> Markdown version of [/jobs/ext/1652559-product-security-lead-of-materialise-software](https://www.wearedevelopers.com/jobs/ext/1652559-product-security-lead-of-materialise-software). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Product Security Lead of Materialise Software - **Company:** ProntoPro - **Location:** Spain - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Code Review, Software Engineering, Software Security, Devsecops - **Published:** July 10, 2026 - **Apply:** https://es.trabajo.org/oferta-5354-6c11c5bbcf999d101cf1fef21b77ff6b ## About the Role and Security Champions, such as improving their understanding of the security checklist Governance and external trust Review security metrics and evidence produced by security engineering Support audits, certifications, and customer security assessments Represent the company's product security posture externally when required What this role does not do Design detailed system architectures Build or operate security tooling Review code or manage vulnerabilities day-to-day Directly manage security champions or software engineers Your profile Required Skills And Experience Strong understanding of product and cloud security in modern DevOps environments Experience working with security regulations and frameworks (ISO 27001, NIS2, SOC 2, NIST, FedRAMP, or similar) Proven ability to make and defend risk-based decisionsCredibility with senior engineering and product stakeholders Clear written and verbal communication, especially around trade-offs Experience profile ~8+ years in software engineering, product security, or security leadership roles ~ Experience in product-centric, engineering-driven organizations ~ Exposure to regulated environments is strongly preferred Success looks like Security expectations are clear and predictable for product and engineering Risk acceptance is explicit, documented, and rarely escalated late Engineering teams ship securely by default using platform guardrails Audits and customer security reviews are uneventful and well-prepared J-18808-Ljbffr ## Description security regulations and standards Define pragmatic compliance intent and scope Identify, document, and accept residual product security risks Ensure risks and exceptions are explicit, time-bounded, and owned Strategy and alignment Define and maintain a product security strategy aligned with business goals Translate regulatory and risk drivers into a prioritized security roadmap Align security priorities with product and engineering planning cycles Cross-functional leadership Partner closely with the: Product Management Team on roadmap alignment and customer commitments Engineering Management Team on delivery realities and investment trade-offs DevSecOps Lead on platform-level security objectives Security Architect on translating intent into secure designs CISO to align product security decisions with enterprise risk posture and regulatory obligations where applicable Act as an escalation point when security, product, and delivery priorities conflict Support the Engineering Delivery teams ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)