← Back to jobs

Senior Product Security Architect / Threat Modeling Expert

  • On-site
  • Finland
  • English
  • Posted 25.09.26 11:10

Job Summary:Role: Product Security Architect / Threat Modelling ExpertWork from Office – 5 days working from Client Office Later after 3 months, it will be 2 days in the office or remoteWork Location: Oulu, Finland Language - Candidate must have strong English communication skills. Finnish language proficiency would be an added advantage. Eligibility: Who have EU Citizenship status and People form Sweeden / Norway / Denmark who can relocate to Oulu are welcome to apply Employment type: Subcontractor or Permanent Client interview – Yes Role OverviewWe are seeking a highly experienced Product Security Architect with strong expertise in Threat Modelling and Application Security to assess, enhance, and validate the cybersecurity posture of complex software-enabled products. The role will focus on secure architecture reviews, threat assessments, cybersecurity compliance, and remediation planning, ensuring alignment with cybersecurity standards and EU Cyber Resilience Act (CRA) requirements. Key ResponsibilitiesThreat Modelling & Security AssessmentsReview, validate, and refine product threat models using industry-standard methodologies (STRIDE, PASTA, Attack Trees, etc.).Perform comprehensive security assessments across:Application and UI softwareLinux-based platformsContainerized environmentsREST APIs and digital interfacesFPGA-integrated systemsBuild and release environmentsProduction processes and customer-facing documentationIdentify attack surfaces, trust boundaries, and security gaps across standalone and integrated product ecosystems. Product Security ArchitectureAnalyse product architectures against internal cybersecurity standards and industry best practices.Assess hardware and software trust boundaries, including:TPM (Trusted Platform Module)TEE (Trusted Execution Environment)Secure Boot and hardware-rooted trust mechanismsReview cybersecurity aspects of multi-product solutions and interconnected systems.Evaluate container-based architectures, Linux security controls, and API security implementations. Compliance & Security GovernanceAssess product readiness against EU Cyber Resilience Act (CRA) requirements.Create and validate Cryptographic Bill of Materials (CBOM).Identify compliance gaps and recommend remediation strategies.Update security architecture and design documentation to reflect required cybersecurity controls.Remediation Planning & AdvisoryDevelop detailed action plans for remediation, categorised by engineering functions such as:UI/Application DevelopmentPlatform SoftwareLinux EngineeringFPGA DevelopmentBuild & Release TeamsProduction/Manufacturing TeamsProvide ongoing security consulting, design reviews, and implementation guidance.Review and approve security improvements implemented by development teams. Key Skills:Threat ModelingApplication Security (AppSec)Product Security Architecture ReviewsSecure SDLC & Secure-by-DesignAPI Security, Container Security, Linux SecuritySecurity Standards & Compliance ReviewsEU Cyber Resilience Act (CRA)MPSOC, FPGA SecurityHardware Security Architecture