368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$111k – $139k per year
Location
Remote (Switzerland)
Employment
Full-Time
Overview
Company
Impact
Profile match
Jobgether is an AI-powered job platform focused on remote and flexible work. It matches candidates with relevant roles using skills and preference-based algorithms, and also offers career coaching and job-search guidance.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Product Security & Compliance Engineer based in Switzerland.

This role combines hands-on product security engineering with cybersecurity compliance across connected hardware and cloud services.

You will help build secure, resilient products while ensuring they meet evolving regulatory and cybersecurity requirements.

Your work will span embedded devices, firmware, networking, software dependencies, and cloud services.

You’ll conduct threat modeling, security validation, vulnerability assessments, and supply-chain risk management while translating findings into practical controls.

The role also involves preparing technical evidence and documentation for product conformity and regulatory assessments.

You’ll collaborate closely with hardware, firmware, cloud, product, external manufacturing, and certification teams in a distributed environment.

It is an opportunity to take meaningful ownership at the intersection of product security, compliance, connected technology, and privacy.

Accountabilities

    • Own cybersecurity aspects of regulatory compliance for connected hardware products, including RED cybersecurity requirements and EN 18031.
    • Support preparation for the EU Cyber Resilience Act, covering vulnerability management, security updates, Software Bills of Materials, support periods, and incident reporting.
    • Create and maintain architecture and data-flow diagrams for connected products and associated services.
    • Conduct threat modeling and translate identified risks into actionable security requirements, controls, and engineering priorities.
    • Perform hands-on product security validation, including vulnerability and dependency scanning, SAST/DAST, software composition analysis, firmware analysis, network and service exposure assessments, and targeted penetration testing.
    • Generate, maintain, and monitor SBOMs to identify and manage vulnerabilities within software dependencies.
    • Validate security mechanisms including authentication, secure boot, and signed software or firmware updates.
    • Translate security assessments and testing results into compliance evidence, technical documentation, risk assessments, conformity assessments, and Declarations of Conformity.
    • Partner with hardware, firmware, cloud, and product engineering teams to embed security and compliance requirements early in the development lifecycle.
    • Coordinate with external manufacturing partners and certification bodies while maintaining internal ownership of cybersecurity evidence.
    • Collaborate with open-source communities and related projects to ensure security information, vulnerability handling, and software documentation are effectively maintained.
    • Track product conformity status, security support periods, regulatory deadlines, and changes that may require reassessment.
    • Provide privacy-by-design guidance for significant changes to cloud and software services when required.
    • Requirements

      • Strong hands-on technical experience in at least one security domain, such as embedded/firmware security, network security, application security, or cloud security.
      • Experience creating architecture or data-flow diagrams and conducting threat modeling for real-world products or systems.
      • Practical experience with security testing and tools, including vulnerability scanning, SAST/DAST, software composition analysis, SBOM tooling, network security testing, firmware analysis, or penetration testing.
      • Experience working with connected products, IoT, embedded systems, firmware, or environments combining hardware, software, and cloud services.
      • Demonstrated ability to translate technical security findings into structured documentation, evidence, risk assessments, and compliance requirements.
      • Knowledge of product cybersecurity standards and regulations such as EN 18031, RED cybersecurity requirements, the EU Cyber Resilience Act, ETSI EN 303 645, IEC 62443, or comparable frameworks.
      • Ability to independently interpret technical requirements, identify security and compliance gaps, and work with engineering teams to implement appropriate solutions.
      • Strong understanding of security principles, vulnerability management, software supply-chain risks, and secure product development practices.
      • Comfortable working autonomously across multiple technical domains within a distributed organization.
      • Strong written and verbal communication skills, with the ability to explain technical security topics to both engineering and non-technical stakeholders.
      • Fluent written and spoken English.
      • Experience with secure boot, signed OTA updates, firmware security, or constrained embedded devices is highly desirable.
      • Familiarity with GDPR, privacy-by-design, ISO/IEC 27001, OWASP ASVS/MASVS, NIST SSDF, or related security and privacy frameworks is advantageous.
      • Relevant certifications such as OSCP, GIAC, CISSP, CIPP/E, or CIPT are a plus.
      • Benefits

        • Full-time employment with a competitive compensation package benchmarked around the 75th percentile for the role, seniority, and local market.
        • UK compensation range of £81,800-£102,700, subject to experience, qualifications, and working hours.
        • Five weeks (25 days) of paid time off.
        • Fourteen days of paid sick leave where required to supplement local statutory provisions.
        • Six weeks of paid and six weeks of unpaid parental leave during the first year after birth, with additional compensation where local provisions are insufficient.
        • Budget for work hardware, with equipment eligible to be retained for personal use after three years.
        • Annual smart-home budget to support access to current smart-home technology.
        • 50% contribution toward the internet connection used for your home workspace.
        • One workday every two weeks dedicated to personal projects.
        • Opportunity to maintain relevant Home Assistant-related side projects during work time.
        • Fully remote working environment with no fixed schedule and approximately three hours of daily team overlap for collaboration.
        • Benefits aligned with the requirements of the employee’s country of residence, alongside a baseline package designed to provide consistent support internationally.
        • Opportunity to work on privacy-focused, open-source, connected technology with global reach.
        • Collaborative, distributed environment centered on autonomy, ownership, privacy, choice, and sustainability.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$20k – $44k per year (Estimated) • Remote • Full-Time • 5+ years exp • Minsk
Bash
PowerShell
Python
DevOps
AWS
Azure
Azure DevOps
Bicep
CI/CD
CloudFormation
Datadog
Docker
GCP
GitHub
GitHub Actions
GitLab
GitLab CI
IAM
Jenkins
Kubernetes
Splunk
Terraform
Cybersecurity
Aqua Security
CIS Benchmarks
CWE
Falco
HIPAA
ISO 27001
Kubescape
Kyverno
Least Privilege
Microsoft Sentinel
MITRE ATT&CK
OPA Gatekeeper
OWASP Top 10
PCI DSS
Prisma Cloud
SBOM
SOC 2
Threat Modeling
Trivy
Zero Trust
Open Policy Agent
Apply
$145k – $193k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • Chicago • Washington • Denver • Jersey City • Boston
Python
AI/ML
AI Agents
Anomaly Detection
Embeddings
Fine-tuning
Function Calling
Hugging Face
LangChain
LLM
LLM Evaluation
LLM Guardrails
PyTorch
RAG
Red Teaming
Scikit-learn
Vertex AI
DevOps
Azure
GCP
Cybersecurity
Threat Modeling
Apply
$191k – $297k per year • In office • Full-Time • 12+ years exp • Bachelor's Degree • Seattle
AI/ML
AI Agents
DevOps
AWS
Azure
CI/CD
GCP
IAM
Platform Engineering
Cybersecurity
Least Privilege
Microsoft Entra ID
PCI DSS
Threat Modeling
Zero Trust
Apply
$16k – $40k per year (Estimated) • Remote • Full-Time • 2+ years exp • Moscow
Python
Databases
Chroma
ElasticSearch
Milvus
OpenSearch
pgvector
Qdrant
Weaviate
PostgreSQL
AI/ML
AI Agents
Anthropic
AWS Bedrock
Embeddings
Function Calling
Human-in-the-Loop
LLM
LLM Guardrails
NIST AI RMF
OpenAI
RAG
Red Teaming
Vertex AI
DevOps
AWS
Azure
Kubernetes
Cybersecurity
OWASP Top 10
Threat Modeling
Apply
$148k – $267k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 5+ years exp • Sunnyvale • Boston • Austin • Toronto • New York
AI/ML
AI Agents
Claude
Claude Code
Lovable
Replit
Cybersecurity
BeyondTrust
Crowdstrike
CyberArk
Delinea
Microsoft Entra ID
Okta
PCI DSS
SOC 2
Threat Modeling
Apply
$152k – $229k per year • Remote • Full-Time
AI/ML
Human-in-the-Loop
Apply
$162k – $180k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Python
SQL
Databases
Snowflake
AI/ML
dbt
DevOps
AWS
Cybersecurity
HIPAA
Zero Trust
Analytics
ETL/ELT
Apply
$14k – $32k per year (Estimated) • Remote • Full-Time • 2+ years exp • Bachelor's Degree
DevOps
Incident Management
Management
ServiceNow
Apply
$29k – $60k per year (Estimated) • Remote • Full-Time • 8+ years exp
DevOps
Azure
Azure DevOps
Apply
$26k – $69k per year (Estimated) • Remote • Full-Time • 12+ years exp • Bachelor's Degree
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.