Role Summary
The Senior Manager, Information Security is accountable for operational security execution, regulatory readiness, and security product leadership. This role oversees daily security operations, manages compliance and governance activities, and owns the integration of security and regulatory requirements, including those introduced by the Cyber Resilience Act, into product development, lifecycle management, and operational processes.
The position combines security operations leadership, regulatory and compliance ownership, and security product responsibility, ensuring that both internal systems and customer‑facing products meet security, resilience, and vulnerability management expectations throughout their lifecycle.
Information Security Operations and Governance
- Lead day‑to‑day execution of the enterprise information security program in alignment with company strategy and risk posture.
- Oversee security operations including monitoring, vulnerability management, incident response, root‑cause analysis, and remediation tracking.
- Manage implementation and continuous improvement of the ISO27001‑based Information Security Management System (ISMS).
- Ensure ongoing compliance with applicable regulatory requirements, industry standards, and customer security expectations, including emerging product security regulations such as the Cyber Resilience Act.
- Coordinate preparation for internal and external audits, regulatory reviews, certifications, and customer security assessments.
- Lead investigation and response activities for security incidents, vulnerabilities, and control failures, including follow‑up remediation actions.
- Maintain and evolve IT and product security policies, standards, procedures, and technical baselines.
- Drive security awareness initiatives and promote a culture of secure‑by‑design and shared responsibility across the organization.
Cyber Resilience Act and Product Security Accountability
- Serve as the operational owner for Cyber Resilience Act readiness, interpretation, and implementation across products, platforms, and services.
- Coordinate adoption of CRA‑aligned requirements including secure development lifecycle controls, product risk assessment, threat modeling, vulnerability handling, and coordinated disclosure processes.
- Partner with engineering and product teams to ensure security and resilience requirements are embedded throughout the full product lifecycle, from design through end‑of‑life.
- Ensure product security documentation, evidence, and technical controls support regulatory conformity assessments and audits.
- Track and manage security vulnerabilities impacting products, including prioritization, remediation tracking, customer communication, and regulatory reporting as required.
- Act as a primary liaison with Legal, Compliance, Engineering, and Product leadership on CRA‑related and product security regulatory matters.
- Monitor evolving global product security regulations and standards, assessing impact and recommending proactive controls or design changes.
Security Product and Portfolio Leadership
- Own and define security requirements across the company’s portfolio of products, software, platforms, and managed services.
- Act as the primary security stakeholder and internal customer proxy for security‑related product initiatives and roadmaps.
- Lead cross‑functional security councils involving product management, engineering, services, legal, compliance, and operations.
- Evaluate and prioritize security features, enhancements, and remediation efforts based on regulatory impact, risk exposure, and customer needs.
- Develop security‑related business cases, including scope definition, impact analysis, and risk mitigation value.
- Partner with Product Owners and Engineering teams to translate security and regulatory requirements into epics, user stories, and acceptance criteria.
- Ensure delivery of completed security capabilities, including validation, documentation, testing, and operational readiness.
- Maintain subject‑matter expertise in product security standards, vulnerability management practices, and security maturity models.
Leadership and Management
- Directly manage the Information Security Manager and assigned security staff.
- Provide coaching, mentorship, and performance management aligned with evolving security and regulatory demands.
- Coordinate cross‑functional execution of security initiatives across IT, engineering, and product organizations.
- Escalate risks, compliance gaps, and resource constraints to the Vice President, Technology and Information Security.
- Support workforce planning, capability development, and scaling of operational and product security functions.