Назад
Company hidden
21 час назад

Product Security & Compliance Engineer (IoT)

Формат работы
remote (только Europe)
Тип работы
fulltime
Английский
c1
Страна
Spain/Romania/Portugal +3 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security & Compliance Engineer (IoT): Securing connected hardware, firmware, networking, and cloud services while preparing evidence for RED, EN 18031, and the Cyber Resilience Act with an accent on threat modeling, vulnerability management, and product conformity. Focus on validating secure boot and signed updates, analyzing firmware and dependencies, generating SBOMs, and translating technical findings into compliance documentation.

Location: Fully remote; people can be employed from all over the world. At least 3 hours of workday overlap is expected for team communication.

Company

hirify.global develops Home Assistant Cloud, connected hardware, and open-source smart home initiatives focused on privacy, choice, and sustainability.

What you will do

  • Own cybersecurity compliance for connected hardware, including EU RED requirements and EN 18031.
  • Prepare products and processes for the Cyber Resilience Act, covering vulnerability handling, security updates, SBOMs, support periods, and incident reporting.
  • Create architecture and data-flow diagrams, perform threat modeling, and translate risks into security requirements and controls.
  • Conduct product security validation, including vulnerability scanning, SAST/DAST, dependency analysis, firmware analysis, network assessment, and targeted penetration testing.
  • Validate authentication, secure boot, signed software and firmware updates, and monitor software dependencies for vulnerabilities.
  • Turn security assessments into compliance evidence, technical documentation, conformity assessments, and Declarations of Conformity while coordinating with engineering teams, ODMs, certification bodies, and the Open Home Foundation.

Requirements

  • Strong hands-on experience in embedded/firmware, network, application, or cloud security.
  • Experience with architecture or data-flow diagrams, threat modeling, security testing, and technical risk documentation.
  • Experience with connected products, IoT, embedded systems, firmware, or integrated hardware, software, and cloud services.
  • Knowledge of product cybersecurity standards or regulations such as EN 18031, RED, the Cyber Resilience Act, ETSI EN 303 645, or IEC 62443.
  • Ability to work autonomously across multiple technical domains and communicate effectively with engineering and compliance stakeholders.
  • Fluent written and spoken English is required.

Nice to have

  • Experience with CE/RED conformity, FCC authorization, EN 18031, RED Article 3.3(d), (e), and (f), or Cyber Resilience Act preparation.
  • Firmware security experience with constrained devices, secure boot, and signed OTA updates.
  • Experience integrating security testing into CI/CD or secure software development processes.
  • Familiarity with GDPR, privacy by design, ISO/IEC 27001, OWASP ASVS/MASVS, NIST SSDF, RoHS, REACH, WEEE, GPSR, or FCC requirements.
  • Experience with Home Assistant, open-source projects, or security and privacy certifications such as OSCP, GIAC, CISSP, CIPP/E, or CIPT.

Culture & Benefits

  • Fully remote employment through Remote as a salaried employee in the country of residence.
  • Benefits aligned with local requirements, including at least five weeks of paid time off and additional sick and parental leave provisions.
  • Budget for work hardware, with equipment available for personal use after three years.
  • Annual smart home budget and a 50% contribution toward the home internet connection.
  • One day every two weeks for personal projects, including maintenance of Home Assistant-related side projects.
  • Compensation is targeted at the 75th percentile for the role, seniority, and local market.

Hiring process

  • Application review by the team and hiring manager.
  • HR screening, technical case, team interview, CTO interview, and founder interview.
  • Offer and onboarding.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →