← Takaisin työpaikkoihin

Senior Product Security Architect / Threat Modeling Expert

  • Paikan päällä
  • Suomi
  • Englanti
  • Julkaistu 28.09.26 14:56

Role Overview

We are seeking a highly experienced Product Security Architect with strong expertise in Threat Modeling and Application Security to assess, enhance, and validate the cybersecurity posture of complex software-enabled products. The role will focus on secure architecture reviews, threat assessments, cybersecurity compliance, and remediation planning, ensuring alignment with cybersecurity standards and EU Cyber Resilience Act (CRA) requirements.

Key Responsibilities

Threat Modeling & Security Assessments

Review, validate, and refine product threat models using industry-standard methodologies (STRIDE, PASTA, Attack Trees, etc.).Perform comprehensive security assessments across:Application and UI softwareLinux-based platformsContainerized environmentsREST APIs and digital interfacesFPGA-integrated systemsBuild and release environmentsProduction processes and customer-facing documentationIdentify attack surfaces, trust boundaries, and security gaps across standalone and integrated product ecosystems. Product Security Architecture

Analyze product architectures against internal cybersecurity standards and industry best practices.Assess hardware and software trust boundaries, including:TPM (Trusted Platform Module)TEE (Trusted Execution Environment)Secure Boot and hardware-rooted trust mechanismsReview cybersecurity aspects of multi-product solutions and interconnected systems.Evaluate container-based architectures, Linux security controls, and API security implementations. Compliance & Security Governance

Assess product readiness against EU Cyber Resilience Act (CRA) requirements.Create and validate Cryptographic Bill of Materials (CBOM).Identify compliance gaps and recommend remediation strategies.Update security architecture and design documentation to reflect required cybersecurity controls.

Remediation Planning & Advisory

Develop detailed action plans for remediation, categorized by engineering functions such as:UI/Application DevelopmentPlatform SoftwareLinux EngineeringFPGA DevelopmentBuild & Release TeamsProduction/Manufacturing TeamsProvide ongoing security consulting, design reviews, and implementation guidance.Review and approve security improvements implemented by development teams. Key Skills

Threat ModelingApplication Security (AppSec)Product Security Architecture ReviewsSecure SDLC & Secure-by-DesignAPI Security, Container Security, Linux SecuritySecurity Standards & Compliance ReviewsEU Cyber Resilience Act (CRA)MPSOC, FPGA SecurityHardware Security Architecture