Jobgether
Jobgether

Product Security & Compliance Engineer

engineeringfull-timeSpain
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
Apply for this position
✦ AutoApply Sick of applying? We apply to roles like this for you, up to 20 a month.
Learn more

About the role

Accountabilities

    • Own cybersecurity aspects of regulatory compliance for connected hardware products, including RED cybersecurity requirements and EN 18031.
    • Support preparation for the EU Cyber Resilience Act, covering vulnerability management, security updates, Software Bills of Materials, support periods, and incident reporting.
    • Create and maintain architecture and data-flow diagrams for connected products and associated services.
    • Conduct threat modeling and translate identified risks into actionable security requirements, controls, and engineering priorities.
    • Perform hands-on product security validation, including vulnerability and dependency scanning, SAST/DAST, software composition analysis, firmware analysis, network and service exposure assessments, and targeted penetration testing.
    • Generate, maintain, and monitor SBOMs to identify and manage vulnerabilities within software dependencies.
    • Validate security mechanisms including authentication, secure boot, and signed software or firmware updates.
    • Translate security assessments and testing results into compliance evidence, technical documentation, risk assessments, conformity assessments, and Declarations of Conformity.
    • Partner with hardware, firmware, cloud, and product engineering teams to embed security and compliance requirements early in the development lifecycle.
    • Coordinate with external manufacturing partners and certification bodies while maintaining internal ownership of cybersecurity evidence.
    • Collaborate with open-source communities and related projects to ensure security information, vulnerability handling, and software documentation are effectively maintained.
    • Track product conformity status, security support periods, regulatory deadlines, and changes that may require reassessment.
    • Provide privacy-by-design guidance for significant changes to cloud and software services when required.
    • Requirements

      • Strong hands-on technical experience in at least one security domain, such as embedded/firmware security, network security, application security, or cloud security.
      • Experience creating architecture or data-flow diagrams and conducting threat modeling for real-world products or systems.
      • Practical experience with security testing and tools, including vulnerability scanning, SAST/DAST, software composition analysis, SBOM tooling, network security testing, firmware analysis, or penetration testing.
      • Experience working with connected products, IoT, embedded systems, firmware, or environments combining hardware, software, and cloud services.
      • Demonstrated ability to translate technical security findings into structured documentation, evidence, risk assessments, and compliance requirements.
      • Knowledge of product cybersecurity standards and regulations such as EN 18031, RED cybersecurity requirements, the EU Cyber Resilience Act, ETSI EN 303 645, IEC 62443, or comparable frameworks.
      • Ability to independently interpret technical requirements, identify security and compliance gaps, and work with engineering teams to implement appropriate solutions.
      • Strong understanding of security principles, vulnerability management, software supply-chain risks, and secure product development practices.
      • Comfortable working autonomously across multiple technical domains within a distributed organization.
      • Strong written and verbal communication skills, with the ability to explain technical security topics to both engineering and non-technical stakeholders.
      • Fluent written and spoken English.
      • Experience with secure boot, signed OTA updates, firmware security, or constrained embedded devices is highly desirable.
      • Familiarity with GDPR, privacy-by-design, ISO/IEC 27001, OWASP ASVS/MASVS, NIST SSDF, or related security and privacy frameworks is advantageous.
      • Relevant certifications such as OSCP, GIAC, CISSP, CIPP/E, or CIPT are a plus.
      • Benefits

        • Full-time employment with a competitive compensation package benchmarked around the 75th percentile for the role, seniority, and local market.
        • UK compensation range of £81,800–£102,700, subject to experience, qualifications, and working hours.
        • Five weeks (25 days) of paid time off.
        • Fourteen days of paid sick leave where required to supplement local statutory provisions.
        • Six weeks of paid and six weeks of unpaid parental leave during the first year after birth, with additional compensation where local provisions are insufficient.
        • Budget for work hardware, with equipment eligible to be retained for personal use after three years.
        • Annual smart-home budget to support access to current smart-home technology.
        • 50% contribution toward the internet connection used for your home workspace.
        • One workday every two weeks dedicated to personal projects.
        • Opportunity to maintain relevant Home Assistant-related side projects during work time.
        • Fully remote working environment with no fixed schedule and approximately three hours of daily team overlap for collaboration.
        • Benefits aligned with the requirements of the employee’s country of residence, alongside a baseline package designed to provide consistent support internationally.
        • Opportunity to work on privacy-focused, open-source, connected technology with global reach.
        • Collaborative, distributed environment centered on autonomy, ownership, privacy, choice, and sustainability.
✦ Sick of applying to 40 jobs a month?
I rewrite your resume for ATS by hand first. Once you sign off on it, AutoApply applies to up to 20 roles like this a month, cover letter in your own voice each time. From $14.99/mo, cancel anytime.
Get AutoApply
Apply now
Product Security & Compliance Engineer at Jobgether — Remote