EU Product Security Officer, Regulatory & Standards Engagement (m/w/d)

Technology, Data & Digital · IT Infrastructure & Security · Cybersecurity · Software Engineering · Embedded Systems

In short

As an EU Product Security Officer, you will be the product cybersecurity authority for Emerson in the European Union. This senior role involves driving secure development practices, ensuring compliance with EU regulations like the Cyber Resilience Act and NIS-2, and representing Emerson in key industry forums. You will provide final cybersecurity sign-off, manage the secure development lifecycle, and oversee software supply chain security for EU-relevant products.

Responsibilities

  • Serve as Emerson's senior representative in EU cybersecurity regulatory and standards forums, contributing to standards drafts and position papers under the EU Cyber Resilience Act (CRA).
  • Provide final cybersecurity sign-off authority on EU product release decisions and participate in product gate reviews.
  • Drive the secure development lifecycle (SDL) across multiple EU-based product companies.
  • Translate evolving EU cybersecurity legislation into actionable internal product security requirements.
  • Own software supply chain security strategy and execution, including third-party component risk assessment and vulnerability impact analysis.
  • Apply deep expertise in product and embedded security fundamentals to guide architectural and design decisions.
  • Mentor and coach Product Security Leads, engineers, and cross-functional partners.
  • Anticipate future regulatory and threat-landscape shifts and recommend strategic investments in cybersecurity.
  • Maintain public technical visibility through publications, conference participation, and working group leadership.
  • Develop and maintain product-level security documentation and compliance artifacts.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Electrical or Systems Engineering, or a related field.
  • Minimum 12 years of progressive experience in product security, secure product development, or industrial/embedded cybersecurity assurance, including at least 5 years in a senior, principal, or distinguished individual contributor role.
  • Business-level English and German (mandatory).
  • Proven track record of representing an organization in cybersecurity standards bodies or regulatory working groups (e.g., IEC 62443, CENELEC, DKE, ETSI, ISA/ISA99, ENISA).
  • Demonstrated experience interpreting and implementing EU cybersecurity regulations, including the Cyber Resilience Act, NIS-2 Directive, RED Delegated Act, or comparable frameworks.
  • Deep expertise across secure development lifecycle practices, threat modeling, vulnerability management, PSIRT operations, and SBOM / software supply chain governance for industrial or embedded products.
  • Experience coordinating vulnerability management and disclosure activities with engineering, legal, and customer-facing teams.

Desired Qualifications

  • Master’s degree in Cybersecurity, Computer Science, Electrical or Systems Engineering, or a related field.
  • Min 15 years of experience in industrial control systems or OT product cybersecurity.
  • Existing membership, leadership role, or recognized credential within German or EU cybersecurity bodies.
  • TeleTrusT T.I.S.P., CISSP, GICSP, ISA/IEC 62443 Cybersecurity Expert, or equivalent senior cybersecurity certifications.
  • Demonstrated authorship of, or substantive contribution to, published cybersecurity standards, technical specifications, or industry position papers.
  • Experience leading regulatory compliance programs for industrial measurement, control, or automation products.
  • Prior experience as a Product Security Officer, Chief Product Security Officer, Distinguished Engineer, Principal Security Architect, or equivalent senior individual contributor role at an industrial manufacturer.

Benefits

  • Emerson prioritizes a workplace where every employee is valued, respected, and empowered to grow.
  • Fosters an environment that encourages innovation, collaboration, and diverse perspectives.
  • Commitment to ongoing career development and growing an inclusive culture.
  • Support through mentorship, training, or leadership opportunities.
  • Investment in employee success to make a lasting impact.
  • Believes diverse teams, working together, are key to driving growth and delivering business results.
#cybersecurity#regulatory#standards#EU#product security#vulnerability#compliance#Cyber Resilience Act#NIS-2#OT#industrial automation
Emerson Logo

Company

Emerson

Job Posted

3 weeks ago

Employment Type

Full Time

WorkMode

Hybrid

Experience Level

Senior

Locations

Berlin, Germany

Qualification

Bachelor, Master

Applicants

Be an early applicant