
11 - 50 employees
Founded 2019
IoT • Home Automation • Privacy
Nabu Casa is the company behind Home Assistant, a smart home control platform that allows users to manage their home devices from anywhere. With a focus on privacy and data encryption, Nabu Casa offers Home Assistant Cloud, enabling remote access and control of home automation systems without storing user data in the cloud. The service is compatible with popular voice assistants like Google Assistant and Amazon Alexa, as well as Nabu Casa's own voice assistant, Assist. By providing these services, Nabu Casa supports the ongoing development of open-source projects like Home Assistant and ESPHome. The company operates without any external investors, prioritizing user needs and data privacy.
🔥 0 minutes ago
🌐 United Kingdom, Hungary, +6 more countries – Remote
💵 £81.8k - £102.7k / year
⏰ Full Time
🟡 Mid-level
🟠 Senior
🚔 Compliance
👻 Ghost score 10%
Improve your chances of getting an interview by checking your resume score before you apply.

11 - 50 employees
Founded 2019
IoT • Home Automation • Privacy
Nabu Casa is the company behind Home Assistant, a smart home control platform that allows users to manage their home devices from anywhere. With a focus on privacy and data encryption, Nabu Casa offers Home Assistant Cloud, enabling remote access and control of home automation systems without storing user data in the cloud. The service is compatible with popular voice assistants like Google Assistant and Amazon Alexa, as well as Nabu Casa's own voice assistant, Assist. By providing these services, Nabu Casa supports the ongoing development of open-source projects like Home Assistant and ESPHome. The company operates without any external investors, prioritizing user needs and data privacy.
• Own cybersecurity aspects of regulatory compliance for connected hardware products, including RED cybersecurity requirements and EN 18031. • Prepare products and processes for the EU Cyber Resilience Act, including vulnerability handling, security updates, SBOMs, support periods, and incident reporting. • Create and maintain architecture and data-flow diagrams. • Perform threat modeling and translate risks into security requirements and controls. • Perform hands-on product security validation, including vulnerability and dependency scanning, SAST/DAST, firmware analysis, network and service exposure assessment, and targeted penetration testing. • Generate and maintain Software Bills of Materials and monitor software dependencies for known vulnerabilities. • Validate authentication, secure boot, and signed software or firmware updates. • Translate security assessments and test results into compliance evidence, technical documentation, conformity assessments, and Declarations of Conformity. • Collaborate with hardware, firmware, cloud, and product teams on security and compliance requirements. • Coordinate with ODMs and external certification bodies while owning cybersecurity evidence internally. • Work with the Open Home Foundation on security information, vulnerability handling, and software documentation. • Track product conformity status, security support periods, regulatory deadlines, and reassessment triggers. • Provide privacy-by-design input for significant cloud-service changes.
• Strong hands-on technical experience in at least one of: embedded/firmware security, network security, application security, or cloud security. • Experience creating architecture or data-flow diagrams and performing threat modeling for real products or systems. • Practical experience with vulnerability scanning, SAST/DAST, software composition analysis, SBOM tooling, network security testing, firmware analysis, or penetration testing. • Experience with connected products, IoT, embedded systems, firmware, or systems combining hardware and software/cloud services. • Experience translating technical security findings into structured documentation, evidence, risk assessments, or compliance requirements. • Knowledge of product cybersecurity standards or regulations such as EN 18031, RED cybersecurity requirements, the Cyber Resilience Act, ETSI EN 303 645, IEC 62443, or comparable frameworks. • Ability to independently interpret technical requirements, identify gaps, and work with engineering teams to implement solutions. • Comfortable working autonomously across multiple technical domains in a distributed organization. • Strong written and verbal communication skills. • Fluent in English, written and spoken. • Familiarity with Home Assistant and the smart home ecosystem is a plus. • Experience with CE/RED conformity or FCC equipment authorization is a plus. • Experience with EN 18031, RED Article 3.3(d), (e), and (f) is a plus. • Experience preparing products or organizations for the EU Cyber Resilience Act is a plus. • Hands-on firmware security experience with constrained or embedded devices is a plus. • Experience with secure boot and signed OTA update mechanisms is a plus. • Experience integrating security testing into CI/CD or secure software development processes is a plus. • Familiarity with ETSI EN 303 645, IEC 62443, ISO/IEC 27001, OWASP ASVS/MASVS, or NIST SSDF is a plus. • Familiarity with GDPR and privacy-by-design principles is a plus. • Broader product-compliance exposure such as RoHS, REACH, WEEE, GPSR, or FCC is a plus. • Experience with open-source projects or communities is a plus. • Relevant certifications such as OSCP, GIAC, CISSP, CIPP/E, or CIPT are a plus.
• Five weeks (twenty-five days) of paid time off. • Fourteen days of paid sick leave if your country/laws treat them as unpaid. • Six weeks of paid and six weeks of unpaid parental leave to be used in the first year after birth. • A budget for your work hardware once you start; after three years, you may keep this equipment for personal use. • An annual smart home budget. • A 50% contribution to your internet connection fee at your home workspace. • One day every two weeks to work on your personal projects. • Work time for maintaining Home Assistant-related side projects. • Benefits required by the country of residence. • Total compensation package targeting the 75th percentile for the role, seniority, and local market rates.
Apply Now🔥 1 hour ago
Regulatory Affairs Consultant strengthening GxP compliance across Parexel’s clinical development and regulatory operations. Managing controlled documents, training governance, inspections, and quality systems.
🇬🇧 United Kingdom – Remote
💰 Venture Round on 1990-01
⏰ Full Time
🟠 Senior
🔴 Lead
🚔 Compliance
🇬🇧 UK Skilled Worker Visa Sponsor
🔥 19 hours ago
Compliance Analyst conducting KYB onboarding, due diligence, and transaction monitoring for Peratera’s global fintech payment platform. Assessing international businesses and escalating financial crime risks.
🕒 Yesterday
Senior Compliance Specialist managing GxP inspections, CAPAs, and regulatory readiness for Thermo Fisher Scientific’s clinical research operations. Mentoring teams across EMEA and supporting global inspection initiatives.
🕒 4 days ago
Compliance and Governance Manager supporting Harris UK’s software and healthcare technology business units. Leading governance frameworks, risk management, internal audits, and regulatory compliance.
🕒 August 18
Training Compliance Officer assuring Capita Fire & Rescue training delivery against Defence and regulatory standards. Conducting audits, reporting risks, and driving continuous improvement across UK training locations.
🇬🇧 United Kingdom – Remote
💵 £37.5k - £39.5k / year
💰 Seed Round on 2018-01
⏰ Full Time
🟡 Mid-level
🟠 Senior
🚔 Compliance
🇬🇧 UK Skilled Worker Visa Sponsor