisciplinary team leadership, workstream ownership, estimation, change control, customer workshops, executive reporting, and difficult-risk communication
  • Conduct product security architecture assessments and threat modelling activities, including attack-tree, abuse-case, misuse-case, secure-update, rollback, recovery and safe-state architecture analysis
  • Perform trust boundary analysis and review data flows across product components and external integrations
  • Oversee CRA-aligned assessment methodology, compliance traceability, and lifecycle security evaluation, including CRA product scope, applicability and classification analysis, essential-requirement interpretation, conformity-assessment strategy, technical-documentation readiness, and compliance-evidence readiness
  • Evaluate operational resilience, recovery considerations, and lifecycle security controls across deployed product environments
  • Review secure-by-design implementation and product security governance practices
  • Guide technical testing activities and validate risk prioritization and exploitability context
  • Review security findings and ensure consistency across technical and compliance outputs
  • Lead executive reporting, release readiness assessment, and remediation discussions
  • Ensure evidence collection and assessment outputs align to CRA requirements, with control traceability, findings calibration, residual-risk governance, release-readiness conclusions, and defensible evidence mapping
  • Review lifecycle security considerations including secure decommissioning and data disposal practices
  • Assess security support-period commitments, update strategy, coordinated vulnerability disclosure, post-market vulnerability handling, incident-reporting readiness, and product logging, monitoring and auditability architecture
  • Evaluate connected-system and ecosystem-impact considerations, data minimization, sensitive-data handling, security-control design, and control effectiveness across product environments
  • Enforce export-control compliant handling of personnel, systems, and data
  • Provide final quality assurance and assessment signoff oversight

Required Skills & Experience

Mandatory:

  • Strong experience in product cybersecurity and secure-by-design principles, including product security architecture, secure-by-design governance, security-control design and effectiveness evaluation
  • Expertise in threat modelling, architecture review, and trust boundary analysis, including attack-tree, abuse-case, misuse-case, data-flow, data-minimization and sensitive-data analysis
  • Strong understanding of product lifecycle security and operational resilience concepts
  • Familiarity with secure SDLC, SBOM governance, and vulnerability management practices
  • Strong executive communication and stakeholder management capability
  • Control traceability, evidence management, release readiness, residual-risk assessment, findings calibration, negotiation, executive escalation, and material-risk communication
  • CRA product scope, applicability and classification analysis; CRA essential-requirement interpretation; conformity-assessment strategy and readiness; technical-documentation and compliance-evidence readiness
  • PSIRT and vulnerability handling processes, coordinated vulnerability disclosure, security support-period and update-strategy assessment, post-market vulnerability and incident-reporting readiness
  • NIST SSDF OR IEC 62443-4-1/4-2 frameworks; compliance and regulatory security assessments; product cybersecurity risk assessment; connected-device, embedded, IoT or regulated-product environments
  • Experience across both offensive security and security architecture domains
  • US Citizen or Green Card holder (US Person)

Good to have:

  • Experience leading CRA, regulated product security, or compliance-driven cybersecurity assessments
  • Experience leading engagement in export-controlled environments
  • FedRAMP or regulated environment experience preferred



Preferred Certifications

IEC 62443 (OT Security) or Certified DevSecOps Professional or any other relevant product-security credentials

Years of Required Experience

  • 12+ years in Product Security Architecture
  • 5+ years in complex customer assessment and regulatory assessment engagements
  • Five years leading complex customer security and regulatory assessment engagements
  • Demonstrated leadership of multidisciplinary product-security teams; experience defining assessment scope, effort estimates, workstream ownership and experience approving security reports


See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available