Назад
Company hidden
обновлено 13 часов назад

Cyber Resilience Act (CRA) Compliance Lead (Cybersecurity)

149 100 - 215 925$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior/lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cyber Resilience Act (CRA) Compliance Lead (Cybersecurity): Establishing and governing an enterprise-wide EU Cyber Resilience Act compliance framework for semiconductor, firmware, and software products with an accent on regulatory interpretation, product lifecycle governance, and conformity evidence. Focus on building requirements traceability, coordinating vulnerability and SBOM governance, and driving cross-functional compliance programs across engineering, security, quality, and legal teams.

Location: San Jose, California, United States

Salary: $149,100–$215,925 USD annually for the Bay Area California region, with additional incentive opportunities.

Company

hirify.global is an independent FPGA solutions provider developing programmable technologies for AI, cloud, networking, and edge markets.

What you will do

  • Establish and govern the enterprise Cyber Resilience Act compliance framework, including policies, procedures, roles, responsibilities, and decision authorities.
  • Translate CRA obligations into product lifecycle processes covering requirements, architecture, design, verification, validation, release, production, maintenance, and end-of-support.
  • Build traceability between cybersecurity risks, product requirements, design controls, technical documentation, and conformity evidence.
  • Coordinate product classification, conformity-assessment pathways, technical documentation, declarations, and evidence management.
  • Govern SBOM, third-party software, open-source components, intellectual property, and external dependency traceability.
  • Partner with product security, engineering, legal, quality, and product teams on vulnerability escalation, non-conformity management, audits, training, metrics, and executive reporting.

Requirements

  • Bachelor's degree in engineering, computer science, information systems, cybersecurity, quality, or a related technical field.
  • 10+ years of experience in product compliance, product cybersecurity, quality systems, regulatory compliance, engineering governance, semiconductor product development, or related disciplines.
  • At least 2 years of experience interpreting and applying the EU Cyber Resilience Act and other product security regulations.
  • At least 8 years of experience leading cross-functional compliance programs, Secure SDLC processes, product cybersecurity risk management, vulnerability management, SBOM or software component governance, and post-market security compliance.
  • At least 8 years of experience managing product lifecycle governance, NPI, requirements and configuration management, engineering change management, release governance, audit readiness, and compliance evidence.
  • Applicants must be eligible for any required U.S. export authorizations.

Nice to have

  • Experience in FPGA, semiconductor, embedded systems, electronics, automotive, aerospace, defense, industrial, or technology industries.
  • Knowledge of IEC 62443, ISO/SAE 21434, ISO/IEC 27001, ISO 9001, AS9100, ISO 26262, IEC 61508, NIST frameworks, Common Criteria, or related assurance frameworks.
  • Experience with CE marking, EU product regulations, technical files, declarations of conformity, or market surveillance.

Culture & Benefits

  • Regular full-time employment.
  • Incentive opportunities based on individual and company performance.
  • Work within the Quality & Reliability organization with cross-functional and global geographic collaboration.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →