Sr Principal Product Security Architect
KION Group AG11 months ago
Grand Rapids, MI, USA +3 moreStaff+
Base Salary
$131k - $201k/yr
Responsibilities
- Provide strategic technical security guidance to globally distributed product development, execution, sales, and support organizations.
- Define and implement product security strategy across software, hardware, cloud, and operational technology products.
- Guide secure product development lifecycle practices, security automation, application security, cloud security, and OT security.
- Perform technical security risk assessments of internally developed and third-party products and systems.
- Advise teams on security architecture, zero trust models, threat modeling, cryptography, compliance, and secure use of third-party products and services.
- Mentor application, infrastructure, operational technology security engineers, and globally distributed security champions.
- Provide guidance during product security incidents and evaluate emerging security technologies, practices, and threats.
- Collaborate with product management, customer-facing teams, corporate security, compliance, and technology leadership.
- Present security research and recommendations to technical, business, and executive leadership and potentially engage directly with customers.
Requirements
- 10+ years of hands-on experience in modern engineering environments, including at least 5 years as a hardware/software engineer and 5+ years in a security engineer or architect role.
- Extensive experience with software development, enterprise architecture, and security engineering in public cloud environments, including GCP, AWS, and/or Azure.
- Strong development skills in multiple languages, platforms, and frameworks, including Java, Python, C, C++, C#, JavaScript, TypeScript, Node, React, and Golang.
- Deep knowledge of operational technology security and associated regulatory frameworks.
- Extensive experience with application security, OT security, cloud security, security analysis of complex software and hardware systems, and vulnerability discovery.
- Expertise in public cloud security models, zero trust security models, threat modeling, applied cryptography, and security and compliance frameworks.
- Significant experience with infrastructure as code, compliance as code, container-based and Kubernetes deployments, serverless architectures, and DevSecOps continuous deployment environments.
- Experience mentoring and leading technical staff and small teams in complex risk environments.
- Outstanding written, spoken, public speaking, and technical and executive communication skills; industry conference presentation experience is a plus.
- Bachelor’s degree in computer science or another STEM discipline is required, with equivalent experience accepted; a graduate degree is a plus.
- Technical security certifications such as GIAC or Offensive Security certifications are highly desirable, especially in ICS, application security, and cloud security.
Benefits
- Career development opportunities.
- Competitive compensation and benefits.
- Pay transparency.
- Global opportunities.