Cra Compliance & Product Security Engineer - Remote in Mexico
gsb
📍 Remote🌐 Remote💰 MX$110K–MX$110K/yr🕐 20d ago🔗 himalayas
Job Description
Important IT company At the Latin American level, growth requires:
### CRA Compliance & Product Security Engineer
### Position Summary
We are seeking a **CRA Compliance & Product Security Engineer** to support the organization in meeting **European Cyber Resilience Act (CRA)** requirements while strengthening product security throughout the product lifecycle.
The ideal candidate combines **regulatory/compliance knowledge with hands-on product security and software engineering experience**, and can translate regulatory requirements into practical security controls, engineering processes, and product requirements.
### Required Experience & Expertise
* Bachelor’s degree in **Computer Science, Cybersecurity, Information Systems**, or a related field.
* **3+ years of experience** in Product Security, Cybersecurity, Compliance, or Secure Software Engineering.
* Strong understanding of the **EU Cyber Resilience Act (CRA)** and its relationship with regulations/frameworks such as **NIS2**.
* Experience with **Product Security / Secure SDLC**, including security requirements, threat/risk assessment, security testing, and vulnerability management.
* Familiarity with **hardware and software architectures**, cybersecurity risks, and security controls.
* Hands-on knowledge of **CVE/vulnerability management**, vulnerability assessment, remediation tracking, and security incident response.
* Understanding of **cryptography, secure data erasure, authentication, access control, and secure communications**.
* Experience translating regulatory and security requirements into **technical requirements, engineering processes, and actionable controls**.
* Strong experience working cross-functionally with **Engineering, Product, Software Development, QA, Legal, Compliance, and Security teams**.
### Key Responsibilities
* Assess products and development processes against **CRA requirements** and identify compliance gaps.
* Translate regulatory requirements into **product security requirements and engineering controls**.
* Support vulnerability management, including **CVE identification, risk assessment, remediation, and reporting**.
* Contribute to **Secure SDLC, threat modeling, security testing, and risk assessments**.
* Support preparation and maintenance of security/compliance documentation and technical evidence.
* Partner with Engineering and Product teams to ensure security and compliance requirements are addressed throughout the **product lifecycle**.
* Monitor changes in relevant cybersecurity regulations and standards and assess their impact on products and processes.
### Preferred Qualifications
* **CISSP, CISM**, or equivalent cybersecurity certification.
* CRA-specific training/certification, such as **CybResActTPro**, is highly desirable.
* Experience with **IoT, connected products, embedded systems, industrial products, or other regulated technology products**.
* Experience with international cybersecurity standards and frameworks such as **ISO 27001, IEC 62443, NIST, or similar**.
**ADVANCED CONVERSATIONAL ENGLISH AND SPANISH ESSENTIAL** (Will be evaluated).
**If you are a foreingner residing in Mexico, you must have a valid INE, CURP, NSS and RFC.**
**Job type**: Remote
**Location**: México.
**Salary**: $110,000 gross
**Benefits**: Excellent superior benefits.
Originally posted on [Himalayas](https://himalayas.app)