Jobgether
Product Security & Compliance Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Job Opportunity: Product Security & Compliance Engineer
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Product Security & Compliance Engineer based in the United Kingdom.
About the Role
This role combines hands-on product security engineering with cybersecurity compliance across connected hardware and cloud services.
You will help build secure, resilient products while ensuring they meet evolving regulatory and cybersecurity requirements.
Key Responsibilities:
- Product Security Engineering: You will conduct threat modeling, security validation, vulnerability assessments, and supply-chain risk management while translating findings into practical controls.
- Compliance and Documentation: The role also involves preparing technical evidence and documentation for product conformity and regulatory assessments.
- Collaboration: You’ll collaborate closely with hardware, firmware, cloud, product, external manufacturing, and certification teams in a distributed environment.
It is an opportunity to take meaningful ownership at the intersection of product security, compliance, connected technology, and privacy.
Accountabilities
- Regulatory Compliance: Own cybersecurity aspects of regulatory compliance for connected hardware products, including RED cybersecurity requirements and EN 18031.
- Preparation for EU Cyber Resilience Act: Support preparation for the EU Cyber Resilience Act, covering vulnerability management, security updates, Software Bills of Materials, support periods, and incident reporting.
- Architecture and Diagrams: Create and maintain architecture and data-flow diagrams for connected products and associated services.
- Threat Modeling and Security Requirements: Conduct threat modeling and translate identified risks into actionable security requirements, controls, and engineering priorities.
- Product Security Validation: Perform hands-on product security validation, including vulnerability and dependency scanning, SAST/DAST, software composition analysis, firmware analysis, network and service exposure assessments, and targeted penetration testing.
- SBOM Management: Generate, maintain, and monitor SBOMs to identify and manage vulnerabilities within software dependencies.
- Security Mechanisms Validation: Validate security mechanisms including authentication, secure boot, and signed software or firmware updates.
- Documentation and Evidence: Translate security assessments and testing results into compliance evidence, technical documentation, risk assessments, conformity assessments, and Declarations of Conformity.
- Embedding Security in Development: Partner with hardware, firmware, cloud, and product engineering teams to embed security and compliance requirements early in the development lifecycle.
- Coordination with External Partners: Coordinate with external manufacturing partners and certification bodies while maintaining internal ownership of cybersecurity evidence.
- Open-Source Collaboration: Collaborate with open-source communities and related projects to ensure security information, vulnerability handling, and software documentation are effectively maintained.
- Regulatory Tracking: Track product conformity status, security support periods, regulatory deadlines, and changes that may require reassessment.
- Privacy Guidance: Provide privacy-by-design guidance for significant changes to cloud and software services when required.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Requirements
- Technical Experience: Strong hands-on technical experience in at least one security domain, such as embedded/firmware security, network security, application security, or cloud security.
- Diagrams and Threat Modeling: Experience creating architecture or data-flow diagrams and conducting threat modeling for real-world products or systems.
- Security Testing: Practical experience with security testing and tools, including vulnerability scanning, SAST/DAST, software composition analysis, SBOM tooling, network security testing, firmware analysis, or penetration testing.
- Connected Products Experience: Experience working with connected products, IoT, embedded systems, firmware, or environments combining hardware, software, and cloud services.
- Documentation Skills: Demonstrated ability to translate technical security findings into structured documentation, evidence, risk assessments, and compliance requirements.
- Standards Knowledge: Knowledge of product cybersecurity standards and regulations such as EN 18031, RED cybersecurity requirements, the EU Cyber Resilience Act, ETSI EN 303 645, IEC 62443, or comparable frameworks.
- Independent Work: Ability to independently interpret technical requirements, identify security and compliance gaps, and work with engineering teams to implement appropriate solutions.
- Security Principles: Strong understanding of security principles, vulnerability management, software supply-chain risks, and secure product development practices.
- Communication Skills: Strong written and verbal communication skills, with the ability to explain technical security topics to both engineering and non-technical stakeholders.
- Language Proficiency: Fluent written and spoken English.
- Desirable Skills: Experience with secure boot, signed OTA updates, firmware security, or constrained embedded devices is highly desirable. Familiarity with GDPR, privacy-by-design, ISO/IEC 27001, OWASP ASVS/MASVS, NIST SSDF, or related security and privacy frameworks is advantageous. Relevant certifications such as OSCP, GIAC, CISSP, CIPP/E, or CIPT are a plus.
Benefits
- Compensation: Full-time employment with a competitive compensation package benchmarked around the 75th percentile for the role, seniority, and local market.
- UK Salary: Compensation range of £81,800–£102,700, subject to experience, qualifications, and working hours.
- Paid Time Off: Five weeks (25 days) of paid time off.
- Sick Leave: Fourteen days of paid sick leave where required to supplement local statutory provisions.
- Parental Leave: Six weeks of paid and six weeks of unpaid parental leave during the first year after birth, with additional compensation where local provisions are insufficient.
- Hardware Budget: Budget for work hardware, with equipment eligible to be retained for personal use after three years.
- Smart-Home Budget: Annual smart-home budget to support access to current smart-home technology.
- Internet Contribution: 50% contribution toward the internet connection used for your home workspace.
- Personal Projects: One workday every two weeks dedicated to personal projects.
- Side Projects: Opportunity to maintain relevant Home Assistant-related side projects during work time.
- Remote Work: Fully remote working environment with no fixed schedule and approximately three hours of daily team overlap for collaboration.
- Benefits Alignment: Benefits aligned with the requirements of the employee’s country of residence, alongside a baseline package designed to provide consistent support internationally.
- Work Focus: Opportunity to work on privacy-focused, open-source, connected technology with global reach.
- Work Environment: Collaborative, distributed environment centered on autonomy, ownership, privacy, choice, and sustainability.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
How Jobgether Works
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location