← Все вакансии/Senior/jobgether
SeniorRemote

Product Security and Regulatory Expert

J
jobgether
Уровень
Senior
Формат
Remote
О роли

Описание вакансии

About the company

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Product Security and Regulatory Expert based in United States.

Responsibilities
  • Interpret and operationalize global and regional product security and technology regulations, translating legal and regulatory requirements into actionable technical controls, standards, and implementation plans.
  • Develop and maintain technical compliance standards covering infrastructure, cloud, networking, applications, identity and access management, data protection, encryption, logging, monitoring, and security tooling.
  • Design, implement, and validate technical controls required to meet regulatory and security obligations, ensuring that controls are practical, measurable, and scalable across technology environments.
  • Conduct control testing, regulatory gap assessments, risk evaluations, and remediation planning, maintaining clear visibility into compliance deficiencies and corrective actions.
  • Lead or support internal and external audits, coordinating evidence collection, responding to auditor requests, tracking findings, and ensuring remediation activities are completed effectively.
  • Automate compliance validation wherever practical by leveraging security and governance technologies such as Cloud Security Posture Management, Security Information and Event Management, and Governance, Risk, and Compliance platforms.
  • Support compliance strategy across multiple countries and regions by monitoring regulatory developments, assessing their potential impact on technology environments, and helping establish appropriate localized controls.
  • Establish repeatable compliance processes for global technology rollouts and collaborate with regional IT leaders to ensure local regulatory and data requirements are appropriately addressed.
  • Perform risk assessments related to regulatory exposure, maintain risk registers and remediation roadmaps, and provide clear visibility into outstanding compliance priorities.
  • Support the development and maintenance of security policies, technical standards, governance documentation, and related compliance frameworks.
  • Provide executive-level reporting on regulatory compliance posture, security risks, remediation progress, and emerging requirements, translating technical and regulatory complexity into clear business insights.
  • Partner across legal, risk, audit, security, product, and technology functions to create a consistent and risk-based approach to global product security and regulatory compliance.
Requirements
  • 7+ years of professional experience in product security, IT security, IT compliance, regulatory compliance, product, or closely related disciplines, with substantial responsibility for security and regulatory programs.
  • Deep expertise in the EU Cyber Resilience Act (EU CRA), EU Radio Equipment Directive (EU RED), and IEC 62443, with the ability to interpret their requirements and translate them into practical technical and organizational controls.
  • Strong understanding of modern cloud environments, including AWS, Azure, and GCP, as well as enterprise networking, identity and access management, data protection, encryption technologies, logging, monitoring, and security tooling.
  • Demonstrated experience leading or supporting external audits, including coordinating evidence, communicating with auditors, addressing findings, and driving remediation activities.
  • Proven ability to translate legal and regulatory language into clear technical requirements, standards, controls, policies, and implementation guidance for engineering and IT teams.
  • Strong documentation and stakeholder communication skills, with the ability to explain complex security, compliance, and regulatory topics to both technical teams and senior business leaders.
  • Experience working within highly regulated industries such as financial services, healthcare, defense, telecommunications, or similarly complex environments is preferred.
  • Professional certifications such as CISA, CRISC, CISSP, or ISO 27001 Lead Implementer/Lead Auditor are preferred.
  • Experience with Governance, Risk, and Compliance platforms such as ServiceNow GRC, Archer, OneTrust, or comparable technologies is valued.
  • Experience managing cross-border data compliance, data residency requirements, and geographically distributed technology environments is preferred.
  • Strong analytical and risk-based decision-making capabilities, with the judgment to assess regulatory exposure and prioritize remediation according to business and security impact.
  • Ability to operate effectively within complex, matrixed, and globally distributed organizations while coordinating stakeholders across multiple functions and regions.
  • Executive-level communication and presentation skills, combined with the ability to influence sta
Стек и навыки

С чем работаем