> Markdown version of [/jobs/ext/185736-director-of-product-security-governance-compliance](https://www.wearedevelopers.com/jobs/ext/185736-director-of-product-security-governance-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director of Product Security Governance & Compliance - **Company:** Keysight Technologies - **Location:** Colorado Springs, CO, United States - **Experience:** Expert - **Salary:** $237,480.0 - $296,850.0 - **Contract:** Permanent contract - **Skills:** Systems Engineering, Cloud Computing, Control Objectives for Information and Related Technology (COBIT), Continuous Integration, Federal Information Processing Standards (FIPS), Firmware, Systems Development Life Cycle, Toolchain, Software Vulnerability Management, Delivery Pipeline, Software Security, Data Analytics, Industrial Software - **Published:** May 15, 2026 - **Apply:** https://jobs.localjobnetwork.com/job/detail/87177334/Director-of-Product-Security-Governance-Compliance ## About the Role * 10+ years in product security, cybersecurity governance, or compliance within software and/or hardware technology companies * 5+ years of leadership experience, including managing managers * Demonstrated experience building governance frameworks across both software and embedded/hardware product environments * Strong working knowledge of EU Cyber Resilience Act (CRA) and related frameworks (e.g., NIS2, ISO/IEC 27001, IEC 62443, ETSI EN 303 645) * Experience translating regulatory and standards requirements into engineering controls and operational processes * Proven track record partnering with engineering, firmware, hardware, legal, and go-to-market teams * Strong executive communication skills with experience presenting to senior leadership * Deep program management experience leading large-scale, cross-functional initiatives Preferred Qualifications * Experience in a Fortune 500 or similarly complex multinational organization * Background in connected devices, IoT, or industrial systems * Familiarity with SBOM generation/management, vulnerability management platforms, and secure build pipelines * Experience supporting regulatory audits and product certifications (e.g., CE marking, FIPS, Common Criteria) * Relevant certifications (e.g., CISSP, CISM, CRISC) Leadership Profile * Strategic and systems-oriented thinker with strong execution discipline * Comfortable operating in ambiguity and driving structure at scale * Influential leader capable of aligning global stakeholders without direct authority * Data-driven with strong risk prioritization and decision-making skills * Clear communicator who translates technical and regulatory requirements into business impact ## Description Governance & Policy * Define and maintain a unified product security policy framework spanning cloud software, on-prem platforms, firmware, and hardware devices * Establish control objectives and standards aligned to secure SDLC, secure firmware development, hardware root of trust, SBOM, vulnerability management, and product lifecycle security * Ensure policies are embedded into engineering systems (CI/CD, PLM, release gates) and are measurable and enforceable Regulatory Leadership (EU CRA & Global) * Act as the internal authority on EU Cyber Resilience Act (CRA), including applicability to software, firmware, and connected devices * Interpret and decompose regulatory requirements into actionable engineering, manufacturing, and support controls * Lead enterprise-wide CRA readiness, including gap assessments, remediation programs, and technical documentation requirements (e.g., conformity assessments, CE marking support) * Monitor evolving global regulations (e.g., NIS2, RED Delegated Act, U.S. EO 14028 implications) and adapt governance strategy accordingly Compliance Programs & Operations * Build and scale a global product compliance program covering both software delivery pipelines and hardware manufacturing lifecycles * Define KPIs/KRIs and maturity models; implement dashboards for executive visibility * Oversee internal/external audits, regulatory inquiries, and evidence management across engineering and manufacturing systems * Ensure traceability from policy control implementation evidence (including SBOM, VEX, and vulnerability disclosure processes) Leadership & Organization Development * Lead a team of managers across governance, risk, and compliance domains * Establish operating models that scale across business units and geographies * Drive talent development, succession planning, and organizational maturity Cross-Functional Partnership * Engineering (software, firmware, hardware): integrate controls into SDLC, toolchains, and design processes * Product Management: align security requirements with product roadmaps and customer commitments * Legal & Compliance: align regulatory interpretation, risk posture, and disclosures * Sales & Customer Success: support customer assurance, RFPs, and contractual obligations * Support & PSIRT: align vulnerability intake, disclosure, and remediation SLAs * Manufacturing & Supply Chain: ensure component-level security, supplier requirements, and product integrity Program Management & Execution * Lead complex, multi-year regulatory and compliance programs with global scope * Drive prioritization, risk management, and dependency resolution across a matrixed organization * Deliver clear executive reporting on posture, risks, and remediation progress ## Related Videos - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Speeding up Web Apps performance with WebAssembly and Emscripten](https://www.wearedevelopers.com/videos/1985-speeding-up-web-apps-performance-with-webassembly-and-emscripten) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [How Data is Shaping our Games](https://www.wearedevelopers.com/videos/176-how-data-is-shaping-our-games) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [What is Software Engineering?](https://www.wearedevelopers.com/magazine/289-what-is-software-engineering)