About the job :
Logitech is the Sweet Spot for people who want their actions to have a positive global impact while having the flexibility to do it in their own way.
Role : Principal Product Security :
Product Security Governance :
- Develop, implement, and maintain comprehensive product security policies, standards, and procedures.
- Establish clear security requirements for all product development initiatives.
- Define and manage the product security risk assessment and threat modeling processes.
- Ensure adherence to industry standards and regulations (e.g., OWASP, GDPR, etc.)
- Conduct regular security reviews and audits of products and processes.
Product Security Tooling :
Evaluate, select, and implement cutting-edge security tools for static and dynamic analysis, vulnerability scanning, and penetration testing.Manage and optimize the configuration and usage of these tools to maximize their effectiveness.Integrate security tools into the software development lifecycle (SDLC) and CI / CD pipelines.Provide training and support to development teams on the effective use of security tools.R&D Security Support :
Partner with R&D teams to identify and mitigate security risks early in the design phase.Conduct secure code reviews and provide actionable feedback to developers.Assist in the investigation and remediation of security incidents related to products.Foster a security-conscious culture within R&D through training, mentorship, and collaboration.Additional Responsibilities :
Stay abreast of the latest security threats, vulnerabilities, and mitigation techniques.Research emerging security technologies and trends to inform future strategies.Represent the company on product security matters to internal and external stakeholders.Working with Multiple Teams :
To cover the entire organization, the Principal Product Security Engineer will work closely with multiple teams, including :
Product Management : to understand product requirements and ensure that security features are aligned with business objectives.Engineering : to integrate security tools into the development process and provide guidance on secure coding practices.Quality Assurance : to collaborate on security testing and validation activities.Operations : to ensure that security measures are implemented and maintained in production environments.Risk and Compliance : to assess and manage product security risks and ensure compliance with regulations(ref : hirist.tech)