Product Security Architect

Thermo Fisher Scientific Inc.
Eindhoven, Netherlands
about 1 month ago
Apply on www.careerjet.nl
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Systems Engineering Cyber Security Key Management Open Source Technology Zero Trust Network Access Secure Coding Software Engineering Software Security Industrial Software

Job description

  • Eindhoven, Noord-Brabant
  • Vast
  • Voltijds

  • 20 uren geleden

Work Schedule Standard (Mon-Fri) Environmental Conditions Office, As part of Thermo Fisher Scientific, you will do meaningful work that helps our customers make the world healthier, cleaner, and safer. Central R&D is seeking a senior Product Security Architect to shape security architecture across a global portfolio of complex products and engineering systems. You will translate product, customer, regulatory, and enterprise requirements into practical security direction that teams can apply throughout the product lifecycle. This is a senior individual contributor role with broad divisional influence. You will lead through technical authority, trusted relationships, governance, and high-quality architecture guidance rather than direct reporting authority. You will work closely with product and software architects, engineering teams, product security leaders, quality and regulatory partners, manufacturing, service, business leaders, and enterprise partners. How Will You Make an Impact? You will establish consistent product security direction across products and platforms, helping teams identify risks earlier, apply secure development practices, and make defensible decisions where security, safety, quality, customer needs, cost, and delivery constraints intersect. As Central R&D’s product security technical authority, you will provide technical analysis and recommendations to the cross-functional Product Security Governance Team and help accountable owners align on material risks, priorities, and decisions. Success means that product teams receive clear and implementable security direction; material risks are identified and escalated early; security practices are applied consistently across the portfolio; and reusable architecture patterns reduce duplicated effort and recurring weaknesses., * Define and maintain product security vision, strategy, architecture principles, roadmaps, standards, reference architectures, and reusable security patterns.

  • Anticipate emerging threats and regulatory changes and evolve product security architecture, standards, and roadmaps accordingly.
  • Lead security architecture and threat modeling reviews covering identity, data protection, network boundaries, communications, update mechanisms, resilience, secrets management, and related product risks.
  • Establish security requirements, architecture review gates, verification criteria, and traceable security evidence across the product lifecycle, including governance for new software and hardware introduced through product development projects.
  • Embed secure-by-design, Zero Trust, and software supply chain security principles in product and platform strategies.
  • Translate regulatory, customer, corporate, and product requirements into practical engineering standards, decision criteria, and escalation paths.
  • Guide product risk, vulnerability, exception, and incident response decisions before and after product release.
  • Establish governance for software supply chain security, including SBOMs, third-party and open-source components, provenance, code signing, and release integrity.
  • Guide security assurance and penetration testing strategy, support customer and regulatory assessments, and build organizational capability through coaching, reusable guidance, and communities of practice.

Requirements

  • Bachelor’s degree in Software Engineering, Cybersecurity, Information Security, Systems Engineering, or a related technical field, or equivalent practical experience. An advanced degree is preferred but not required.
  • 15+ years of relevant experience in product security, application security, embedded systems security, or security architecture.
  • At least 10 years of experience performing or leading product security architecture, secure design, threat modeling, or technical security governance activities.
  • Demonstrated experience guiding security decisions across multiple products, platforms, or engineering organizations.
  • Experience translating security, regulatory, customer, and risk requirements into architecture guidance, verification criteria, and traceable evidence within a regulated development lifecycle.
  • Experience with vulnerability governance and post-release product security response.
  • Experience influencing cross-functional decisions in a distributed organization without relying on direct reporting authority., * Experience with regulated, safety-relevant, connected, or long-lifecycle products, including scientific instruments, medical devices, industrial systems, or embedded products.
  • Experience with software supply chain security and product penetration testing.
  • Familiarity with product security regulations and standards, including the EU Cyber Resilience Act and relevant secure development or product assurance frameworks.
  • One or more relevant professional certifications, such as CISSP, CSSLP, an applicable GIAC certification, CCSP, or an equivalent credential.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.nl
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:41 min

Protecting etcd databases using Key Management System plugins

Alex Soto Alex Soto · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

2:47 min

Securing code provenance with digital identity signatures

Marcus Ross Marcus Ross · World Congress 2026 Europe

Videos

See all

Related articles

See all