
CRA Compliance & Product Security Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Mexico.
• Evaluate products and development processes for adherence to CRA requirements and pinpoint compliance deficiencies.
• Convert regulatory mandates into product security specifications and engineering safeguards.
• Assist in vulnerability management, encompassing CVE identification, risk evaluation, remediation, and reporting.
• Contribute to the Secure SDLC, including threat modeling, security testing, and risk assessments.
• Aid in the development and upkeep of security/compliance documentation and technical proof.
• Collaborate with Engineering and Product teams to ensure that security and compliance needs are met throughout the product lifecycle.
• Stay updated on changes in pertinent cybersecurity regulations and standards, evaluating their effects on products and processes.
• Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a similar discipline.
• Over 3 years of experience in Product Security, Cybersecurity, Compliance, or Secure Software Engineering.
• In-depth knowledge of the EU Cyber Resilience Act (CRA) and its connection to regulations/frameworks such as NIS2.
• Proficiency in Product Security / Secure SDLC, including security requirements, threat/risk assessments, security testing, and vulnerability management.
• Understanding of hardware and software architectures, cybersecurity threats, and security measures.
• Practical experience with CVE/vulnerability management, vulnerability assessments, remediation tracking, and security incident response.
• Knowledge of cryptography, secure data deletion, authentication, access control, and secure communications.
• Experience in translating regulatory and security requirements into technical specifications, engineering processes, and actionable controls.
• Strong background in cross-functional collaboration with Engineering, Product, Software Development, QA, Legal, Compliance, and Security teams.
• Preferred: CISSP, CISM, or equivalent cybersecurity certification.
• Highly desirable: CRA-specific training/certification, such as CybResActTPro.
• Preferred: Experience with IoT, connected products, embedded systems, industrial products, or other regulated technology products.
• Preferred: Familiarity with international cybersecurity standards and frameworks such as ISO 27001, IEC 62443, NIST, or similar.
• Essential: Advanced conversational proficiency in English and Spanish (will be assessed).
• Foreign candidates residing in Mexico must possess a valid INE, CURP, NSS, and RFC.
• Must reside in Mexico and hold a valid visa for employment in Mexico.
• Excellent superior benefits.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.