Назад
Company hidden
13 часов назад

Product Security & Compliance Engineer (IoT)

81 800 - 102 700GBP
Формат работы
remote (только United_kingdom)
Тип работы
fulltime
Английский
c1
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security & Compliance Engineer (IoT): Building secure, resilient connected hardware products and cloud services with an accent on embedded security, regulatory compliance, and vulnerability management. Focus on threat modeling, hands-on security validation, SBOM and supply-chain risk management, and preparing technical evidence for product conformity assessments.

Location: United Kingdom; fully remote with approximately three hours of daily team overlap.

Salary: £81,800–£102,700 per year, depending on experience, qualifications, and working hours.

Company

hirify.global manages the application process on behalf of a partner developing privacy-focused, open-source connected technology with global reach.

What you will do

  • Own cybersecurity aspects of regulatory compliance for connected hardware, including RED cybersecurity requirements, EN 18031, and the EU Cyber Resilience Act.
  • Create architecture and data-flow diagrams, conduct threat modeling, and translate risks into security requirements, controls, and engineering priorities.
  • Perform product security validation, including vulnerability scanning, SAST/DAST, software composition analysis, SBOM analysis, firmware analysis, network assessments, and targeted penetration testing.
  • Validate authentication, secure boot, signed software and firmware updates, and other product security mechanisms.
  • Prepare compliance evidence, technical documentation, risk assessments, conformity assessments, and Declarations of Conformity.
  • Collaborate with hardware, firmware, cloud, product engineering, manufacturing, certification, and open-source teams.

Requirements

  • Hands-on experience in at least one security domain, such as embedded or firmware security, network security, application security, or cloud security.
  • Experience with architecture or data-flow diagrams, threat modeling, security testing, vulnerability management, and software supply-chain risks.
  • Experience with connected products, IoT, embedded systems, firmware, or environments combining hardware, software, and cloud services.
  • Knowledge of product cybersecurity standards and regulations including EN 18031, RED cybersecurity requirements, the EU Cyber Resilience Act, ETSI EN 303 645, or IEC 62443.
  • Ability to convert technical findings into documentation, evidence, risk assessments, compliance requirements, and engineering actions.
  • Fluent written and spoken English, with strong communication skills for technical and non-technical stakeholders.

Nice to have

  • Experience with secure boot, signed OTA updates, firmware security, or constrained embedded devices.
  • Familiarity with GDPR, privacy-by-design, ISO/IEC 27001, OWASP ASVS/MASVS, NIST SSDF, or related frameworks.
  • Certifications such as OSCP, GIAC, CISSP, CIPP/E, or CIPT.

Culture & Benefits

  • Full-time employment with compensation benchmarked around the 75th percentile for the role, seniority, and local market.
  • Twenty-five days of paid time off and fourteen days of paid sick leave where required.
  • Paid and unpaid parental leave, with additional compensation where local provisions are insufficient.
  • Budget for work hardware, a smart-home budget, and 50% contribution toward the home-workspace internet connection.
  • One workday every two weeks for personal projects and the opportunity to maintain relevant Home Assistant side projects during work time.
  • Remote work with no fixed schedule in a distributed environment focused on autonomy, ownership, privacy, choice, and sustainability.

Hiring process

  • hirify.global uses an AI-powered matching process to review applications against the role's core requirements.
  • A shortlist is shared with the hiring company, which manages interviews, assessments, and final decisions.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →