
11 - 50 Mitarbeiter
Gegründet 2019
IoT • Home Automation • Privacy
Nabu Casa ist ein Unternehmen, das sich auf Cloud-Dienste für die Home-Assistant-Plattform konzentriert, gegründet vom Home-Assistant-Gründer. Ihre Dienste ermöglichen es Nutzerinnen und Nutzern, ihre Home-Assistant-Geräte von überall aus über vollständig verschlüsselte Verbindungen zu steuern und so Datenschutz und Sicherheit zu gewährleisten. Nabu Casa bietet Integrationen mit beliebten Sprachassistenten wie Google Assistant und Amazon Alexa und stellt mit Assist auch einen eigenen Sprachassistenten bereit. Das Unternehmen finanziert zudem die Entwicklung von Open-Source-Projekten wie Home Assistant und ESPHome, mit dem Schwerpunkt, die Privatsphäre zu schützen und Daten lokal zu halten. Weitere Dienste umfassen durch neuronale Netze unterstütztes Text-to-Speech. Nabu Casa stellt die Zufriedenheit der Nutzerinnen und Nutzer über die Interessen von Investoren und betreibt eine Cloud, die keine Nutzerdaten speichert – im Einklang mit der Mission, Informationen der Nutzerinnen und Nutzer privat zu halten.
🕒 vor 22 Tagen
🌐 Vereinigtes Königreich, Ungarn, +6 weitere Länder – Remote
💵 £81.800 - £102.700 / Jahr
⏰ Vollzeit
🟡 Mittelstufe
🟠 Senior
🚔 Compliance
👻 Geisterscore 3%
🗣️🇺🇸🇬🇧 Englisch erforderlich
Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

11 - 50 Mitarbeiter
Gegründet 2019
IoT • Home Automation • Privacy
Nabu Casa ist ein Unternehmen, das sich auf Cloud-Dienste für die Home-Assistant-Plattform konzentriert, gegründet vom Home-Assistant-Gründer. Ihre Dienste ermöglichen es Nutzerinnen und Nutzern, ihre Home-Assistant-Geräte von überall aus über vollständig verschlüsselte Verbindungen zu steuern und so Datenschutz und Sicherheit zu gewährleisten. Nabu Casa bietet Integrationen mit beliebten Sprachassistenten wie Google Assistant und Amazon Alexa und stellt mit Assist auch einen eigenen Sprachassistenten bereit. Das Unternehmen finanziert zudem die Entwicklung von Open-Source-Projekten wie Home Assistant und ESPHome, mit dem Schwerpunkt, die Privatsphäre zu schützen und Daten lokal zu halten. Weitere Dienste umfassen durch neuronale Netze unterstütztes Text-to-Speech. Nabu Casa stellt die Zufriedenheit der Nutzerinnen und Nutzer über die Interessen von Investoren und betreibt eine Cloud, die keine Nutzerdaten speichert – im Einklang mit der Mission, Informationen der Nutzerinnen und Nutzer privat zu halten.
• Own cybersecurity aspects of regulatory compliance for connected hardware products, including RED cybersecurity requirements and EN 18031. • Prepare products and processes for the EU Cyber Resilience Act, including vulnerability handling, security updates, SBOMs, support periods, and incident reporting. • Create and maintain architecture and data-flow diagrams. • Perform threat modeling and translate risks into security requirements and controls. • Perform hands-on product security validation, including vulnerability and dependency scanning, SAST/DAST, firmware analysis, network and service exposure assessment, and targeted penetration testing. • Generate and maintain Software Bills of Materials and monitor software dependencies for known vulnerabilities. • Validate authentication, secure boot, and signed software or firmware updates. • Translate security assessments and test results into compliance evidence, technical documentation, conformity assessments, and Declarations of Conformity. • Collaborate with hardware, firmware, cloud, and product teams on security and compliance requirements. • Coordinate with ODMs and external certification bodies while owning cybersecurity evidence internally. • Work with the Open Home Foundation on security information, vulnerability handling, and software documentation. • Track product conformity status, security support periods, regulatory deadlines, and reassessment triggers. • Provide privacy-by-design input for significant cloud-service changes.
• Strong hands-on technical experience in at least one of: embedded/firmware security, network security, application security, or cloud security. • Experience creating architecture or data-flow diagrams and performing threat modeling for real products or systems. • Practical experience with vulnerability scanning, SAST/DAST, software composition analysis, SBOM tooling, network security testing, firmware analysis, or penetration testing. • Experience with connected products, IoT, embedded systems, firmware, or systems combining hardware and software/cloud services. • Experience translating technical security findings into structured documentation, evidence, risk assessments, or compliance requirements. • Knowledge of product cybersecurity standards or regulations such as EN 18031, RED cybersecurity requirements, the Cyber Resilience Act, ETSI EN 303 645, IEC 62443, or comparable frameworks. • Ability to independently interpret technical requirements, identify gaps, and work with engineering teams to implement solutions. • Comfortable working autonomously across multiple technical domains in a distributed organization. • Strong written and verbal communication skills. • Fluent in English, written and spoken. • Familiarity with Home Assistant and the smart home ecosystem is a plus. • Experience with CE/RED conformity or FCC equipment authorization is a plus. • Experience with EN 18031, RED Article 3.3(d), (e), and (f) is a plus. • Experience preparing products or organizations for the EU Cyber Resilience Act is a plus. • Hands-on firmware security experience with constrained or embedded devices is a plus. • Experience with secure boot and signed OTA update mechanisms is a plus. • Experience integrating security testing into CI/CD or secure software development processes is a plus. • Familiarity with ETSI EN 303 645, IEC 62443, ISO/IEC 27001, OWASP ASVS/MASVS, or NIST SSDF is a plus. • Familiarity with GDPR and privacy-by-design principles is a plus. • Broader product-compliance exposure such as RoHS, REACH, WEEE, GPSR, or FCC is a plus. • Experience with open-source projects or communities is a plus. • Relevant certifications such as OSCP, GIAC, CISSP, CIPP/E, or CIPT are a plus.
• Five weeks (twenty-five days) of paid time off. • Fourteen days of paid sick leave if your country/laws treat them as unpaid. • Six weeks of paid and six weeks of unpaid parental leave to be used in the first year after birth. • A budget for your work hardware once you start; after three years, you may keep this equipment for personal use. • An annual smart home budget. • A 50% contribution to your internet connection fee at your home workspace. • One day every two weeks to work on your personal projects. • Work time for maintaining Home Assistant-related side projects. • Benefits required by the country of residence. • Total compensation package targeting the 75th percentile for the role, seniority, and local market rates.
Jetzt Bewerben🕒 vor 22 Tagen
Compliance Analyst conducting KYB onboarding, due diligence, and transaction monitoring for Peratera’s global fintech payment platform. Assessing international businesses and escalating financial crime risks.
🗣️🇺🇸🇬🇧 Englisch erforderlich
🕒 vor 23 Tagen
Senior Compliance Specialist managing GxP inspections, CAPAs, and regulatory readiness for Thermo Fisher Scientific’s clinical research operations. Mentoring teams across EMEA and supporting global inspection initiatives.
🗣️🇺🇸🇬🇧 Englisch erforderlich
🕒 vor 1 Monat
Safeguarding regulatory specialist managing notifications, audits, records, and compliance for Bright Horizons’ UK childcare network. Coordinating cases and advising operational teams.
🗣️🇺🇸🇬🇧 Englisch erforderlich
🕒 vor 1 Monat
Compliance Officer specializing in conveyancing/residential property at an established property firm. Support legal teams ensuring compliance with regulatory requirements and best practices.
🗣️🇺🇸🇬🇧 Englisch erforderlich
🕒 vor 1 Monat
Senior Regulatory Consultant for Yordas guiding clients through global chemical regulations compliance. Leading a team of regulatory experts on multi-client projects within the chemical management field.
🗣️🇺🇸🇬🇧 Englisch erforderlich