GSB Solutions

CRA Compliance & Product Security Engineer - Remote in Mexico

GSB Solutions Ciudad de México, Mexico · MX$1M/yr

Information Technology & Services · 201-500 employees

7 h ago
Remote security Mid (2-5 yrs) Full-time Mexico
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Assess products and development processes against EU Cyber Resilience Act requirements while identifying compliance gaps. Partner with cross-functional teams to integrate security controls and vulnerability management throughout the product lifecycle.

What they look for

Product Security Cybersecurity Compliance Secure Software Engineering EU Cyber Resilience Act NIS2 Secure SDLC Vulnerability Management Threat Assessment Risk Assessment Security Testing Cryptography Access Control Incident Response Hardware Architecture Software Architecture

Requirements

Requires a bachelor's degree in a relevant field and at least 3 years of experience in product security or compliance. Candidates must possess strong knowledge of secure SDLC, regulatory frameworks, and technical security controls.

Benefits

Excellent superior benefits

Full description

Important IT company At the Latin American level, growth requires:

CRA Compliance & Product Security Engineer 

Position Summary 

We are seeking a CRA Compliance & Product Security Engineer to support the organization in meeting European Cyber Resilience Act (CRA) requirements while strengthening product security throughout the product lifecycle. 

The ideal candidate combines regulatory/compliance knowledge with hands-on product security and software engineering experience, and can translate regulatory requirements into practical security controls, engineering processes, and product requirements. 

Required Experience & Expertise 

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field. 
  • 3+ years of experience in Product Security, Cybersecurity, Compliance, or Secure Software Engineering. 
  • Strong understanding of the EU Cyber Resilience Act (CRA) and its relationship with regulations/frameworks such as NIS2. 
  • Experience with Product Security / Secure SDLC, including security requirements, threat/risk assessment, security testing, and vulnerability management. 
  • Familiarity with hardware and software architectures, cybersecurity risks, and security controls. 
  • Hands-on knowledge of CVE/vulnerability management, vulnerability assessment, remediation tracking, and security incident response. 
  • Understanding of cryptography, secure data erasure, authentication, access control, and secure communications. 
  • Experience translating regulatory and security requirements into technical requirements, engineering processes, and actionable controls. 
  • Strong experience working cross-functionally with Engineering, Product, Software Development, QA, Legal, Compliance, and Security teams. 

Key Responsibilities 

  • Assess products and development processes against CRA requirements and identify compliance gaps. 
  • Translate regulatory requirements into product security requirements and engineering controls. 
  • Support vulnerability management, including CVE identification, risk assessment, remediation, and reporting. 
  • Contribute to Secure SDLC, threat modeling, security testing, and risk assessments. 
  • Support preparation and maintenance of security/compliance documentation and technical evidence. 
  • Partner with Engineering and Product teams to ensure security and compliance requirements are addressed throughout the product lifecycle. 
  • Monitor changes in relevant cybersecurity regulations and standards and assess their impact on products and processes. 

Preferred Qualifications 

  • CISSP, CISM, or equivalent cybersecurity certification. 
  • CRA-specific training/certification, such as CybResActTPro, is highly desirable. 
  • Experience with IoT, connected products, embedded systems, industrial products, or other regulated technology products. 
  • Experience with international cybersecurity standards and frameworks such as ISO 27001, IEC 62443, NIST, or similar. 

 

ADVANCED CONVERSATIONAL ENGLISH AND SPANISH ESSENTIAL (Will be evaluated).

If you are a foreingner residing in Mexico, you must have a valid INE, CURP, NSS and RFC.

Job type: Remote

Location: México.

Salary: $110,000 gross

Benefits: Excellent superior benefits.

Similar roles