Head of Product Security at CompuGroup Medical | Berlin, DE | Rezi

Head of Product Security at CompuGroup Medical

Head of Product Security

CompuGroup Medical · Berlin, DE

2 weeks ago

Head of Product Security

CompuGroup Medical · Berlin, DE

19 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

CGM is seeking individuals passionate about AI in e-health to help shape the future of healthcare through smarter, simpler, and better technology. Join our mission to make a difference where knowledge saves lives.

Responsibilities

  • Define and own the product security strategy for the global portfolio.
  • Establish the policy framework for secure development, security baselines, and release criteria.
  • Drive CRA readiness across the entire portfolio, including product classification, conformity assessment, SBOM, and evidence processes.
  • Set the mandatory security tooling baseline (SAST, DAST, SCA, secrets scanning).
  • Define security quality gates within the delivery pipeline.
  • Shape the governance for AI-driven security remediation, including guardrails, approval criteria, and quality assurance.
  • Build the Security Guild and a network of Security Champions embedded in FIRE teams.
  • Foster lived security practice through training and coaching.

Requirements

  • Several years of experience in product security, application security, or as a deputy CISO within a complex, multi-product software organization.
  • Demonstrable, current expertise in the EU Cyber Resilience Act – requirements, classification logic, and conformity assessment.
  • Working knowledge of NIS2 and GDPR.
  • Strong, practical knowledge of the secure development lifecycle, threat modelling, and application security testing.
  • Hands-on experience with SAST, DAST, SCA, and SonarQube tooling.
  • Experience with SBOM generation and governance.
  • Experience managing supply chain risk.
  • Understanding of AI-assisted and agentic development workflows.
  • Strong communication and stakeholder management skills to enforce standards without direct line authority.
  • CISSP or an equivalent certification is an advantage.

Skills

  • Product Security
  • Application Security
  • EU Cyber Resilience Act
  • NIS2
  • GDPR
  • Secure Development Lifecycle
  • Threat Modelling
  • Application Security Testing
  • SAST
  • DAST
  • SCA
  • SonarQube
  • SBOM Generation
  • Supply Chain Risk Management
  • AI-assisted Development
  • Agentic Development Workflows
  • Communication
  • Stakeholder Management

Location

  • Global

Work Type

  • Mobile work (2 days/week)
  • On site (3 days/week)

Experience Level

  • Several years of experience

Benefits

  • Flexible work arrangements
  • Fully equipped workplaces
  • Regular company events
  • In-house academy for development
  • External training partnerships
  • Healthy food options in canteen
  • Fully equipped fitness center with courses
  • On-campus kindergarten
  • Corporate benefits
  • Job bike option
  • Company pension scheme

About the Company

  • Leading company in software solutions for healthcare.
  • Operates in 19 countries.
  • Employs over 9,000 staff members.
  • Dynamic and innovative environment.
  • Leverages AI in the e-health environment.
  • Shaping the healthcare system of the future.

Equal Opportunity

  • Diversity is part of CGM. Applications are welcome regardless of disability, gender, nationality, ethnic and social background, religion, age, sexual orientation, and identity.