$ cat jobs/staff-product-security-specialist-wabtec-39450f236293.json
Staff Product Security Specialist
Essa posição é para atuar presencialmente em Contagem, MG. Who will you be working with? You will be working with the Product Security Incident Response Team (PSIRT), partnering closely with Product Security, Engineering, Enterprise Information Security, Compliance, Product Management, and business leaders across the organization. This team is responsible for coordinating security incident response activities, managing product vulnerability disclosures, supporting regulatory reporting requirements, and ensuring the organization's readiness to effectively respond to cybersecurity threats. How will you make a difference? As a member of the Product Cybersecurity organization, you will be responsible for leading Product Security Incident Response Team (PSIRT) activities and coordinating cross-functional stakeholders during product vulnerability and cybersecurity emergency response situations. The Staff Product Security Specialist serves as a technical and operational leader, driving rapid decision-making, communication, and execution during critical security events. In this role, you will facilitate incident response activities, support regulatory compliance obligations, conduct threat analysis, and lead organizational readiness initiatives to strengthen Wabtec's product security posture. You will work closely with global teams to ensure vulnerabilities and security incidents are effectively managed while continuously improving the maturity and effectiveness of the PSIRT program. What do we want to know about you? Required Experience & Qualifications Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or a related field. Strong experience in Cybersecurity. Advanced cybersecurity certifications such as CISSP, CISM, GCIH, GCIL, or equivalent. Experience with product vulnerability management. Strong critical thinking and analytical problem-solving skills. Experience with Secure Development Lifecycle (SDLC) practices. Experience with cybersecurity co