10 days ago
Remote, EMEA or Bucharest, RomaniaSenior
Responsibilities
- Own cybersecurity aspects of regulatory compliance for connected hardware, including RED cybersecurity requirements and EN 18031.
- Prepare products and processes for the Cyber Resilience Act, including vulnerability handling, security updates, SBOMs, support periods, and incident reporting.
- Create architecture and data-flow diagrams and perform threat modeling for connected products and services.
- Perform vulnerability and dependency scanning, SAST/DAST, firmware analysis, network and service exposure assessment, and targeted penetration testing.
- Generate and maintain SBOMs and monitor software dependencies for known vulnerabilities.
- Validate authentication, secure boot, and signed software or firmware update mechanisms.
- Translate security assessments into compliance evidence, technical documentation, conformity assessments, and Declarations of Conformity.
- Work with hardware, firmware, cloud, product, ODM, certification, and open-source teams to implement security and compliance requirements.
- Track conformity status, security support periods, regulatory deadlines, reassessment needs, and privacy-by-design considerations.
Requirements
- Strong hands-on technical experience in embedded/firmware security, network security, application security, or cloud security.
- Experience creating architecture or data-flow diagrams and performing threat modeling for real products or systems.
- Practical experience with vulnerability scanning, SAST/DAST, software composition analysis, SBOM tooling, network security testing, firmware analysis, or penetration testing.
- Experience with connected products, IoT, embedded systems, firmware, or systems combining hardware with software and cloud services.
- Experience translating technical security findings into structured documentation, evidence, risk assessments, or compliance requirements.
- Knowledge of product cybersecurity standards or regulations such as EN 18031, RED cybersecurity requirements, the Cyber Resilience Act, ETSI EN 303 645, or IEC 62443.
- Ability to interpret technical requirements independently, identify gaps, and work with engineering teams on solutions.
- Fluent English and strong written and verbal communication skills.
- Preferred qualifications include CE/RED conformity or FCC authorization experience, secure boot and signed OTA update experience, security testing in CI/CD or secure development processes, familiarity with ISO/IEC 27001, OWASP ASVS/MASVS, NIST SSDF, GDPR, privacy-by-design, RoHS, REACH, WEEE, GPSR, or FCC, open-source experience, and OSCP, GIAC, CISSP, CIPP/E, or CIPT certifications.
Benefits
- Fully remote employment through Remote with no fixed schedule and at least three hours of team-workday overlap encouraged.
- Full-time schedule of 40 hours per week.
- At least five weeks of paid time off and fourteen days of paid sick leave where required local provisions are unpaid.
- Six weeks of paid and six weeks of unpaid parental leave, supplemented where local law does not provide equivalent compensation.
- Work hardware budget, with the option to keep the equipment after three years.
- Annual smart home budget and a 50% contribution toward the home-workspace internet connection.
- One day every two weeks for personal projects, including time for maintaining Home Assistant-related side projects.
- Benefits required by the employee's country of residence.
