Senior Product Security Engineer managing security vulnerabilities across Red Hat software and OSS projects. Leading incident response and ensuring compliance with EU Cyber Resilience Act.
Responsibilities
Manage and provide timely response and disclosure of security vulnerabilities and incidents across Red Hat software, Fedora, and other OSS projects.
Ensure Red Hat Product Security processes and disclosures align with the EU Cyber Resilience Act (CRA) and other relevant regulations.
Conduct in-depth risk assessments on vulnerabilities in Red Hat OSS projects and communicate risks effectively to diverse stakeholders (engineers, architects, senior leadership).
Contribute to customer-facing security documentation, references, and data, including Common Vulnerabilities and Exposures (CVE) pages and metadata.
Provide technical leadership, mentor junior engineers, and drive continuous improvement in vulnerability management practices (e.g., contributing to SBOM generation).
Actively participate in relevant OSS working groups to shape and implement industry standards for vulnerability disclosure and coordination.
Requirements
6+ years of experience in cybersecurity incident management and coordination and/or with delivering technology-related software
Bachelor’s degree in a technical field
Industry certifications like CISSP, CSSLP, CISA/CISM, PMP are a plus
Expert knowledge and practical understanding of the Linux Operating System
Proven expertise in security vulnerabilities, risk assessment, and the Confidentiality, Integrity, and Availability (CIA) triad
Strong change management skills to identify, track, and implement improvements for continuous enhancement of incident response following security events
Ability to work effectively and autonomously in a demanding, fast-paced, and culturally diverse environment across multiple time zones
Exceptional professional written and verbal communication skills in English.
Senior Data Engineer architecting and overseeing the implementation of scalable data ecosystems. Driving AI integration into data pipelines while mentoring junior engineers at Red Hat.
Data Engineer working on enhancing security data visibility within Red Hat’s product security team. Building data pipelines and integrating AI for data workflows, based in North Carolina.
Network Security Engineer at Eurobank leading the design of network security architectures. Collaborating with teams to ensure compliance and effective network security implementations in a banking environment.
Patrol Officer creating a secure environment for patients at Health Sciences Centre. Enforcing laws and assisting in medical and nursing staff in Winnipeg, Canada.
OT (Cyber) Security Officer responsible for securing IT and OT systems in large infrastructure projects. Collaborating with a security team to develop cybersecurity strategies and incident responses.
Cyber Security Consultant at NewTec aiding clients in implementing security measures and management plans. Engaging in project diversity with experienced specialists in a supportive environment.
Technical Security Engineer supporting national security by implementing security solutions for government clients. Collaborating with teams to assess vulnerabilities and protect mission data.
Lead Information Systems Security Manager at Booz Allen managing Risk Management Framework authorization and continuous monitoring of IT systems in compliance with security policies.
ISSO providing advanced cyber solutions for government clients. Leading security assessments and mitigation planning to secure mission - critical systems.
Cybersecurity Senior Associate analyzing complex cybersecurity issues and mentoring junior team members. Building client relationships while contributing to threat intelligence and vulnerability management initiatives.