openleverjobgether
Product Security & Compliance Engineer
Jobgether
LocationItaly
EmploymentFull-time
Posted2026-08-26T17:47:39.815000+00:00
Last observed2026-08-26 21:51:40.410433
Job idjobgether-jobgether:lever:ddf2acc7-f484-4871-a01c-f24d46ed60b6
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Product Security & Compliance Engineer based in Italy. This role combines hands-on product security engineering with cybersecurity compliance across connected hardware and cloud services. You will help build secure, resilient products while ensuring they meet evolving regulatory and cybersecurity requirements. Your work will span embedded devices, firmware, networking, software dependencies, and cloud services. You’ll conduct threat modeling, security validation, vulnerability assessments, and supply-chain risk management while translating findings into practical controls. The role also involves preparing technical evidence and documentation for product conformity and regulatory assessments. You’ll collaborate closely with hardware, firmware, cloud, product, external manufacturing, and certification teams in a distributed environment. It is an opportunity to take meaningful ownership at the intersection of product security, compliance, connected technology, and privacy. Own cybersecurity aspects of regulatory compliance for connected hardware products, including RED cybersecurity requirements and EN 18031. Support preparation for the EU Cyber Resilience Act, covering vulnerability management, security updates, Software Bills of Materials, support periods, and incident reporting. Create and maintain architecture and data-flow diagrams for connected products and associated services. Conduct threat modeling and translate identified risks into actionable security requirements, controls, and engineering priorities. Perform hands-on product security validation, including vulnerability and dependency scanning, SAST/DAST, software composition analysis, firmware analysis, network and service exposure assessments, and targeted penetration testing. Generate, maintain, and monitor SBOMs to identify and manage vulnerabilities within software dependencies. Validate security mechanisms including authentication, secure boot, and signed software or firmware updates. Translate security assessments and testing results into compliance evidence, technical documentation, risk assessments, conformity assessments, and Declarations of Conformity. Partner with hardware, firmware, cloud, and product engineering teams to embed security and compliance requirements early in the development lifecycle. Coordinate with external manufacturing partners and certification bodies while maintaining internal ownership of cybersecurity evidence. Collaborate with open-source communities and related projects to ensure security information, vulnerability handling, and software documentation are effectively maintained. Track product conformity status, security support periods, regulatory deadlines, and changes that may require reassessment. Provide privacy-by-design guidance for significant changes to cloud and software services when required. Requirements Strong hands-on technical experience in at least one security domain, such as embedded/firmware security, network security, application security, or cloud security. Experience creating architecture or data-flow diagrams and conducting threat modeling for real-world products or systems. Practical experience with security testing and tools, including vulnerability scanning, SAST/DAST, software composition analysis, SBOM tooling, network security testing, firmware analysis, or penetration testing. Experience working with connected products, IoT, embedded systems, firmware, or environments combining hardware, software, and cloud services. Demonstrated ability to translate technical security findings into structured documentation, evidence, risk assessments, and compliance requirements. Knowledge of product cybersecurity standards and regulations such as EN 18031, RED cybersecurity requirements, the EU Cyber Resilience Act, ETSI EN 303 645, IEC 62443, or comparable frameworks. Ability to independ
This page is generated from the committed OpenOpps static snapshot. Use the source posting or apply link for the employer's current canonical posting state.