Cyber Product Architect
Experis
Hybrid - London | 2-Month Initial Contract | Outside IR35
Day Rate: Competitive | Start Date: August 2026
We're looking for a senior Product Security Architect to join an initial two-month engagement, bringing cyber security architecture and product security expertise to a mix of client and internal work. This is a hands-on, secure-by-design role spanning embedded, connected, cloud and software products, not tied to any single sector or regulatory framework. If you thrive on threat modelling, secure architecture and translating standards into practical controls, this one's for you.
What you'll be doing:
- Designing, reviewing and documenting secure product, system, application, cloud and infrastructure architectures, advising on IAM, authentication, cryptography, key management, network security, logging, monitoring and data protection.
- Leading and supporting threat modelling, attack surface analysis and risk assessments, including TARA to ISO/SAE 21434, from item definition through to attack feasibility rating and risk treatment.
- Defining and embedding security requirements across the secure development lifecycle, covering firmware, embedded systems, cloud services, APIs, CI/CD and software supply-chain security.
- Improving vulnerability intake, triage, remediation and reporting, plus SBOM/dependency visibility and product security incident readiness.
- Communicating complex risks to technical and non-technical stakeholders and producing assurance-grade documentation.
What we need from you:
- Senior product security or security architecture experience across embedded, connected and cloud products.
- Demonstrable experience leading or executing TARAs to ISO/SAE 21434.
- The ability to derive and integrate security requirements into a secure development lifecycle.
- Strong written communication and assurance-grade documentation skills.
- Familiarity with Threat Guard (the client's TARA tooling), or the ability to get up to speed quickly.
- Working knowledge of standards such as ISO/IEC 27001, NIST, OWASP, IEC 62443, ISO/SAE 21434, UNECE R155 & R156, TISAX, Cyber Essentials and the EU Cyber Resilience Act.
Nice to have:
- Delivery experience against the EU Cyber Resilience Act.
- Automotive, off-highway or connected-vehicle domain experience.
- Relevant certifications (e.g. CISSP, or an ISO/SAE 21434 / product security qualification).
If you receive suspicious outreach claiming to be from us, please contact us via the ManpowerGroup website.
Application opens at the source listing. Free for jobseekers.