Senior Director, Product Security

hace 6 días


Barcelona, España Workato A tiempo completo

**About Workato**: **Why join us?**: Ultimately, Workato believes in fostering a **flexible, trust-oriented culture that empowers everyone to take full ownership of their roles**. We are driven by **innovation**and looking for** team players**who want to actively build our company. But, we also believe in **balancing productivity with self-care**. That's why we offer all of our employees a vibrant and dynamic work environment along with a multitude of benefits they can enjoy inside and outside of their work lives. Also, feel free to check out why: - Business Insider named us an "enterprise startup to bet your career on" - Forbes' Cloud 100 recognized us as one of the top 100 private cloud companies in the world - Deloitte Tech Fast 500 ranked us as the 17th fastest growing tech company in the Bay Area, and 96th in North America - Quartz ranked us the #1 best company for remote workers **Responsibilities**: Workato is looking for an exceptional security leader to establish and lead a global security team responsible for Workato's product and infrastructure security. In this role, you will also be responsible to: - Lead the company's development and implementation of a comprehensive product security strategy. - As a hands-on leader, manage and mentor a team of security engineers and analysts, providing guidance and direction for their professional growth. - Identify, develop, implement, and maintain security programs and processes across product development and production environments. - Oversee critical cybersecurity areas, including incident response, disaster recovery, awareness, monitoring, remediation, information governance, and digital security. - Lead all product security operations that protect against immediate threats and respond when something goes wrong. - Grow the product security programs and capabilities to an industry-leading position, finding opportunities to improve our existing approach and helping to guide the team to unlock that potential. - Communicate effectively with stakeholders at all levels about the security posture of products and the importance of product security. - Develop and oversee the development and enforcement of security policies and procedures based on industry-standard best practices. - Utilize business-relevant metrics to measure the program's efficiency and effectiveness, facilitate appropriate resource allocation, and increase the security program's maturity. - Work closely with internal stakeholders and business units to keep abreast of planned changes to technologies, working practices, and business activities that could impact the organization's Information Security or risk profile. - Support continued compliance with SOC2, HIPAA and other currently required standards and act as Product and Engineering technical lead within product security to expand certifications to include PCI, NIST800-171, ISO27001/277001, and FedRAMP. Ensure operation of related controls. Coordinate the provision of required evidence for audit. - Lead incident response activities and post-mortem analysis for any security breaches or incidents, liaising with the Legal, Security and Privacy teams on data protection, ensuring root causes of such breaches are understood and addressed. - Conduct hands-on security assessments, code reviews, and penetration testing to identify product vulnerabilities and security gaps as needed. - Leverage Workato as an automation solution for SOAR, GRC and other security-related use cases. **Requirements**: **Qualifications / Experience / Technical Skills**: - Deep understanding of security principles, techniques, and technologies such as OWASP Top 10, SANS Top 25, encryption, identity and access management, network security, and cloud security. - Familiarity with compliance frameworks and standards such as ISO 27001, SOC 2, GDPR, and CCPA. - An understanding of Application Security threats and countermeasures - Ability to provide strategic product security mentorship based on experience performing threat modeling and design reviews to assess security implications and requirements - Bachelor's or Master's degree in Computer Science, Information Security, or a related field. - Relevant security certifications (e.g., CISSP, OSCP, CEH) are a plus. **Soft Skills / Personal Characteristics**: - Outstanding interpersonal and communication skills; ability to communicate information successfully internally and externally and to drive multi-functional alignment and action - Excellent people leadership skills - providing direction, monitoring performance, motivating staff, and building a positive working environment



  • Barcelona, España Mirantis A tiempo completo

    **Company Description** **About Mirantis** Mirantis is seeking a **Senior Product Security Engineer** to help secure our portfolio of products and services, including enterprise software and critical infrastructure. This role is part of our growing** Product Security program** and will play a key role in implementing security controls, driving remediation...


  • Barcelona, España Almirall Hermal GmbH A tiempo completo

    Our executive search firm is partnering with a leading international pharmaceutical company headquartered in Barcelona to appoint an Information Security Associate Director to further strengthen its global cybersecurity capabilities within a complex, industrial and highly regulated environment. Role Overview The Information Security Associate Director will...


  • Barcelona, España Headhunting Firm A tiempo completo

    Our executive search firm is partnering with a leading international pharmaceutical company headquartered in Barcelona to appoint an Information Security Associate Director to further strengthen its global cybersecurity capabilities within a complex, industrial and highly regulated environment. Experiencia, cualificaciones y habilidades interpersonales,...


  • Barcelona, España Headhunting Firm A tiempo completo

    Our executive search firm is partnering with a leading international pharmaceutical company headquartered in Barcelona to appoint an Information Security Associate Director to further strengthen its global cybersecurity capabilities within a complex, industrial and highly regulated environment. Role Overview The Information Security Associate Director...


  • Barcelona, España Headhunting Firm A tiempo completo

    Our executive search firm is partnering with a leading international pharmaceutical company headquartered in Barcelona to appoint an Information Security Associate Director to further strengthen its global cybersecurity capabilities within a complex, industrial and highly regulated environment.¿Está considerando presentar su candidatura para este trabajo?...


  • Barcelona, España Headhunting Firm A tiempo completo

    Our executive search firm is partnering with a leading international pharmaceutical company headquartered in Barcelona to appoint an Information Security Associate Director to further strengthen its global cybersecurity capabilities within a complex, industrial and highly regulated environment.¿Está considerando presentar su candidatura para este trabajo?...


  • Barcelona, España Headhunting Firm A tiempo completo

    Our executive search firm is partnering with a leading international pharmaceutical company headquartered in Barcelona to appoint an Information Security Associate Director to further strengthen its global cybersecurity capabilities within a complex, industrial and highly regulated environment.¿Está considerando presentar su candidatura para este trabajo?...


  • Barcelona, España Mirantis A tiempo completo

    Mirantis is the Kubernetes-native AI infrastructure company, enabling organizations to build and operate scalable, secure, and sovereign infrastructure for modern AI, machine learning, and data-intensive applications. By combining open source innovation with deep expertise in Kubernetes orchestration, Mirantis empowers platform engineering teams to deliver...


  • Barcelona, Barcelona, España Headhunting Firm A tiempo completo

    Our executive search firm is partnering with aleading international pharmaceutical company headquartered in Barcelonato appoint anInformation Security Associate Directorto further strengthen its global cybersecurity capabilities within a complex, industrial and highly regulated environment.Role OverviewThe Information Security Associate Director will provide...

  • Product Security Manager

    hace 1 semana


    Barcelona, España Werfen A tiempo completo

    **Job Information**: - Number - WEBWW-2025-000061 - Job function - IT - Job type - Full-time - Location - Barcelona - Country - Spain **About the Position**: **Introduction**: Werfen is a growing, family-owned, innovative company founded in 1966 in Barcelona, Spain. We are a worldwide leader in specialized diagnostics in the areas of Hemostasis, Acute Care...