Product Development Cyber Risk Specialist
Your Mission
Guide and support project managers in integrating cybersecurity throughout the lifecycle of digital products and services.
The mission focuses on ensuring compliance with key regulations such as CRA and NIS2, alignment with international standards including ISO27001, and application of recognized best practices like OWASP.
The role also includes managing cyber risks and vulnerabilities to ensure secure‑by‑design and secure‑by‑default products and services.
Main Tasks
Embed cybersecurity requirements from the earliest project stages and ensure their consistent application throughout the project lifecycle.
Perform and review threat modeling and cyber risk assessments using methods such as EBIOS RM.
Translate regulatory requirements (CRA, NIS2) into actionable security controls and project deliverables.
Support ISO27001 ISMS implementation and align project activities with AnnexA controls.
Define, implement, and monitor vulnerability management frameworks, including integration of SAST, SCA, and DAST tools in CI/CD pipelines
Review system, application, cloud, and embedded architectures to ensure effective security controls and risk mitigation.
Coordinate with developers, architects, and stakeholders to track remediation actions and ensure closure of critical vulnerabilities.
Produce audit‑ready documentation, security assessments, and compliance evidence.
Qualifications & Professional skills
- 5 to 10 years of experience in cybersecurity, preferably in product‑oriented or regulated environments.
- Strong knowledge of cybersecurity frameworks and standards: ISO27001/27002, ISO27005, OWASP (Top10, ASVS, SAMM).
- Solid experience in risk assessment and threat modeling methodologies (EBIOSRM, STRIDE, TARA).
- Practical understanding of vulnerability management processes and security testing tools (SAST, SCA, DAST).
- Expertise in integrating DevSecOps practices within CI/CD environments.
- Ability to assess and secure diverse architectures: web, cloud, networked systems, and embedded/IoT.
- Additional experience in penetration testing, security auditing, or security architecture is an asset.
- Fluent English with good writing and presentation skills
Attitude & Interpersonal skills
- Strong communication skills, with the ability to engage and advise diverse stakeholders.
- Analytical mindset and structured approach to problem solving and risk evaluation.
- Proactive attitude with a focus on continuous improvement of security practices.
- Ability to collaborate effectively across project management, R&D, IT, and security teams.
- Strong technical writing skills to produce clear, actionable, and audit‑ready documentation.
- Comfortable challenging designs and decisions constructively to enhance security posture.