Product Security – Compliance Engineer

🕒 il y a 1 mois

🌐 Royaume-Uni, Hongrie, +6 autres pays – Distant

infoinfo

💵 £81 800 - £102 700 / an

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

🚔 Conformité

👻 Score fantôme 0%

infoinfo

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Nabu Casa

Nabu Casa

11 - 50 employés

Fondée en 2019

IoT • Home Automation • Privacy

Nabu Casa est une entreprise spécialisée dans la fourniture de services cloud pour la plateforme Home Assistant, créée par le fondateur de Home Assistant. Ses services permettent aux utilisateurs de piloter leurs appareils Home Assistant depuis n’importe où via des connexions entièrement chiffrées, garantissant confidentialité et sécurité. Nabu Casa s’intègre aux assistants vocaux populaires tels que Google Assistant et Amazon Alexa, et propose son propre assistant vocal, Assist. L’entreprise finance également le développement de projets open source comme Home Assistant et ESPHome, avec un accent fort sur la confidentialité des utilisateurs et la conservation des données en local. Parmi les services complémentaires figurent la synthèse vocale (text-to-speech) basée sur des réseaux de neurones. Nabu Casa privilégie la satisfaction des utilisateurs plutôt que celle des investisseurs, en opérant un cloud qui ne stocke pas les données des utilisateurs, en accord avec sa mission de préserver la confidentialité des informations.

Description

• Own cybersecurity aspects of regulatory compliance for connected hardware products, including RED cybersecurity requirements and EN 18031. • Prepare products and processes for the EU Cyber Resilience Act, including vulnerability handling, security updates, SBOMs, support periods, and incident reporting. • Create and maintain architecture and data-flow diagrams. • Perform threat modeling and translate risks into security requirements and controls. • Perform hands-on product security validation, including vulnerability and dependency scanning, SAST/DAST, firmware analysis, network and service exposure assessment, and targeted penetration testing. • Generate and maintain Software Bills of Materials and monitor software dependencies for known vulnerabilities. • Validate authentication, secure boot, and signed software or firmware updates. • Translate security assessments and test results into compliance evidence, technical documentation, conformity assessments, and Declarations of Conformity. • Collaborate with hardware, firmware, cloud, and product teams on security and compliance requirements. • Coordinate with ODMs and external certification bodies while owning cybersecurity evidence internally. • Work with the Open Home Foundation on security information, vulnerability handling, and software documentation. • Track product conformity status, security support periods, regulatory deadlines, and reassessment triggers. • Provide privacy-by-design input for significant cloud-service changes.

🎯 Exigences

• Strong hands-on technical experience in at least one of: embedded/firmware security, network security, application security, or cloud security. • Experience creating architecture or data-flow diagrams and performing threat modeling for real products or systems. • Practical experience with vulnerability scanning, SAST/DAST, software composition analysis, SBOM tooling, network security testing, firmware analysis, or penetration testing. • Experience with connected products, IoT, embedded systems, firmware, or systems combining hardware and software/cloud services. • Experience translating technical security findings into structured documentation, evidence, risk assessments, or compliance requirements. • Knowledge of product cybersecurity standards or regulations such as EN 18031, RED cybersecurity requirements, the Cyber Resilience Act, ETSI EN 303 645, IEC 62443, or comparable frameworks. • Ability to independently interpret technical requirements, identify gaps, and work with engineering teams to implement solutions. • Comfortable working autonomously across multiple technical domains in a distributed organization. • Strong written and verbal communication skills. • Fluent in English, written and spoken. • Familiarity with Home Assistant and the smart home ecosystem is a plus. • Experience with CE/RED conformity or FCC equipment authorization is a plus. • Experience with EN 18031, RED Article 3.3(d), (e), and (f) is a plus. • Experience preparing products or organizations for the EU Cyber Resilience Act is a plus. • Hands-on firmware security experience with constrained or embedded devices is a plus. • Experience with secure boot and signed OTA update mechanisms is a plus. • Experience integrating security testing into CI/CD or secure software development processes is a plus. • Familiarity with ETSI EN 303 645, IEC 62443, ISO/IEC 27001, OWASP ASVS/MASVS, or NIST SSDF is a plus. • Familiarity with GDPR and privacy-by-design principles is a plus. • Broader product-compliance exposure such as RoHS, REACH, WEEE, GPSR, or FCC is a plus. • Experience with open-source projects or communities is a plus. • Relevant certifications such as OSCP, GIAC, CISSP, CIPP/E, or CIPT are a plus.

🏖️ Avantages

• Five weeks (twenty-five days) of paid time off. • Fourteen days of paid sick leave if your country/laws treat them as unpaid. • Six weeks of paid and six weeks of unpaid parental leave to be used in the first year after birth. • A budget for your work hardware once you start; after three years, you may keep this equipment for personal use. • An annual smart home budget. • A 50% contribution to your internet connection fee at your home workspace. • One day every two weeks to work on your personal projects. • Work time for maintaining Home Assistant-related side projects. • Benefits required by the country of residence. • Total compensation package targeting the 75th percentile for the role, seniority, and local market rates.

Postuler Maintenant

Emplois Similaires

🕒 il y a 1 mois

Peratera

11 - 50

💳 Fintech

🤝 B2B

🔌 API

Compliance Analyst conducting KYB onboarding, due diligence, and transaction monitoring for Peratera’s global fintech payment platform. Assessing international businesses and escalating financial crime risks.

🇬🇧 Royaume-Uni – Télétravail

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

🚔 Conformité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Harris Computer

10 000+ employés

🏥 Santé

💼 Conseil

📦 Logistique

Compliance and Governance Manager supporting governance, risk, privacy, security, and regulatory compliance across Harris UK’s software and healthcare technology businesses. Conducting audits and improving management systems.

🇬🇧 Royaume-Uni – Télétravail

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

🚔 Conformité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 2 mois

ICON plc

10 000+ employés

💼 Conseil

🏥 Santé

📦 Logistique

Senior Global Regulatory Scientist shaping global regulatory strategies and clinical submissions at ICON, a healthcare intelligence and clinical research organisation. Mentoring regulatory teams across European locations.

🇬🇧 Royaume-Uni – Télétravail

⏰ Temps Plein

🟠 Senior

🚔 Conformité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 2 mois

Mallory Pryce Recruitment

1 - 10

💼 Conseil

⚖️ Juridique

🎯 Recrutement

Compliance Officer specializing in conveyancing/residential property at an established property firm. Support legal teams ensuring compliance with regulatory requirements and best practices.

🇬🇧 Royaume-Uni – Télétravail

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

🚔 Conformité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 2 mois

Yordas Group

51 - 200

💼 Conseil

🔬 Science

📋 Conformité

Senior Regulatory Consultant for Yordas guiding clients through global chemical regulations compliance. Leading a team of regulatory experts on multi-client projects within the chemical management field.

🇬🇧 Royaume-Uni – Télétravail

⏰ Temps Plein

🟠 Senior

🚔 Conformité

🗣️🇺🇸🇬🇧 Anglais requis