Product Security & Compliance Engineer
JobgetherRemotely
securityiotthreat modelingfirmwaresastdastsbomvulnerability scanning
Job Description
📋 Description
- Own cybersecurity aspects of regulatory compliance for connected hardware products, including RED
- Support EU Cyber Resilience Act readiness, covering vulnerability management, security updates
- Create and maintain architecture and data-flow diagrams for connected products and services.
- Conduct threat modeling and translate risks into actionable security requirements and engineering
- Perform hands-on product security validation: vulnerability/dependency scanning, SAST/DAST, SBOM
- Generate, maintain, and monitor SBOMs to manage vulnerabilities in software dependencies.
🎯 Requirements
- Strong hands-on technical experience in at least one security domain (embedded/firmware, network
- Experience creating architecture or data-flow diagrams and conducting threat modeling for
- Practical experience with security testing and tools: vulnerability scanning, SAST/DAST, SBOM
- Experience working with connected products, IoT, embedded systems, firmware, or hardware-cloud
- Ability to translate technical security findings into documentation, risk assessments, and
- Knowledge of product cybersecurity standards and regulations such as EN 18031, RED, EU Cyber
🎁 Benefits
- Full-time employment with compensation benchmarked around the 75th percentile for the role and
- UK compensation range of £81,800–£102,700, subject to experience.
- Five weeks of paid time off; fourteen days of paid sick leave as required.
- Parental leave: six weeks paid and six weeks unpaid during the first year after birth.
- Budget for work hardware and a smart-home budget; fully remote with flexible schedule.
- 50% contribution toward home internet used for work.
Back to all jobs