About this role
Job title: Head of Product Security
About the Role The Head of Product Security is responsible for establishing, maintaining, and overseeing Logitech's comprehensive security strategy for all products and customer-facing services, including IoT devices, mobile apps, desktop software, and cloud infrastructure. The role leads a global team of security professionals and champions to protect customer data, ensure compliance, and preserve brand trust. Based in Lausanne and reporting to the CISO.
What You'll Do
- Architect and execute a comprehensive product security strategy and roadmap aligned with business growth, reporting on risk posture and program performance to executive leadership.
- Integrate product security resilience as a differentiator, supporting brand trust, enabling new service-based revenue models, and mitigating P&L exposure from legal and product liability risks.
- Develop and implement product security policies, standards, and guidelines.
- Direct global regulatory compliance strategies for mandatory standards such as the EU CRA and UK PSTI, overseeing gap analysis and remediation across cross-functional teams.
- Lead and mentor a high-performing security team while fostering a proactive, collaborative security culture across the global organization.
- Champion Security by Design by integrating secure development lifecycle practices into all IoT, mobile, desktop, and cloud infrastructure products and development teams; establish and enforce Safe AI by Design principles; ensure disclosure and reporting requirements are publicly communicated.
- Enforce robust supply chain and manufacturing security standards for Operations teams, third-party partners, and suppliers; provide expert security advice to engineering and product teams; ensure secure product decommissioning.
- Oversee penetration testing and vulnerability management programs; drive remediation and establish AI-enabled threat hunting capabilities; provide leadership for product-related security incidents.
What We're Looking For
- Minimum 12 years of experience in Product, Application, and Embedded Systems Security with hands-on and leadership roles across IoT, mobile, and cloud.
- Deep mastery of Secure Software Development Lifecycle (SDLC) and DevSecOps; experience scaling global programs, threat modeling, and security architecture reviews.
- Advanced expertise in product security tooling: SAST, DAST, SCA, binary analysis, and fuzzing.
- Embedded and hardware security experience: firmware, embedded systems, HSMs, secure provisioning, and OTA updates for IoT.
- AI/ML security expertise: adversarial AI, data poisoning, model inversion, and prompt injection.
- Cryptography and PQC: PKI and key management frameworks.
Compensation & Benefits
- Not disclosed in the posting.