Назад
Company hidden
обновлено 5 дней назад

Head of Product Security (IoT)

Формат работы
hybrid
Тип работы
fulltime
Грейд
head
Английский
b2
Страна
Switzerland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Head of Product Security (IoT): Establishing and overseeing product security for IoT devices, mobile applications, desktop software, and cloud services across their entire lifecycle with an accent on secure development, regulatory compliance, and customer data protection. Focus on leading global security programs, securing firmware and AI systems, managing vulnerabilities and incidents, and planning cryptographic migration to post-quantum standards.

Location: Lausanne, Switzerland; hybrid role with 3 days on site

Company

hirify.global designs software-enabled hardware solutions for gaming, productivity, creativity, and connectivity, including IoT products and related digital services.

What you will do

  • Define and execute the global product security strategy, roadmap, policies, standards, and risk reporting.
  • Lead compliance programs for regulations including the EU Cyber Resilience Act and UK PSTI Act.
  • Embed Security by Design and Safe AI by Design practices across IoT, mobile, desktop, and cloud product development.
  • Oversee firmware, supply chain, manufacturing, secure provisioning, OTA updates, and product decommissioning security.
  • Direct penetration testing, vulnerability management, AI-enabled threat hunting, and product-related incident response.
  • Lead and mentor the product security team and collaborate with engineering, manufacturing, cloud, legal, compliance, and cybersecurity functions.

Requirements

  • At least 12 years of experience in product, application, and embedded systems security across IoT, mobile, and cloud environments.
  • Advanced knowledge of secure SDLC, DevSecOps, threat modeling, security architecture reviews, SAST, DAST, SCA, binary analysis, and fuzzing.
  • Experience securing firmware, embedded systems, HSMs, provisioning processes, and OTA update mechanisms.
  • Deep understanding of adversarial AI, data poisoning, model inversion, prompt injection, cryptography, PKI, key management, and post-quantum cryptography.
  • Knowledge of global product security regulations, vulnerability disclosure requirements, and third-party and supply chain security governance.
  • Demonstrated leadership, executive communication, team mentoring, budgeting, forecasting, and financial management skills.

Culture & Benefits

  • Flexible hybrid work model with remote and on-premises collaboration depending on the team or department.
  • Inclusive and collaborative environment focused on diversity, creativity, and positive global impact.
  • Comprehensive benefits packages that vary by location.
  • Support for physical, financial, emotional, intellectual, and social wellbeing.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →