freehire launches on Product Hunt on 26 August.

Follow →

Product Security Technical Consultant

Open 35d posting dated last week

We are seeking a Product Security Technical Consultant to advise industrial product development teams on security requirements, regulatory compliance and AI-driven secure development practices across large, federated product portfolios.

Responsibilities

  • Design and maintain product security requirements frameworks for large federated product portfolios including central control libraries, deviation governance workflows and risk acceptance procedures
  • Translate Cyber Resilience Act essential requirements into actionable engineering specifications covering SBOM governance, secure-by-default configurations and vulnerability handling procedures
  • Perform OT/ICS security level assessments including SL-T vs SL-A gap analysis, zone/conduit modeling and component requirement mapping
  • Lead threat modeling workshops with engineering teams using STRIDE, PASTA or MITRE ATT&CK for ICS
  • Define and implement SDL/SSDLC programs including OWASP ASVS compliance matrices, SAST/DAST/SCA toolchain integration and secure coding standards
  • Support Notified Body engagement and technical documentation preparation for CRA Class I and Class II products
  • Design and execute threat models for industrial products integrating AI/ML or LLM capabilities and apply OWASP LLM Top 10 mitigations
  • Integrate AI security controls into DevSecOps pipelines including model provenance, AI SBOM and MLOps security gates
  • Support conformity obligations for high-risk AI systems including technical documentation, human oversight mechanism design and audit trail architecture
  • Conduct engineering-level regulatory gap assessments across CRA, NIS2, EU AI Act and DORA frameworks and deliver remediation roadmaps
  • Present compliance posture and security architecture findings to senior client stakeholders and facilitate cross-functional alignment workshops
  • Contribute to external publications, white papers and industry forums to support practice capability-building

Requirements

  • 5+ years of experience in product security advisory for industrial product development
  • Knowledge of CRA, IEC 62443 and NIS2 regulatory frameworks
  • Expertise in threat modeling methodologies including STRIDE, PASTA and MITRE ATT&CK for ICS
  • Proficiency in secure SDLC practices including OWASP ASVS compliance matrices and SAST/DAST/SCA toolchain integration
  • Familiarity with AI/ML security including OWASP LLM Top 10 and AI SBOM governance
  • Understanding of EU AI Act conformity obligations for high-risk AI systems
  • Background in DevSecOps pipeline integration including CI/CD compliance checks and MLOps security gates
  • Skills in stakeholder communication and presenting findings to senior client stakeholders such as CISOs and engineering VPs
  • Capability to conduct engineering-level gap assessments and deliver remediation roadmaps across regulatory frameworks

Benefits

We gather like-minded people:

  • Top tech minds driving innovation in AI, cloud and digital platform modernization
  • Supportive team and agile, startup-like culture
  • Hybrid by design mode and opportunity to work remotely within Poland
  • Chance to work abroad for up to 60 days annually
  • Business-driven relocation opportunities

We provide growth opportunities:

  • Career development programs
  • Thought leadership, mentoring, soft skills and well-being programs
  • Certification (Anthropic, Gemini, GCP, Azure, AWS)
  • English classes

We cover it all:

  • Stable pay
  • Participation in the Employee Stock Purchase Plan with a 15% discount
  • Benefits package (health insurance, multisport, shopping vouchers)
  • Referral bonuses up to $2,000
  • Offices featuring entertainment and relaxation zones, table tennis and football, free snacks, coffee and more
  • Corporate, social and well-being events

Please, note:

  • Benefits listed above are available to employees only
  • We are open for working with Contractors. Terms of B2B cooperation agreements are agreed individually
  • We will reach out to selected candidates exclusively

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available