- Location
- Netherlands - Eindhoven - Achtseweg Noord 5
- Workplace
- Onsite
- Type
- Full-time
- Department
- Engineering
- Experience
- 10+ years
- Source
- Workday
Description
Work Schedule
Standard (Mon-Fri)Environmental Conditions
OfficeJob Description
As part of Thermo Fisher Scientific, you will do meaningful work that helps our customers make the world healthier, cleaner, and safer.
Central R&D is seeking a senior Product Security Architect to shape security architecture across a global portfolio of complex products and engineering systems. You will translate product, customer, regulatory, and enterprise requirements into practical security direction that teams can apply throughout the product lifecycle.
This is a senior individual contributor role with broad divisional influence. You will lead through technical authority, trusted relationships, governance, and high-quality architecture guidance rather than direct reporting authority. You will work closely with product and software architects, engineering teams, product security leaders, quality and regulatory partners, manufacturing, service, business leaders, and enterprise partners.
How Will You Make an Impact?
You will establish consistent product security direction across products and platforms, helping teams identify risks earlier, apply secure development practices, and make defensible decisions where security, safety, quality, customer needs, cost, and delivery constraints intersect.
As Central R&D’s product security technical authority, you will provide technical analysis and recommendations to the cross-functional Product Security Governance Team and help accountable owners align on material risks, priorities, and decisions.
Success means that product teams receive clear and implementable security direction; material risks are identified and escalated early; security practices are applied consistently across the portfolio; and reusable architecture patterns reduce duplicated effort and recurring weaknesses.
Key Responsibilities
- Define and maintain product security vision, strategy, architecture principles, roadmaps, standards, reference architectures, and reusable security patterns.
- Anticipate emerging threats and regulatory changes and evolve product security architecture, standards, and roadmaps accordingly.
- Lead security architecture and threat modeling reviews covering identity, data protection, network boundaries, communications, update mechanisms, resilience, secrets management, and related product risks.
- Establish security requirements, architecture review gates, verification criteria, and traceable security evidence across the product lifecycle, including governance for new software and hardware introduced through product development projects.
- Embed secure-by-design, Zero Trust, and software supply chain security principles in product and platform strategies.
- Translate regulatory, customer, corporate, and product requirements into practical engineering standards, decision criteria, and escalation paths.
- Guide product risk, vulnerability, exception, and incident response decisions before and after product release.
- Establish governance for software supply chain security, including SBOMs, third-party and open-source components, provenance, code signing, and release integrity.
- Guide security assurance and penetration testing strategy, support customer and regulatory assessments, and build organizational capability through coaching, reusable guidance, and communities of practice.
Minimum Qualifications
- Bachelor’s degree in Software Engineering, Cybersecurity, Information Security, Systems Engineering, or a related technical field, or equivalent practical experience. An advanced degree is preferred but not required.
- 15+ years of relevant experience in product security, application security, embedded systems security, or security architecture.
- At least 10 years of experience performing or leading product security architecture, secure design, threat modeling, or technical security governance activities.
- Demonstrated experience guiding security decisions across multiple products, platforms, or engineering organizations.
- Experience translating security, regulatory, customer, and risk requirements into architecture guidance, verification criteria, and traceable evidence within a regulated development lifecycle.
- Experience with vulnerability governance and post-release product security response.
- Experience influencing cross-functional decisions in a distributed organization without relying on direct reporting authority.
Preferred Qualifications
- Experience with regulated, safety-relevant, connected, or long-lifecycle products, including scientific instruments, medical devices, industrial systems, or embedded products.
- Experience with software supply chain security and product penetration testing.
- Familiarity with product security regulations and standards, including the EU Cyber Resilience Act and relevant secure development or product assurance frameworks.
- One or more relevant professional certifications, such as CISSP, CSSLP, an applicable GIAC certification, CCSP, or an equivalent credential.