Product Security & Compliance Engineer
Nabu CasaRemotely
securityiotthreat modelingsastdastsbomvulnerability scanning
Job Description
📋 Description
- Own cybersecurity aspects of regulatory compliance for connected hardware and cloud services (RED
- Prepare products/processes for EU Cyber Resilience Act including SBOMs and incident reporting.
- Create and maintain architecture/data-flow diagrams; conduct threat modeling.
- Perform hands-on security validation: vulnerability scanning, SAST/DAST, firmware analysis
- Maintain SBOMs and monitor dependencies for vulnerabilities.
- Collaborate with hardware, firmware, cloud, and product teams early in development.
🎯 Requirements
- Hands-on security experience in embedded/firmware, network, application, or cloud security.
- Experience creating architecture/diagrams and threat modeling for real systems.
- Practical security testing tooling experience (SBOM tooling, SAST/DAST, vulnerability scanning
- Experience with connected devices/IoT or hardware/software/cloud systems.
- Ability to translate security findings into structured documentation and compliance evidence.
- Knowledge of EN 18031, RED, CRA, ETSI EN 303 645, IEC 62443 or similar standards.
🎁 Benefits
- Fully remote organization with global flexibility; remote work with country-appropriate benefits.
- Full-time, 40 hours/week; flexible scheduling with some overlap for team communication.
- Paid time off, paid sick leave, parental leave, hardware budget, smart home budget, internet
- Compensation packages aligned to local markets; examples across countries provided (UK, Spain
Back to all jobs