Haystack
← Back to Jobs
Administrative
EG

Product Security Lead

Eliassen GroupIrvine, CA🇺🇸United StatesPosted Sep 19, 2026

Why This Role Stands Out

This on-site Product Security Lead role offers a fantastic opportunity to build and shape a critical security program, with clear potential for growth into a leadership position with direct reports. You'll thrive here if you are a proactive security professional eager to drive compliance initiatives and establish robust secure development practices within a dynamic environment. This contract-to-hire position, with competitive hourly pay, is an excellent chance to make a significant impact.

Quick Overview

Salary
$70 - $80/hr
Seniority
Mid Senior
Work mode
On Site
Location
Irvine, CA, United States
Posted
14 hours ago
Stakeholder Management

Job Description

Description:
On-site Monday-Thursday in Irvine, CA
Our client seeks a Product Security Lead to build, own, and mature the product security program. The role will partner with an MSP to implement EU Cyber Resilience Act (CRA) compliance, then transition to full program ownership. The scope includes coordinating internal stakeholders, validating MSP deliverables, establishing governance and secure development practices, managing SBOMs and vulnerability processes, and preparing for ISO/SAE 21434 expansion. The position reports to the CISO and is expected to evolve into a player-coach role with 1-2 direct reports as the program scales. Familiarity with semiconductor industry practices is a plus. On-site presence is required Monday through Thursday to support internal customers across engineering, quality, legal, and related functions.
This is a contract to hire opportunity. Applicants must be willing and able to work on a w2 basis and convert to FTE following contract duration. For our w2 consultants, we offer a great benefits package that includes Medical, Dental, and Vision benefits, 401k with company matching, and life insurance.
Rate: $70.00 to $80.00/hr. w2
JN -64
Responsibilities:
  • Serve as primary liaison to the MSP during the EU CRA compliance engagement.
  • Coordinate engineering, product, legal, quality, and supply chain to meet MSP timelines and deliverables.
  • Ensure timely provision of product architecture, SBOMs, and vulnerability handling information for CRA conformity assessments.
  • Review and validate MSP outputs, including risk assessments, technical documentation, and gap analyses.
  • Track CRA milestones, manage risks and blockers, and escalate issues to the CISO as needed.
  • Build internal understanding of CRA obligations and conformity assessment pathways.
  • Assume full ownership of the product security program after MSP transition.
  • Establish governance, policies, and procedures for secure development, vulnerability management, incident response, and supply chain risk.
  • Define and report KPIs and metrics to demonstrate maturity and compliance posture.
  • Manage relationships with regulators, auditors, and external assessors.
  • Maintain technical documentation, SBOMs, and risk assessments as products evolve.
  • Manage coordinated vulnerability disclosure and product security incident response.
  • Build the business case to hire and lead 1-2 direct reports as scope grows.
  • Design and implement a roadmap for ISO/SAE 21434 compliance including CSMS and TARA.
  • Integrate ISO 21434 requirements with CRA activities to avoid duplication.
  • Partner with engineering, hardware, and firmware teams to embed security through the lifecycle.
  • Prepare for ISO 21434 audits and assessments.
  • Champion a security-first culture and advise leadership on evolving standards such as CRA, ISO 21434, and NIS2.
  • Collaborate with Legal and Compliance on regulatory interpretation and reporting.
  • Present program status, risks, and roadmap to leadership and the board with the CISO.

Experience Requirements:
  • 7+ years in product security, application security, or cybersecurity engineering with program ownership experience.
  • Working knowledge of EU CRA requirements or strong ability to ramp on complex regulatory frameworks.
  • Experience managing external vendors or consultants such as MSPs or MSSPs.
  • Strong understanding of SSDLC and SDLC practices.
  • Experience with vulnerability management, SBOM generation and management, and coordinated vulnerability disclosure.
  • Effective stakeholder management and communication across executive, legal, and engineering audiences.
  • Experience maturing a compliance-driven security program into an operational function.
  • Comfort operating as an individual contributor with interest in people leadership.
  • Willingness and ability to work on-site 4 days per week.
  • Preferred: ISO/SAE 21434 experience including CSMS and TARA.
  • Preferred: Semiconductor industry experience across hardware, firmware, and supply chain security.
  • Preferred: Prior small-team leadership experience.
  • Preferred: Certifications such as CISSP, CISM, ISO 21434 practitioner or auditor.
  • Preferred: Familiarity with NIS2, IEC 62443, UNECE WP.29/R155, and conformity assessment processes.
  • Preferred: Regulated hardware or embedded systems industry experience.

Education Requirements:
  • Bachelor's degree in Computer Science, Engineering, Cybersecurity, or equivalent practical experience.

Recruitment Transparency Notice

Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team (, ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process.
Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.
W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.
If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:

When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group.
If you have any indication of fraudulent activity, please contact .
About Eliassen Group:
Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.
Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws.
Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!

Similar jobs