Product Security Manager responsible for securing RIB Software products by executing SDL requirements and ensuring compliance throughout product lifecycles.
Responsibilities
Own operational security for assigned RIB Software products
Execute secure development lifecycle (SDL) requirements and ensure compliance through coordinated security reviews and assessments.
Serve as the primary security point of contact for product teams while collecting evidence required for compliance.
Drive regular threat modelling, security reviews, and risk assessments for assigned products.
Track and manage product-specific security issues through resolution, communicating status to leadership.
Manage supply chain security risks for externally provided components used within the product.
Collect and maintain compliance evidence for compliance requirements.
Coordinate security activities with development teams through Security Architects and Product Owners.
Identify and refine security requirements applicable to the product across its lifecycle.
Serve as primary contact for customer security discussions, assessments, and vulnerability disclosure.
Support security training and assessment initiatives to ensure product teams have demonstrated security expertise.
Mentor assigned Product Security Engineers through collaborative review and guidance.
Requirements
5+ years experience in product security or application security
Strong understanding of SDL processes and security compliance frameworks.
Proven ability to conduct security testing using SAST, DAST, and SCA tools.
Familiarity with one or more of C#, Typescript, Java, JavaScript, Dart, C++, Python, and/or Delphi
Experience with vulnerability management and risk assessment.
Excellent communication skills for technical and business stakeholders.
Project management experience with cross-functional teams.
Ability to drive improvements in security culture.
Demonstrated ability to work independently and provide guidance to technical colleagues.
Bachelor's degree in Computer Science, Cybersecurity, or related field, or equivalent professional experience.
Benefits
competitive salary and benefits package
opportunities for professional growth and development
Senior Security Engineer managing security across the company for an AI healthcare startup. Overseeing vulnerability management and incident response to enhance security standards.
IT Security Administrator managing security controls and protecting Uline's systems from threats. Collaborating with IT teams and enhancing security posture in a growing North American enterprise.
AVP of Network Security Governance at LPL Financial focused on enterprise security and networking projects, requiring extensive IT security and architecture expertise.
Manager in PwC's Identity and Access Management team focusing on cybersecurity through advanced technologies and strategies. Leading client engagements and mentoring junior staff while maintaining project success.
Manager in Cybersecurity at PwC overseeing threat intelligence strategies and team management. Liaising with stakeholders and maintaining project success while mentoring junior staff.
Product Security Manager responsible for operational security and compliance for RIB Software products, leading security reviews and risk assessments. Collaborates with multidisciplinary teams to ensure secure development practices.
SAP Security Architect and Team Lead ensuring security for vital defence systems. Overseeing audits and managing a team of SAP specialists in a hybrid working environment.
Cyber Supplier Qualification Specialist guiding suppliers through cyber security compliance for a defence program. Collaborating with stakeholders and supporting risk management and assurance processes.
Internal Audit Senior Manager overseeing audit transformation and execution at GE Vernova. Leading teams to develop audit strategies and manage stakeholder relationships in a hybrid work environment.
Internal Audit Senior Manager overseeing audit teams and aligning audit strategies with risk priorities at GE Vernova. Leading high - performance audit teams under a hybrid working model.