Product Security – Compliance Engineer

Posted Aug 26

This is a fully remote position, open to applicants in United Kingdom, +7 more countries.

📋 Description

• Take ownership of cybersecurity responsibilities related to regulatory compliance for connected hardware products, including RED cybersecurity requirements and EN 18031.

• Prepare products and processes in alignment with the EU Cyber Resilience Act, focusing on vulnerability handling, security updates, SBOMs, support periods, and incident reporting.

• Develop and maintain architecture and data-flow diagrams.

• Conduct threat modeling and convert risks into security requirements and controls.

• Execute hands-on product security validation, encompassing vulnerability and dependency scanning, SAST/DAST, firmware analysis, network and service exposure evaluation, and targeted penetration testing.

• Create and manage Software Bills of Materials while overseeing software dependencies for known vulnerabilities.

• Validate authentication processes, secure boot mechanisms, and signed software or firmware updates.

• Transform security assessments and test outcomes into compliance evidence, technical documentation, conformity assessments, and Declarations of Conformity.

• Collaborate with hardware, firmware, cloud, and product teams regarding security and compliance needs.

• Liaise with ODMs and external certification bodies while managing cybersecurity evidence within the organization.

• Partner with the Open Home Foundation on security information, vulnerability management, and software documentation.

• Monitor product conformity status, security support timelines, regulatory deadlines, and reassessment triggers.

• Provide privacy-by-design insights for significant changes to cloud services.


⛳️ Requirements

• Solid hands-on technical experience in at least one of the following areas: embedded/firmware security, network security, application security, or cloud security.

• Proven experience in creating architecture or data-flow diagrams and performing threat modeling for actual products or systems.

• Practical experience with vulnerability scanning, SAST/DAST, software composition analysis, SBOM tools, network security testing, firmware analysis, or penetration testing.

• Background in connected products, IoT, embedded systems, firmware, or systems that integrate hardware and software/cloud services.

• Experience in translating technical security findings into structured documentation, evidence, risk assessments, or compliance requirements.

• Familiarity with product cybersecurity standards or regulations such as EN 18031, RED cybersecurity requirements, the Cyber Resilience Act, ETSI EN 303 645, IEC 62443, or similar frameworks.

• Capability to independently interpret technical requirements, identify deficiencies, and collaborate with engineering teams to implement solutions.

• Comfortable working autonomously across various technical domains within a distributed organization.

• Excellent written and verbal communication abilities.

• Proficiency in English, both written and spoken.

• Knowledge of Home Assistant and the smart home ecosystem is advantageous.

• Experience with CE/RED conformity or FCC equipment authorization is a plus.

• Familiarity with EN 18031, RED Article 3.3(d), (e), and (f) is an added benefit.

• Previous experience preparing products or organizations for the EU Cyber Resilience Act is advantageous.

• Hands-on firmware security experience with constrained or embedded devices is a plus.

• Familiarity with secure boot and signed OTA update mechanisms is beneficial.

• Experience with integrating security testing into CI/CD or secure software development practices is a plus.

• Knowledge of ETSI EN 303 645, IEC 62443, ISO/IEC 27001, OWASP ASVS/MASVS, or NIST SSDF is beneficial.

• Understanding of GDPR and privacy-by-design principles is advantageous.

• Exposure to broader product-compliance requirements such as RoHS, REACH, WEEE, GPSR, or FCC is a plus.

• Involvement in open-source projects or communities is a plus.

• Relevant certifications such as OSCP, GIAC, CISSP, CIPP/E, or CIPT are advantageous.


🏝️ Benefits

• Five weeks (twenty-five days) of paid time off.

• Fourteen days of paid sick leave if your country/laws classify them as unpaid.

• Six weeks of paid and six weeks of unpaid parental leave to be utilized within the first year after childbirth.

• A budget for your work hardware upon starting; after three years, you may retain this equipment for personal use.

• An annual budget for smart home expenses.

• A 50% contribution towards your internet connection fee for your home workspace.

• One day every two weeks dedicated to working on your personal projects.

• Work time allocated for maintaining Home Assistant-related side projects.

• Benefits as mandated by the country of residence.

• A total compensation package aimed at the 75th percentile for the role, seniority, and local market rates.

People also viewed

LabConnect1 day ago

Head of IT Governance, Risk, Compliance

US flagTennessee OnlyFull-timeCompliance
ApplyView job
Ripple Effect1 day ago

Compliance Analyst

US flagMaryland OnlyFull-timeCompliance$85.3k – $98.1k/year
ApplyView job
Binance1 day ago

Team Lead – Compliance Monitoring, Assurance & Testing

AE flagUnited Arab Emirates (UAE) OnlyFull-timeCompliance
ApplyView job
biBerk Business Insurance1 day ago

Claims Compliance Analyst – Workers' Compensation

US flagUnited States OnlyFull-timeCompliance$77k – $96.5k/year
ApplyView job
Doppel1 day ago

Director, Governance, Risk & Compliance

US flagUnited States OnlyFull-timeCompliance
ApplyView job
PingWind Inc. (SDVOSB)1 day ago

Risk and Compliance Analyst

US flagUnited States OnlyFull-timeCompliance
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers