обновлено 13 часов назад
Cyber Resilience Act (CRA) Compliance Lead (Cybersecurity)
149 100 - 215 925$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cyber Resilience Act (CRA) Compliance Lead (Cybersecurity): Establishing and governing an enterprise-wide EU Cyber Resilience Act compliance framework for semiconductor, firmware, and software products with an accent on regulatory interpretation, product lifecycle governance, and conformity evidence. Focus on building requirements traceability, coordinating vulnerability and SBOM governance, and driving cross-functional compliance programs across engineering, security, quality, and legal teams.
Location: San Jose, California, United States
Salary: $149,100–$215,925 USD annually for the Bay Area California region, with additional incentive opportunities.
Company
is an independent FPGA solutions provider developing programmable technologies for AI, cloud, networking, and edge markets.
What you will do
- Establish and govern the enterprise Cyber Resilience Act compliance framework, including policies, procedures, roles, responsibilities, and decision authorities.
- Translate CRA obligations into product lifecycle processes covering requirements, architecture, design, verification, validation, release, production, maintenance, and end-of-support.
- Build traceability between cybersecurity risks, product requirements, design controls, technical documentation, and conformity evidence.
- Coordinate product classification, conformity-assessment pathways, technical documentation, declarations, and evidence management.
- Govern SBOM, third-party software, open-source components, intellectual property, and external dependency traceability.
- Partner with product security, engineering, legal, quality, and product teams on vulnerability escalation, non-conformity management, audits, training, metrics, and executive reporting.
Requirements
- Bachelor's degree in engineering, computer science, information systems, cybersecurity, quality, or a related technical field.
- 10+ years of experience in product compliance, product cybersecurity, quality systems, regulatory compliance, engineering governance, semiconductor product development, or related disciplines.
- At least 2 years of experience interpreting and applying the EU Cyber Resilience Act and other product security regulations.
- At least 8 years of experience leading cross-functional compliance programs, Secure SDLC processes, product cybersecurity risk management, vulnerability management, SBOM or software component governance, and post-market security compliance.
- At least 8 years of experience managing product lifecycle governance, NPI, requirements and configuration management, engineering change management, release governance, audit readiness, and compliance evidence.
- Applicants must be eligible for any required U.S. export authorizations.
Nice to have
- Experience in FPGA, semiconductor, embedded systems, electronics, automotive, aerospace, defense, industrial, or technology industries.
- Knowledge of IEC 62443, ISO/SAE 21434, ISO/IEC 27001, ISO 9001, AS9100, ISO 26262, IEC 61508, NIST frameworks, Common Criteria, or related assurance frameworks.
- Experience with CE marking, EU product regulations, technical files, declarations of conformity, or market surveillance.
Culture & Benefits
- Regular full-time employment.
- Incentive opportunities based on individual and company performance.
- Work within the Quality & Reliability organization with cross-functional and global geographic collaboration.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
Principal Product Security Engineer (Cybersecurity)
118 000 - 203 550$
28 минут назад
Senior Director Product Security (Cybersecurity)
220 010 - 329 600$
7 дней назад
Cybersecurity Project Manager
135 000 - 145 000$
3 дня назад
Cyber Systems Engineer IV – Vulnerability Management (Cybersecurity)
115 575 - 200 964$
3 дня назад
Cybersecurity Systems Engineer
133 901 - 232 828$
4 дня назад
Associate Principal, Regulatory Compliance (Cybersecurity)
97 300 - 136 600$