Nabu Casa

Product Security & Compliance Engineer

Nabu Casa
Apply
10 days ago
Remote, EMEA or Bucharest, RomaniaSenior

Responsibilities

  • Own cybersecurity aspects of regulatory compliance for connected hardware, including RED cybersecurity requirements and EN 18031.
  • Prepare products and processes for the Cyber Resilience Act, including vulnerability handling, security updates, SBOMs, support periods, and incident reporting.
  • Create architecture and data-flow diagrams and perform threat modeling for connected products and services.
  • Perform vulnerability and dependency scanning, SAST/DAST, firmware analysis, network and service exposure assessment, and targeted penetration testing.
  • Generate and maintain SBOMs and monitor software dependencies for known vulnerabilities.
  • Validate authentication, secure boot, and signed software or firmware update mechanisms.
  • Translate security assessments into compliance evidence, technical documentation, conformity assessments, and Declarations of Conformity.
  • Work with hardware, firmware, cloud, product, ODM, certification, and open-source teams to implement security and compliance requirements.
  • Track conformity status, security support periods, regulatory deadlines, reassessment needs, and privacy-by-design considerations.

Requirements

  • Strong hands-on technical experience in embedded/firmware security, network security, application security, or cloud security.
  • Experience creating architecture or data-flow diagrams and performing threat modeling for real products or systems.
  • Practical experience with vulnerability scanning, SAST/DAST, software composition analysis, SBOM tooling, network security testing, firmware analysis, or penetration testing.
  • Experience with connected products, IoT, embedded systems, firmware, or systems combining hardware with software and cloud services.
  • Experience translating technical security findings into structured documentation, evidence, risk assessments, or compliance requirements.
  • Knowledge of product cybersecurity standards or regulations such as EN 18031, RED cybersecurity requirements, the Cyber Resilience Act, ETSI EN 303 645, or IEC 62443.
  • Ability to interpret technical requirements independently, identify gaps, and work with engineering teams on solutions.
  • Fluent English and strong written and verbal communication skills.
  • Preferred qualifications include CE/RED conformity or FCC authorization experience, secure boot and signed OTA update experience, security testing in CI/CD or secure development processes, familiarity with ISO/IEC 27001, OWASP ASVS/MASVS, NIST SSDF, GDPR, privacy-by-design, RoHS, REACH, WEEE, GPSR, or FCC, open-source experience, and OSCP, GIAC, CISSP, CIPP/E, or CIPT certifications.

Benefits

  • Fully remote employment through Remote with no fixed schedule and at least three hours of team-workday overlap encouraged.
  • Full-time schedule of 40 hours per week.
  • At least five weeks of paid time off and fourteen days of paid sick leave where required local provisions are unpaid.
  • Six weeks of paid and six weeks of unpaid parental leave, supplemented where local law does not provide equivalent compensation.
  • Work hardware budget, with the option to keep the equipment after three years.
  • Annual smart home budget and a 50% contribution toward the home-workspace internet connection.
  • One day every two weeks for personal projects, including time for maintaining Home Assistant-related side projects.
  • Benefits required by the employee's country of residence.
Contact me