> Markdown version of [/jobs/ext/2365036-principal-product-security-architect-engagement-lead](https://www.wearedevelopers.com/jobs/ext/2365036-principal-product-security-architect-engagement-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Product Security Architect & Engagement Lead - **Company:** RIVAGO INFOTECH INC. - **Location:** Tewksbury, MA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Systems Development Life Cycle, Sherwood Applied Business Security Architecture, Data Streaming, Software Vulnerability Management, Software Security, Togaf - **Published:** August 28, 2026 - **Apply:** https://www.dice.com/job-detail/69f24161-2e29-4bef-b4dd-38097aef2f03 ## About the Role Mandatory: * Strong experience in product cybersecurity and secure-by-design principles * Expertise in threat modelling, architecture review, and trust boundary analysis * Strong understanding of product lifecycle security and operational resilience concepts * Familiarity with secure SDLC, SBOM governance, and vulnerability management practices * Strong executive communication and stakeholder management capability * Experience across both offensive security and security architecture domains Good to have: * Experience leading CRA, regulated product security, or compliance-driven cybersecurity assessments * Experience leading engagement in export-controlled environments Preferred Certifications * CISSP, CSSLP, SABSA / TOGAF (preferred) * FedRAMP or regulated environment experience preferred Years of Required Experience * 7-10 years in product application security * 5+ years in complex customer assessment and regulatory assessment engagements ## Description Lead and govern the end-to-end product lifecycle cybersecurity assessment engagement for the customer product, including CRA-aligned security evaluation, architecture assessment, threat modeling, technical oversight, evidence traceability, and executive reporting. Serve as the primary customer interface and ensure all assessment activities are executed in compliance with export-control requirements., * Lead overall engagement delivery, governance, and customer coordination * Conduct product security architecture assessments and threat modeling activities * Perform trust boundary analysis and review data flows across product components and external integrations * Oversee CRA-aligned assessment methodology, compliance traceability, and lifecycle security evaluation * Evaluate operational resilience, recovery considerations, and lifecycle security controls across deployed product environments * Review secure-by-design implementation and product security governance practices * Guide technical testing activities and validate risk prioritization and exploitability context * Review security findings and ensure consistency across technical and compliance outputs * Lead executive reporting, release readiness assessment, and remediation discussions * Ensure evidence collection and assessment outputs align to CRA requirements * Review lifecycle security considerations including secure decommissioning and data disposal practices * Enforce export-control compliant handling of personnel, systems, and data * Provide final quality assurance and assessment signoff oversight ## Related Videos - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Python-Based Data Streaming Pipelines Within Minutes](https://www.wearedevelopers.com/videos/1233-python-based-data-streaming-pipelines-within-minutes) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Why and when should we consider Stream Processing frameworks in our solutions](https://www.wearedevelopers.com/videos/1085-why-and-when-should-we-consider-stream-processing-frameworks-in-our-solutions) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)