Product Security and Regulatory Expert

Posted 19 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Interpret and implement global and regional regulations into actionable technical controls.

• Convert regulatory requirements into technical standards applicable to infrastructure, cloud, network, application, and data environments.

• Collaborate with legal, risk, audit, and security teams to maintain a consistent global compliance posture.

• Design and implement technical controls to fulfill regulatory obligations.

• Conduct control testing, gap assessments, and develop remediation plans.

• Lead internal and external audits, coordinating evidence collection and responses to auditors.

• Automate compliance validation using tools where feasible, including CSPM, SIEM, and GRC platforms.

• Support compliance strategies across various countries and regions.

• Monitor global regulatory changes and evaluate their impact on IT systems.

• Establish repeatable compliance processes for global implementations.

• Collaborate with regional IT leaders to ensure adherence to localized regulations.

• Conduct risk assessments related to regulatory exposure.

• Maintain risk registers and develop remediation roadmaps.

• Assist in policy development and the documentation of technical standards.

• Provide executive-level reports on compliance status and risk management.


⛳️ Requirements

• Over 7 years of experience in product security, IT compliance/regulatory, product, or IT security.

• In-depth knowledge of EU CRA, EU RED, and IEC 62443.

• Strong understanding of cloud environments such as AWS, Azure, and GCP.

• Solid grasp of enterprise networking concepts.

• Comprehensive understanding of identity and access management.

• Proficient knowledge of data protection and encryption technologies.

• Strong familiarity with logging, monitoring, and security tools.

• Experience leading or supporting external audits.

• Ability to convert legal/regulatory terminology into technical specifications.

• Excellent documentation and stakeholder communication skills.

• Preferred: Experience in highly regulated sectors (financial services, healthcare, defense, telecom).

• Preferred: Certifications such as CISA, CRISC, CISSP, or ISO 27001 Lead Implementer / Lead Auditor.

• Preferred: Experience with GRC platforms like ServiceNow GRC, Archer, OneTrust, etc.

• Preferred: Experience managing cross-border data compliance and data residency requirements.


🏝️ Benefits

• Opportunity for professional development and growth.

• Competitive salary and comprehensive benefits package.

• Collaborative and inclusive work environment.

• Flexible work arrangements to support work-life balance.

People also viewed

EverCommerce19 hours ago

Senior Director, Information Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$225k – $275k/year
ApplyView job
NatWest Group19 hours ago

Security Intelligence Specialist

GB flagUnited Kingdom OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Inviso20 hours ago

Security & Identity Engineer

PL flagPoland OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Atlas Governance21 hours ago

Information Security Governance Intern

BR flagBrazil OnlyInternshipCybersecurity / Security Engineer
ApplyView job
Triumph Enterprises, Inc.21 hours ago

Cloud Security Architect / Engineer

US flagDistrict of Columbia, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
Inviso21 hours ago

Security & Identity Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$145k – $190k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers