Third Party Product Security Engineer
Core
Lead supplier security assessments, risk-based qualification, and secure product qualification for third-party components to strengthen supply chain security and compliance.
Role type
Third-party product security engineer (supply chain risk & compliance)
Builds
Secure qualification of third-party software and firmware components
Domain
Industrial automation / Manufacturing / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
supplier security assessments, risk-based qualification, Secure Development Lifecycle (SDL) implementation, regulatory compliance (EU CRA, NIS2), threat analysis & risk assessments (TARA), root cause analysis (RCA), program governance, stakeholder engagement
Preferred skills
Lean / Six Sigma certification, Agile methodologies, Third-Party Risk Management (TPRM), GRC platforms
Technologies
Jira, OneTrust, GRC platforms
Responsibilities
Lead evaluation and onboarding of suppliers; Conduct supplier security assessments with closed-loop remediation; Review supplier design controls and secure software development practices; Partner on Threat Analysis & Risk Assessments (TARA) and design-for-security reviews; Guide enterprise-wide adoption of supply chain security requirements; Support Quality and Security Agreements; Lead investigation of security and quality issues; Deliver training and enablement sessions; Ensure readiness transition of suppliers to production; Present risk and compliance insights to leadership
Seniority
Mid-Senior, hands-on IC
