
Product Security and Regulatory Expert
Posted 19 hours ago

Posted 19 hours ago
This is a fully remote position, open to applicants in United States.
• Interpret and implement global and regional regulations into actionable technical controls.
• Convert regulatory requirements into technical standards applicable to infrastructure, cloud, network, application, and data environments.
• Collaborate with legal, risk, audit, and security teams to maintain a consistent global compliance posture.
• Design and implement technical controls to fulfill regulatory obligations.
• Conduct control testing, gap assessments, and develop remediation plans.
• Lead internal and external audits, coordinating evidence collection and responses to auditors.
• Automate compliance validation using tools where feasible, including CSPM, SIEM, and GRC platforms.
• Support compliance strategies across various countries and regions.
• Monitor global regulatory changes and evaluate their impact on IT systems.
• Establish repeatable compliance processes for global implementations.
• Collaborate with regional IT leaders to ensure adherence to localized regulations.
• Conduct risk assessments related to regulatory exposure.
• Maintain risk registers and develop remediation roadmaps.
• Assist in policy development and the documentation of technical standards.
• Provide executive-level reports on compliance status and risk management.
• Over 7 years of experience in product security, IT compliance/regulatory, product, or IT security.
• In-depth knowledge of EU CRA, EU RED, and IEC 62443.
• Strong understanding of cloud environments such as AWS, Azure, and GCP.
• Solid grasp of enterprise networking concepts.
• Comprehensive understanding of identity and access management.
• Proficient knowledge of data protection and encryption technologies.
• Strong familiarity with logging, monitoring, and security tools.
• Experience leading or supporting external audits.
• Ability to convert legal/regulatory terminology into technical specifications.
• Excellent documentation and stakeholder communication skills.
• Preferred: Experience in highly regulated sectors (financial services, healthcare, defense, telecom).
• Preferred: Certifications such as CISA, CRISC, CISSP, or ISO 27001 Lead Implementer / Lead Auditor.
• Preferred: Experience with GRC platforms like ServiceNow GRC, Archer, OneTrust, etc.
• Preferred: Experience managing cross-border data compliance and data residency requirements.
• Opportunity for professional development and growth.
• Competitive salary and comprehensive benefits package.
• Collaborative and inclusive work environment.
• Flexible work arrangements to support work-life balance.
EverCommerce
NatWest Group
Inviso
Atlas Governance
Get handpicked remote jobs straight to your inbox weekly.