Jobgether
Product Security & Compliance Engineer
engineeringfull-timeSpain
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more
About the role
Accountabilities
- Own cybersecurity aspects of regulatory compliance for connected hardware products, including RED cybersecurity requirements and EN 18031.
- Support preparation for the EU Cyber Resilience Act, covering vulnerability management, security updates, Software Bills of Materials, support periods, and incident reporting.
- Create and maintain architecture and data-flow diagrams for connected products and associated services.
- Conduct threat modeling and translate identified risks into actionable security requirements, controls, and engineering priorities.
- Perform hands-on product security validation, including vulnerability and dependency scanning, SAST/DAST, software composition analysis, firmware analysis, network and service exposure assessments, and targeted penetration testing.
- Generate, maintain, and monitor SBOMs to identify and manage vulnerabilities within software dependencies.
- Validate security mechanisms including authentication, secure boot, and signed software or firmware updates.
- Translate security assessments and testing results into compliance evidence, technical documentation, risk assessments, conformity assessments, and Declarations of Conformity.
- Partner with hardware, firmware, cloud, and product engineering teams to embed security and compliance requirements early in the development lifecycle.
- Coordinate with external manufacturing partners and certification bodies while maintaining internal ownership of cybersecurity evidence.
- Collaborate with open-source communities and related projects to ensure security information, vulnerability handling, and software documentation are effectively maintained.
- Track product conformity status, security support periods, regulatory deadlines, and changes that may require reassessment.
- Provide privacy-by-design guidance for significant changes to cloud and software services when required.
- Strong hands-on technical experience in at least one security domain, such as embedded/firmware security, network security, application security, or cloud security.
- Experience creating architecture or data-flow diagrams and conducting threat modeling for real-world products or systems.
- Practical experience with security testing and tools, including vulnerability scanning, SAST/DAST, software composition analysis, SBOM tooling, network security testing, firmware analysis, or penetration testing.
- Experience working with connected products, IoT, embedded systems, firmware, or environments combining hardware, software, and cloud services.
- Demonstrated ability to translate technical security findings into structured documentation, evidence, risk assessments, and compliance requirements.
- Knowledge of product cybersecurity standards and regulations such as EN 18031, RED cybersecurity requirements, the EU Cyber Resilience Act, ETSI EN 303 645, IEC 62443, or comparable frameworks.
- Ability to independently interpret technical requirements, identify security and compliance gaps, and work with engineering teams to implement appropriate solutions.
- Strong understanding of security principles, vulnerability management, software supply-chain risks, and secure product development practices.
- Comfortable working autonomously across multiple technical domains within a distributed organization.
- Strong written and verbal communication skills, with the ability to explain technical security topics to both engineering and non-technical stakeholders.
- Fluent written and spoken English.
- Experience with secure boot, signed OTA updates, firmware security, or constrained embedded devices is highly desirable.
- Familiarity with GDPR, privacy-by-design, ISO/IEC 27001, OWASP ASVS/MASVS, NIST SSDF, or related security and privacy frameworks is advantageous.
- Relevant certifications such as OSCP, GIAC, CISSP, CIPP/E, or CIPT are a plus.
- Full-time employment with a competitive compensation package benchmarked around the 75th percentile for the role, seniority, and local market.
- UK compensation range of £81,800–£102,700, subject to experience, qualifications, and working hours.
- Five weeks (25 days) of paid time off.
- Fourteen days of paid sick leave where required to supplement local statutory provisions.
- Six weeks of paid and six weeks of unpaid parental leave during the first year after birth, with additional compensation where local provisions are insufficient.
- Budget for work hardware, with equipment eligible to be retained for personal use after three years.
- Annual smart-home budget to support access to current smart-home technology.
- 50% contribution toward the internet connection used for your home workspace.
- One workday every two weeks dedicated to personal projects.
- Opportunity to maintain relevant Home Assistant-related side projects during work time.
- Fully remote working environment with no fixed schedule and approximately three hours of daily team overlap for collaboration.
- Benefits aligned with the requirements of the employee’s country of residence, alongside a baseline package designed to provide consistent support internationally.
- Opportunity to work on privacy-focused, open-source, connected technology with global reach.
- Collaborative, distributed environment centered on autonomy, ownership, privacy, choice, and sustainability.
Requirements
Benefits
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply