Haystack
← Back to Jobs
Remote
Administrative
GD

GRC Product Security and Regulatory Advisor

GDHUnited States🇺🇸United StatesPosted Sep 30, 2026

Quick Overview

Salary
$53 - $55/hr
Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
20 hours ago

Job Description

Role Summary

This Product Security & Regulatory Compliance role supports product-level security certification and regulatory readiness across a broad portfolio of networking, infrastructure, hardware, software, and endpoint products. The position leads security certification and compliance initiatives, translating complex regulatory requirements into actionable engineering and product security controls. This role requires hands-on product compliance experience and close collaboration with engineering, product security, legal, risk, and external certification organizations.

Responsibilities

  • Lead product-level security certification assessments, regulatory reviews, conformity evaluations, and external certification activities.
  • Interpret and translate complex legal and regulatory requirements into actionable engineering, product security, and development requirements.
  • Serve as a subject matter expert for product security regulations and standards, including EU CRA, EU RED, IEC 62443, and related requirements.
  • Design, implement, and validate technical controls to support applicable product security and regulatory requirements.
  • Partner directly with engineering and product security teams to integrate security and certification requirements throughout the product development lifecycle.
  • Conduct control testing, gap assessments, risk assessments, and remediation planning to address identified compliance requirements.
  • Coordinate evidence collection, certification documentation, and responses for external assessors, auditors, certification organizations, and regulatory reviews.
  • Develop and support compliance strategies across multiple countries and regions, including applicable data residency and cross-border data requirements.
  • Monitor regulatory changes and evaluate their potential impact on products, technical controls, and compliance processes.
  • Develop repeatable processes and standards to support consistent regulatory compliance across global product portfolios.
  • Support automation of compliance validation and control testing using tools such as CSPM, SIEM, and GRC platforms.
  • Maintain risk registers, remediation roadmaps, policies, technical standards, and other required compliance documentation.
  • Provide reporting to stakeholders and leadership regarding compliance status, regulatory risk, remediation activities, and certification readiness.

Required Qualifications

  • Minimum of 7 years of relevant experience in product security, product compliance, regulatory certification, or secure product development involving commercial hardware, software, networking, infrastructure, or endpoint products.
  • Demonstrated experience leading product-level regulatory and certification programs involving commercial technology products.
  • Strong expertise in EU CRA, EU RED, IEC 62443, and related product security regulations and standards.
  • Demonstrated experience leading product security certification assessments, regulatory reviews, conformity evaluations, or external certification activities.
  • Experience working with certification organizations, independent assessors, auditors, laboratories, or regulatory organizations.
  • Demonstrated ability to translate regulatory and legal requirements into actionable engineering, technical, and product security requirements.
  • Experience working directly with engineering and product security teams to implement product security controls and certification requirements.
  • Strong understanding of cloud environments such as AWS, Azure, and GCP, as well as enterprise networking, identity and access management, data protection and encryption, and security monitoring technologies.
  • Strong documentation, project management, and stakeholder communication skills.
  • Ability to work effectively across technical, business, legal, risk, and compliance teams within a complex organization.

Preferred Qualifications

  • Experience supporting security and compliance initiatives for networking, infrastructure, server, endpoint, telecommunications, or related technology products.
  • Experience managing large-scale product portfolios or global product certification programs.
  • Experience supporting compliance requirements across multiple countries and regions, including cross-border data and data residency considerations.
  • Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, or comparable technologies.
  • Experience within highly regulated industries such as financial services, healthcare, defense, or telecommunications.
  • Relevant professional certifications such as CISA, CRISC, CISSP, or ISO 27001 Lead Implementer/Lead Auditor are preferred.
  • Strong analytical and risk-based decision-making skills.
  • Ability to manage multiple priorities and operate effectively within complex, cross-functional environments.
  • Strong written and verbal communication skills, including the ability to communicate technical and regulatory concepts to leadership and diverse stakeholder groups.

Publishing Pay Range: $52.75 - $55.23 Hourly

This is a fully remote role and can be performed from an approved location.

Similar jobs