Product Security and Regulatory Expert

Summary

Senior product security and regulatory compliance expert who translates global regulations (EU CRA, EU RED, IEC 62443) into practical technical controls across cloud, networking, IAM, and data environments. Day to day: leading audits, risk assessments, and compliance automation using CSPM, SIEM, and GRC platforms while partnering with legal, risk, and technology teams.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Product Security and Regulatory Expert based in United States.

This is a senior product security and regulatory compliance opportunity focused on translating complex global requirements into practical technical controls.
You will help shape compliance strategies across cloud, infrastructure, networking, identity, application, and data environments.
The role combines product security expertise, regulatory interpretation, risk management, audit leadership, and cross-functional program execution.
You will work closely with legal, risk, audit, security, and regional technology teams to maintain a consistent global compliance posture.
A major focus will be understanding evolving regulations, assessing their impact, and establishing repeatable processes for implementation and validation.
The environment is global and highly collaborative, requiring strong analytical judgment and the ability to balance regulatory rigor with business enablement.
This role is ideal for an experienced security and compliance professional who can connect regulatory expectations with scalable, automated technical solutions.

Accountabilities:

  • Interpret and operationalize global and regional product security and technology regulations, translating legal and regulatory requirements into actionable technical controls, standards, and implementation plans.
  • Develop and maintain technical compliance standards covering infrastructure, cloud, networking, applications, identity and access management, data protection, encryption, logging, monitoring, and security tooling.
  • Design, implement, and validate technical controls required to meet regulatory and security obligations, ensuring that controls are practical, measurable, and scalable across technology environments.
  • Conduct control testing, regulatory gap assessments, risk evaluations, and remediation planning, maintaining clear visibility into compliance deficiencies and corrective actions.
  • Lead or support internal and external audits, coordinating evidence collection, responding to auditor requests, tracking findings, and ensuring remediation activities are completed effectively.
  • Automate compliance validation wherever practical by leveraging security and governance technologies such as Cloud Security Posture Management, Security Information and Event Management, and Governance, Risk, and Compliance platforms.
  • Support compliance strategy across multiple countries and regions by monitoring regulatory developments, assessing their potential impact on technology environments, and helping establish appropriate localized controls.
  • Establish repeatable compliance processes for global technology rollouts and collaborate with regional IT leaders to ensure local regulatory and data requirements are appropriately addressed.
  • Perform risk assessments related to regulatory exposure, maintain risk registers and remediation roadmaps, and provide clear visibility into outstanding compliance priorities.
  • Support the development and maintenance of security policies, technical standards, governance documentation, and related compliance frameworks.
  • Provide executive-level reporting on regulatory compliance posture, security risks, remediation progress, and emerging requirements, translating technical and regulatory complexity into clear business insights.
  • Partner across legal, risk, audit, security, product, and technology functions to create a consistent and risk-based approach to global product security and regulatory compliance.
  • Requirements:

    • 7+ years of professional experience in product security, IT security, IT compliance, regulatory compliance, product, or closely related disciplines, with substantial responsibility for security and regulatory programs.
    • Deep expertise in the EU Cyber Resilience Act (EU CRA), EU Radio Equipment Directive (EU RED), and IEC 62443, with the ability to interpret their requirements and translate them into practical technical and organizational controls.
    • Strong understanding of modern cloud environments, including AWS, Azure, and GCP, as well as enterprise networking, identity and access management, data protection, encryption technologies, logging, monitoring, and security tooling.
    • Demonstrated experience leading or supporting external audits, including coordinating evidence, communicating with auditors, addressing findings, and driving remediation activities.
    • Proven ability to translate legal and regulatory language into clear technical requirements, standards, controls, policies, and implementation guidance for engineering and IT teams.
    • Strong documentation and stakeholder communication skills, with the ability to explain complex security, compliance, and regulatory topics to both technical teams and senior business leaders.
    • Experience working within highly regulated industries such as financial services, healthcare, defense, telecommunications, or similarly complex environments is preferred.
    • Professional certifications such as CISA, CRISC, CISSP, or ISO 27001 Lead Implementer/Lead Auditor are preferred.
    • Experience with Governance, Risk, and Compliance platforms such as ServiceNow GRC, Archer, OneTrust, or comparable technologies is valued.
    • Experience managing cross-border data compliance, data residency requirements, and geographically distributed technology environments is preferred.
    • Strong analytical and risk-based decision-making capabilities, with the judgment to assess regulatory exposure and prioritize remediation according to business and security impact.
    • Ability to operate effectively within complex, matrixed, and globally distributed organizations while coordinating stakeholders across multiple functions and regions.
    • Executive-level communication and presentation skills, combined with the ability to influence stakeholders and build alignment around compliance priorities.
    • Process-oriented mindset with an emphasis on automation, scalability, continuous improvement, and reducing manual compliance effort wherever practical.
    • Ability to balance regulatory rigor with business enablement, applying sound judgment to support secure innovation without creating unnecessary operational friction.
    • Benefits:

      • Opportunity to shape product security and regulatory compliance strategy across global technology environments.
      • High-impact work at the intersection of cybersecurity, regulatory requirements, cloud technology, risk, and product security.
      • Exposure to major global regulatory frameworks including EU CRA, EU RED, and IEC 62443.
      • Opportunity to work cross-functionally with legal, risk, audit, security, product, and technology teams.
      • Professional environment focused on ownership, continuous learning, innovation, and meaningful impact.
      • Opportunity to develop scalable compliance processes and introduce automation across security and governance activities.
      • Exposure to complex global compliance, cross-border data, and data residency challenges.
      • No specific salary or additional formal benefits were provided in the source description.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available