Product Security Manager ensuring compliance with Secure Development Lifecycle and managing security assessments at RIB. Collaborating with interdisciplinary teams to enhance product security across the lifecycle.
Responsibilities
Implementation of Secure Development Lifecycle (SDL) requirements across the entire product lifecycle
Conducting threat modeling, security reviews, and risk assessments for assigned products
Tracking and managing product-specific security incidents through to resolution and communicating status to management
Managing supply chain security risks for external components
Collecting and maintaining evidence to meet compliance requirements
Coordinating all security activities with development teams, security architects, and product owners in collaboration with our vulnerability and penetration testing team
Defining and evolving product-specific security requirements across the lifecycle
Primary contact for customer discussions on security, assessments, and vulnerability disclosure
Supporting security training and assessments to ensure product team expertise
Mentoring Product Security Engineers (if applicable) through reviews and technical guidance
Contributing to security architecture and roadmap by advising on emerging threats and technologies
Requirements
At least 5 years of experience in Product Security or Application Security
Deep understanding of Secure Development Lifecycle (SDL) processes and common security compliance frameworks
Demonstrable experience conducting security testing using SAST, DAST, and SCA tools
Knowledge of one or more programming languages such as C#, TypeScript, Java, JavaScript, Dart, C++, Python, or Delphi
Experience in vulnerability management and risk assessments
Strong communication skills for technical and business stakeholders
Project management experience in interdisciplinary teams
Independent working style and ability to mentor technical colleagues
Good German (C1) and English (C1) language skills
Benefits
Employee discounts (e.g., Corporate Benefits)
Bonuses (e.g., for marriage, birth, anniversaries)
Schneider Electric stock participation
Employee events (team events, summer parties, …)
Health management (e.g., gym discounts, company doctor, …)
Head of Physical Security leading security practices across Babcock. Ensuring protection of infrastructure and national security while managing complex projects and stakeholder relationships.
Security Officer providing safety and security for patients and visitors at healthcare facilities. Responding to emergencies, patrolling, and monitoring security protocols across multiple locations.
Director of Data Security and Governance leading comprehensive data protection program. Responsible for implementing data governance framework, classification program, and managing data security policies.
Quality and Patient Safety Specialist supporting implementation and monitoring in a healthcare network. Engaging in quality processes and ensuring patient safety across hospitals.
Expert security professional leading incident response and security platform administration. Collaborating with stakeholders to enhance information security programs at Pluralsight.
Technical Specialist - Cybersecurity role in India emphasizing hands - on expertise with security tools and incident response capabilities. Responsibilities include automation scripting and workflow integration.
Technical Lead - Cybersecurity responsible for securing systems against threats at Birlasoft. Developing incident response strategies and collaborating with teams to enhance security.
Security staff ensuring comprehensive safety monitoring using modern technologies in a metallurgical company. Work in different shifts to provide safety in assigned areas.
Security Engineer at a leading research - intensive biopharmaceutical company. Building and operating cloud security data pipelines with modern tooling to protect research and innovation.
Security Officer responsible for the safety and protection of customers at Pond Security Service GmbH. Performing various security tasks including patrols, access control, and monitoring systems.