Head of Product Security

Posted Yesterday
Be an Early Applicant
2 Locations
In-Office
Senior level
Healthtech
The Role
Own and execute product security strategy for a global software portfolio: ensure CRA readiness, SBOM and evidence processes, set SAST/DAST/SCA/security tooling baselines, define security quality gates, govern AI-driven remediation, and build a Security Guild and Security Champions to embed secure development practices.
Summary Generated by Built In

As the leading company in the field of software solutions for healthcare, we operate in 19 countries and employ over 9,000 dedicated staff members. You will work in a dynamic and innovative environment full of opportunities. With your commitment and passion, you have the chance to make a sustainable difference.  

CGM Leverages AI: We’re looking for people who feel the power of AI in the e-health environment, who want to help shape change, and who are driven by a curious passion to see how technology can make healthcare smarter, simpler, and better. 

Together, we are shaping the healthcare system of the future. Become part of our mission and make a difference – for a world where knowledge saves lives! 

Are you passionate about groundbreaking products? Do you have the talent to turn ideas into real, valuable solutions—while always keeping the bigger picture in mind? Then we’d love to meet you! 

Your Responsibilities:

  • You define and own the product security strategy for our global portfolio and establish the policy framework for secure development, security baselines, and release criteria.
  • You drive CRA readiness across the entire portfolio – from product classification to conformity assessment, and the build-out of SBOM and evidence processes.
  • You set the mandatory security tooling baseline (SAST, DAST, SCA, secrets scanning) and define security quality gates within the delivery pipeline.
  • You shape the governance for our AI-driven security remediation (agentic OpenCode pipeline) – including guardrails, approval criteria, and quality assurance.
  • You build the Security Guild and a network of Security Champions embedded in the FIRE teams, and foster lived security practice through training and coaching

Your Profile:

  • Several years of experience in product security, application security, or as a deputy CISO within a complex, multi-product software organisation.
  • Demonstrable, current expertise in the EU Cyber Resilience Act – requirements, classification logic, and conformity assessment – along with working knowledge of NIS2 and GDPR.
  • Strong, practical knowledge of the secure development lifecycle, threat modelling, and application security testing, together with hands-on experience with SAST, DAST, SCA, and SonarQube tooling.
  • Experience with SBOM generation and governance, as well as with managing supply chain risk; understanding of AI-assisted and agentic development workflows.
  • Strong communication and stakeholder management skills to enforce standards without direct line authority; CISSP or an equivalent certification is an advantage.

What you can expect from us:  

  • Mobile work: Work flexibly on the move two days a week and on site three days a week. 

  • Attractive locations: In addition to fully equipped workplaces, regular events such as summer parties and Christmas parties await you at our locations. 

  • Development: Our in-house academy and our portfolio of external cooperation partners will support you in your further development. 

  • Health: Health is a valuable asset for us. Our in-house canteen offers a selection of tasty and healthy dishes every day, and we welcome you to our fully equipped fitness center for weekly courses (online & offline). 

  • More is always possible: The kindergarten on our CGM campus in Koblenz helps our employees to organize their working day even more flexibly. We also offer corporate benefits, the option of a job bike, a company pension scheme, and much more. 

Diversity is part of CGM! We look forward to receiving your application regardless of disability, gender, nationality, ethnic and social background, religion, age, sexual orientation, and identity. 

Convinced? Apply online now with your detailed application documents (including salary expectations and earliest possible starting date).

Skills Required

  • Several years of experience in product security, application security, or deputy CISO within a complex, multi-product software organisation.
  • Demonstrable, current expertise in the EU Cyber Resilience Act (classification logic and conformity assessment) and working knowledge of NIS2 and GDPR.
  • Strong practical knowledge of secure development lifecycle, threat modelling, and application security testing.
  • Hands-on experience with SAST, DAST, SCA, SonarQube, and secrets scanning.
  • Experience with SBOM generation and governance, managing supply chain risk, and understanding AI-assisted/agentic development workflows.
  • Strong communication and stakeholder management skills to influence without direct line authority.
  • CISSP or equivalent certification.

CompuGroup Medical US Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CompuGroup Medical US and has not been reviewed or approved by CompuGroup Medical US.

  • Leave & Time Off Breadth Paid time off, sick leave, and company holidays are part of the package, and feedback suggests the time-off policies are viewed favorably by many.
  • Retirement Support A 401(k) plan with company match is offered, which feedback suggests adds meaningful value to total rewards.
  • Flexible Benefits Remote or flexible work options are available in some roles and are framed as part of the total package, which feedback suggests can improve perceived value even when base pay varies.

CompuGroup Medical US Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Austin, Texas
320 Employees

What We Do

CompuGroup Medical is a global e-health provider with a comprehensive portfolio of cutting-edge IT solutions for the healthcare industry. We connect doctors, hospitals, community health facilities, dentists, pharmacists, health insurers and other service providers to create an integrated network of all healthcare stakeholders. As a result, we can help these organizations improve efficiency, optimize care and increase patient satisfaction while also improving profitability. Our market-leading solutions include everything from electronic health records to innovative practice management systems. These solutions are present in over 400,000 practices and healthcare organizations worldwide. We are also proud to maintain and sustain long-term relationships with our clients, many of whom have been using our products for decades. Our dedicated, knowledgeable team consistently delivers innovative products and services with the customer in mind, knowing that in addition to running an effective business, their main focus is to heal the patient. We share that same passion and it drives everything we do. As an owner-led and publicly traded company, CGM uniquely combines the personal touch of a local business with the strength of a global entity. We are committed to meeting and exceeding our clients’ expectations, and our goal is to become the #1 choice for all healthcare providers in the United States – a position we have already achieved in many other countries around the world.

Similar Jobs

Navan Logo Navan

Staff Software Engineer

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Hybrid
Berlin, DEU
3300 Employees
60K-120K Annually

Deepgram Logo Deepgram

Account Executive

Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
In-Office or Remote
28 Locations
150 Employees

Datadog Logo Datadog

Senior Software Engineer

Artificial Intelligence • Cloud • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
6 Locations
6500 Employees

Navan Logo Navan

Chief Of Staff

Fintech • Information Technology • Payments • Productivity • Software • Travel • Automation
Easy Apply
Hybrid
Berlin, DEU
3300 Employees

Similar Companies Hiring

Sailor Health Thumbnail
Healthtech • Social Impact • Telehealth
New York City, NY
20 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account