Product Security & Cyber Compliance Consultant

Insight Global
Dennis, MA, United States
about 1 month ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Cyber Security System Configuration Firmware Linux System Administration Linux Security Modules Systems Development Life Cycle Cyber-physical Systems Software Vulnerability Management Cloud Platform System Software Security Backend
+1 more
IoT Security

Job description

Regulatory & Compliance Assessment

*Analyze UK PSTI requirements and determine applicability to the clients products and supporting systems.

*Evaluate the impact of the EU Cyber Resilience Act (CRA) on current and future product offerings.

*Identify regulatory obligations associated with connected devices sold in the UK and European markets.

*Conduct compliance assessments across products, services, and supporting infrastructure.

*Identify compliance gaps and prioritize associated risks.

*Develop recommendations and remediation strategies to achieve regulatory compliance.

Product & Technical Architecture Review

*Assess the clients product architecture and connectivity model.

*Evaluate backend systems, remote support infrastructure, cloud environments, and technical dependencies supporting the product.

*Review cybersecurity controls across product, infrastructure, and support systems.

*Analyze Linux-based environments and system configurations where applicable.

*Identify security weaknesses, compliance deficiencies, and technical risks.

Advisory & Remediation Guidance

*Develop a practical roadmap toward compliance.

*Provide technical recommendations that align with regulatory requirements.

*Educate internal stakeholders on compliance obligations and implementation considerations.

*Advise leadership on business risk, compliance exposure, and prioritization strategies.

*Support decision-making regarding remediation efforts and future compliance planning.

Stakeholder Collaboration

*Work closely with engineering, product, and leadership teams.

*Gather information necessary to understand the clients current environment.

*Present findings, recommendations, and implementation approaches to key stakeholders.

*Support knowledge transfer and ongoing compliance readiness efforts.

Desired Deliverables

The consultant will be expected to provide:

*Regulatory applicability assessment

*Current-state compliance review

*Gap analysis report

*Compliance risk assessment

*Prioritized remediation recommendations

*Compliance roadmap and implementation guidance

Requirements

5+ years of experience in cybersecurity, product security, compliance consulting, systems security, or a related field.

Demonstrated experience with UK PSTI requirements.

Experience supporting organizations with EU Cyber Resilience Act (CRA), ETSI EN 303 645, NIS2, IEC 62443, or similar regulatory frameworks.

Strong Linux administration or Linux security background.

Experience evaluating connected products, IoT devices, embedded systems, or cyber-physical systems.

Deep understanding of cybersecurity risk management and compliance assessments.

Ability to assess technical architectures and translate regulatory requirements into practical recommendations.

Strong communication and consulting skills with the ability to work directly with executive stakeholders. Experience conducting cybersecurity gap assessments and compliance readiness reviews.

Product Security Architect or IoT Security background.

Experience securing connected devices, firmware, embedded systems, and cloud-connected products.

Knowledge of secure product development lifecycle (Secure SDLC).

Experience with vulnerability management, threat modeling, and product security programs.

*

Prior consulting experience supporting companies expanding into international markets.

Experience working in a fractional, advisory, or independent consulting capacity.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:13 min

Exposing application programming interface vulnerabilities in robotic devices

Chris Heilmann +2 · LIVE

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac · World Congress 2021

1:52 min

Structuring and scaling the backend engineering team

Stefan Lingler Stefan Lingler +1 · Coffee With Developers

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

5:59 min

Examining connectivity concerns in modern consumer hardware ecosystems

Chris Heilmann +2 · LIVE

Videos

See all

Related articles

See all