Product & Solution Security Expert
Listed on 2026-10-02
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Together with our customers, we combine the real and digital worlds.
We are seeking a highly skilled and experienced Product & Solution Security Expert with a strong background in AWS, cloud security, AI security, governance, risk and compliance (GRC), and secure software development, who is passionate about cybersecurity and AI, to join our Building X cloud ecosystem. The ideal candidate will support and consult product teams in implementing security features in their products, identifying security risks, driving continuous compliance initiatives, and enabling the secure adoption of AI-powered development capabilities.
This role involves working closely with product teams to conduct security activities throughout the development process and driving a company-wide Shift-Left Security culture across software engineering, cloud operations, and AI-enabled development processes.
The Role:Product & Solution Security
- Supporting and consulting our product lines in implementing required product and solution security practices
- Acting as the primary security point of contact for product teams during development, project execution, and service operations
- Reporting to the Product / Technical Lead and the Product & Solution Security Officer
- Providing specialized knowledge in secure architecture and design to help product teams create and operate secure applications and services
- Bringing a strong application-security perspective by understanding the application stack end to end, including frontend, backend, APIs, data, identity, infrastructure, and cloud layers
- Providing strong AWS security expertise to improve the security posture of cloud-native applications and services
- Supporting security assessments, threat modeling, risk analysis, and remediation planning throughout the software lifecycle
- Supporting the implementation of Cybersecurity Compliance programs across multiple product teams
- Defining compliance-by-design approaches and integrating security and compliance controls directly into engineering workflows
- Supporting audits and certification programs including: ISO 2700, SOC2 and Internal security and compliance assessments
- Driving the organization's Shift-Left Security strategy, enabling teams to identify and address security issues early in the development lifecycle
- Defining and implementing secure development practices, policies, standards, and guardrails
- Working closely with development teams to embed security controls into CI/CD pipelines
- Supporting implementation of: ake care of secure coding practices, software supply chain security, dependency and container security, Infrastructure as Code (IaC) security, Cloud Security Posture Management (CSPM), and vulnerability and risk management processes
- Promoting self-service security capabilities and security automation across engineering teams
- Contributing to the design of the Building X Agentic AI Framework operating model
- Defining security requirements, governance standards, and control frameworks for AI-assisted development
- Conducting risk assessments, threat modeling, and security reviews for AI-enabled product development workflows
- Collaborate with platform, architecture, and development teams to embed Security-by-Design and Compliance-by-Design principles into the AI Development Lifecycle (AI-DLC)
- Support alignment with emerging AI security and governance standards (e.g., ISO 42001)
- Master's degree in Information Systems, Cybersecurity, Computer Science, or a related field
- Extensive experience (5+ years) as a Security Expert with deep knowledge of AWS security services, architectures, and best practices
- Experience implementing security controls in cloud-native and SaaS environments, coupled with a strong understanding of modern application architectures across all layers
- Proven experience in driving Continuous Compliance programs, security governance initiatives, and utilizing GRC platforms for automated control assessments
- Strong knowledge of Dev Sec Ops , modern software security practices, defining security controls for the AI-DLC, and understanding secure AI development and governance
- Strong knowledge of ISO 27001, SOC 2, CRA, and the EU Data Act.
- Relevant certifications such as AWS Certified Security - Specialty (highly desirable), CISSP, CISM, CCSP, and AWS Solutions Architect Professional (preferred)
- Experience working in highly regulated and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).