Sr Principal Product Security Architect
About the role
As a technical leader of Product Security architecture at Dematic, you will be critical to advancing security throughout the company, enabling business success and growth in an environment of increasing demands for comprehensive and robust product security. Reporting to the Vice President of Global Product Security, you will provide strategic and expertly informed technical security guidance to product development, execution, sales, and support organizations across Dematic.
You will assist in defining and implementing a broad, detailed technical security strategy encompassing all Dematic products, including next-gen software solutions, existing software solutions, and operational technology solutions. Your role will be crucial in ensuring the development of truly secure products and their operation in a robustly secure environment by providing best-in-class architectural guidance and vision.
You will collaborate with technology leadership and engineering teams to define and implement the Product Security organization’s vision and strategy, inspiring and supporting development, execution, and customer-facing teams as they progress toward greater security maturity. As a trusted resource, you will proactively defend systems and data from attack while ensuring product security meets or exceeds all relevant regulatory requirements.
Responsibilities
- Provide strategic and expertly informed technical security guidance to globally distributed product development, execution, sales, and support organizations.
- Contribute to a technical security strategy encompassing all Dematic products, including next-gen software, existing software, and operational technology solutions.
- Collaborate with leadership to define and implement the vision and strategy of the Product Security organization.
- Drive advancement of technical and operational capabilities necessary to implement a robust product security strategy that earns customer and business partner trust.
- Provide guidance and leadership for building security into every aspect of Dematic’s product development lifecycle for both software and operational technology.
- Perform technical security risk assessments of internally developed and third-party products and systems.
- Advise and educate development teams on application, cloud, and product security best practices, security automation, and the proper use of third-party security products and services.
- Build and maintain high-trust, collaborative relationships with product development, product management, corporate security, compliance, and other teams.
- Mentor application, infrastructure, and operational technology security engineers, as well as security champions globally.
- Provide guidance in response to product security incidents.
- Continuously learn, evaluate industry trends, and engage with industry leaders to inform and direct Dematic’s security technology strategy.
- Perform research and present on relevant security technology, practices, and threats.
- Work closely with security staff and product development teams to ensure products and services withstand foreseeable attacks.
- Engage with product management, customer sales/support, and other functions to further business development from a security perspective.
- Potentially engage with customers directly as required by project leadership.
Requirements
- 10+ years of hands-on experience in modern engineering environments, including at least 5 years as a hardware/software engineer and 5+ years in a security engineer/architect role.
- Extensive experience in software development, enterprise architecture, and security engineering in public cloud environments (GCP, AWS, and/or Azure).
- Strong development skills in multiple languages, platforms, and frameworks (Java, Python, C, C++, C#, JavaScript, TypeScript, Node, React, Golang).
- Deep knowledge of Operational Technology (OT) security and associated regulatory frameworks.
- Extensive experience with AppSec, OT security, and cloud security principles, patterns, and techniques.
- Ability to analyze complex software and hardware systems, architectures, and code to uncover weaknesses and vulnerabilities.
- Deep understanding of public cloud security models, best practices, and compliance frameworks/regulations.
- Expert understanding of zero trust security models to meet security and compliance requirements while enabling business flexibility.
- Expert threat modeling skills.
- Significant experience in infrastructure as code, compliance as code, container-based/Kubernetes deployments, serverless architectures, and DevSecOps continuous deployment environments.
- Proficiency in applied cryptography, including methods, algorithms, uses, and patterns.
- Experience successfully mentoring and leading technical staff and small teams.
- Proven ability to lead in complex risk environments.
- Preference for and ability to thrive in highly collaborative work environments.
- Passionate, quick learner with dedication to quality and successful outcomes.
- Outstanding written and spoken communication skills, including public speaking and presenting to engineering, business, and executive leadership.
- Experience presenting persuasive arguments and complex information to technical and non-technical audiences.
- Experience giving industry conference presentations is a plus.
- Bachelor’s degree in computer science or other STEM discipline is required; equivalent experience may be substituted.
- Graduate degree is a plus.
- Technical security certifications (e.g., GIAC, Offensive Security) are highly desirable, especially in ICS, application security, and cloud security.
Benefits
- Career development opportunities
- Competitive compensation and benefits
- Pay transparency
- Global opportunities
Pay
The base pay range for this role is estimated to be $131,250 - $201,250 at the time of posting. Final compensation will be determined by factors such as work location, education, experience, knowledge, and skills.