Product Security Engineering Lead

hace 1 semana


Barcelona, España AstraZeneca A tiempo completo

Are you ready to be part of the future of healthcare? Are you able to think big, be bold, and harness the power of digital and AI to tackle longstanding life sciences challenges? Then Evinova, a new health tech business part of the AstraZeneca Group might be for you

Transform billions of patients’ lives through technology, data and cutting-edge ways of working. You’re disruptive, decisive and transformative. Someone who’s excited to use technology to improve patients’ health. We’re building a new healthtech business - Evinova, a fully-owned subsidiary of AstraZeneca Group.

Evinova is know looking for someone who would like to join the Cyber Security team as a Product Security Engineering Lead.

Evinova delivers market-leading digital health solutions that are science-based, evidence-led, and human experience-driven. Thoughtful risks and quick decisions come together to accelerate innovation across the life sciences sector. Be part of a diverse team that pushes the boundaries of science by digitally empowering a deeper understanding of the patients we’re helping. Launch pioneering digital solutions that improve the patients’ experience and deliver better health outcomes. Together, we have the opportunity to combine deep scientific expertise with digital and artificial intelligence to serve the wider healthcare community and create new standards across the sector.

**Key responsibilities**
- Develop and operationalize a standardized Application Security program which encompasses the core activities of Threat Modeling, Security Tools and Testing (e.g., SAST, SCA, DAST, IAST, etc.), and incorporating “privacy by design” and “secure by default” design processes into the CI / CD pipeline. Additionally, in collaboration with the Cyber GRC Lead - develop security metrics articulating the health of the overall Application Security program.
- Establish strong and productive relationships with Development and Engineering teams to ensure cyber security is viewed as a partner and not a blocker.
- Develop secure development standards and related trainings to raise awareness of secure coding practices, threat actor tactics, and regulatory requirements
- Execute security architecture reviews for major product changes, providing assurance over security standards alignment, and driving security enhancements across existing solutions.

**Minimum Qualifications**
- Bachelor’s degree in Technology, Computer Science, Software Engineering, or a related field.
- Prior experience providing AppSec capabilities for a SaaS / cloud service provider.
- Familiarity with “Software as a Medical Device” related regulations and standards is a strong plus.
- Expert level understanding of the OWASP Top Ten vulnerabilities, API security considerations, and related remediation strategies.
- Expert level understanding and prior use of AppSec scanning tools and processing results into actionable tasks (e.g., SAST, SCA, DAST).
- Strong familiarity and past experiences conducting Open-Source Software Clearance (technical focus) and Threat Modelling.
- Prior experiences successfully driving “secure by default” buy in across multiple teams.
- Ability to make pragmatic decisions by analyzing highly complex situations, assessing risks and balancing strategic and tactical compliance/quality requirements.
- Ability to work independently in a fast-paced environment with a proven ability to manage competing priorities.
- Excellent written and verbal communications skills (English), project management, process improvement, attention to details and strategic thinking skills are highly preferred
- At leasr one of the following professional certifications: Certified Information Systems Security Professional (CISSP), Certified Cloud Security Professional (CCSP), AWS Certified Security, and / or Certified Ethical Hacker (CEH).

**Desired Qualifications**
- Master’s degree in Technology, Computer Science, Software Engineering, or a related field.
- Prior experience as a Software Developer
- Expert knowledge on threat actors targeting the Healthtech sector and SaaS solution providers.
- Experience in providing AppSec capabilities within a highly regulated sophisticated global business environment, particularly in the healthcare and / or clinical research industry.
- Demonstrate initiative, strong customer orientation, and cross-cultural working.

**Why Evinova( AstraZeneca)?**

Evinova draws on AstraZeneca’s deep experience developing novel therapeutics, informed by insights from thousands of patients and clinical researchers. Together, we can accelerate the delivery of life-changing medicines, improve the design and delivery of clinical trials for better patient experiences and outcomes, and think more holistically about patient care before, during and after treatment. We know that regulators, healthcare professionals and care teams at clinical trial sites do not want a fragmented approach. They do not want a future where ever



  • Barcelona, España N26 A tiempo completo

    **About the opportunity**: We are looking for a data-driven, security savvy **Product Manager to help build the Trust & Safety suite of products** of the future bank and help deliver key growth and operational metrics. Our Security Engineering segment's mission is to make N26 the most trusted bank by efficiently integrating state-of-the-art information...

  • Technical Product Lead

    hace 3 semanas


    Barcelona, España Capitole A tiempo completo

    Opportunity – Technical Product Lead Cualquier información adicional que necesite para este trabajo se encuentra en el texto a continuación. Asegúrese de leerla detenidamente y luego envíe su solicitud. About the roleWe’re looking for a Technical Product Lead to define and lead data-driven engineering products that help teams deliver better, faster,...


  • Barcelona, España N26 A tiempo completo

    We are seeking a Tech Lead to join the Database Platform Team within the Platform Engineering Domain. You will define the future of our operational data storage, focusing on next-generation scaling, security, and developer experience. Platform Engineering's mission is to provide trusted, performant, and self-service platforms, enabling product teams to build...

  • Technical Product Lead

    hace 2 semanas


    Barcelona, España agap2 Spain A tiempo completo

    Overview We are supporting a large, international aviation and technology group in the search for a Technical Product Lead with a strong Platform Engineering background. This role sits at the intersection of Product, Engineering, Data and Cloud , owning the vision and roadmap for a greenfield Engineering Metrics Platform . The platform aggregates data from...


  • Barcelona, España Workato A tiempo completo

    **About Workato**: **Why join us?**: Ultimately, Workato believes in fostering a **flexible, trust-oriented culture that empowers everyone to take full ownership of their roles**. We are driven by **innovation**and looking for** team players**who want to actively build our company. But, we also believe in **balancing productivity with self-care**. That's why...


  • Barcelona, España Werfen A tiempo completo

    **Job Information**: - Number - WEBWW-2025-000061 - Job function - IT - Job type - Full-time - Location - Barcelona - Country - Spain **About the Position**: **Introduction**: Werfen is a growing, family-owned, innovative company founded in 1966 in Barcelona, Spain. We are a worldwide leader in specialized diagnostics in the areas of Hemostasis, Acute Care...

  • Technical Product Lead

    hace 3 semanas


    Barcelona, España Provide A tiempo completo

    We’re hiring a Technical Product Lead to own the vision and roadmap for a suite of engineering platform and metrics products used by software, data, and AI teams at scale.Cualquier información adicional que necesite para este trabajo se encuentra en el texto a continuación. Asegúrese de leerla detenidamente y luego envíe su solicitud.This role focuses...


  • Barcelona, España Mirantis A tiempo completo

    Mirantis is the Kubernetes-native AI infrastructure company, enabling organizations to build and operate scalable, secure, and sovereign infrastructure for modern AI, machine learning, and data-intensive applications. By combining open source innovation with deep expertise in Kubernetes orchestration, Mirantis empowers platform engineering teams to deliver...

  • Product Security Manager

    hace 2 semanas


    Barcelona, España Werfen A tiempo completo

    Job SummaryThe Product Security Manager is responsible for developing and managing a central Secure Development Lifecycle program, to ensure security and privacy by design across the entire product portfolio, covering all stages from pre-market development to post-market surveillance. This role involves developing and implementing global security strategies,...

  • Product Security Manager

    hace 2 semanas


    Barcelona, España Werfen A tiempo completo

    Job SummaryThe Product Security Manager is responsible for developing and managing a central Secure Development Lifecycle program, to ensure security and privacy by design across the entire product portfolio, covering all stages from pre-market development to post-market surveillance. This role involves developing and implementing global security strategies,...