03 Sep
|
Secure Elements India
|
Bangalore Metropolitan Area
03 Sep
Secure Elements India
Bangalore Metropolitan Area
About Us
Secure Elements is an automotive and Software-Defined Vehicle (SDV) cybersecurity engineering company delivering cybersecurity solutions across the complete product lifecycle from concept and design through development, production, deployment and in-life operations.
Our CRISKLE™ Workspace platform enables organisations to manage cybersecurity engineering and regulatory compliance in one environment, including TARA, vulnerability management, SBOM and supply-chain security, cybersecurity requirements, compliance evidence, PSIRT processes and continuous risk monitoring.
Secure Elements also develops embedded cybersecurity solutions including CAN and Automotive Ethernet IDPS, integrated with CRISKLE™ MSOC for real-time vehicle threat detection, security monitoring and incident response.
With operations across the UK and India and engagements with automotive OEMs, Tier-1 suppliers and technology partners internationally, we are building cybersecurity solutions for the next generation of connected and software-defined products.
The Role
We are looking for an EU Cyber Resilience Act (CRA) Cybersecurity Engineer with hands-on experience in cybersecurity of Products with Digital Elements (PDEs) and product compliance activities.
The successful candidate will help Secure Elements and its customers translate EU CRA regulatory requirements into practical engineering controls, processes and auditable evidence that support CRA conformity assessment, EU Declaration of Conformity and CE-marking readiness .
This is an engineering-focused compliance role. You will work directly with software, embedded, cloud, product, PSIRT and cybersecurity teams to ensure cybersecurity requirements are implemented and evidenced throughout the product lifecycle.
Key Responsibilities
EU CRA Compliance & Conformity Assessment
- Perform EU CRA applicability and product classification assessments for Products with Digital Elements.
- Determine whether products fall within default, Important Class I, Important Class II or Critical Product categories and identify the applicable conformity-assessment route.
- Perform gap assessments against the EU CRA Essential Cybersecurity Requirements in Annex I .
- Translate CRA regulatory requirements into actionable product, software and organisational cybersecurity controls.
- Develop CRA compliance plans and maintain requirement-to-evidence traceability.
- Support Module A, Module B+C or Module H conformity-assessment activities , where applicable.
- Coordinate technical evidence and responses for external assessors, notified bodies, customers and regulatory stakeholders.
- Support preparation for the EU Declaration of Conformity and CE marking .
Product Cybersecurity Engineering
- Conduct cybersecurity risk assessments for Products with Digital Elements across planning, architecture, design, development, production, delivery and maintenance.
- Define cybersecurity requirements based on identified threats, vulnerabilities and product risks.
- Review product architectures, embedded software, cloud services, applications, interfaces and communication networks for cybersecurity weaknesses.
- Perform or coordinate threat modelling, attack-surface analysis and vulnerability assessments.
- Support secure-by-design and secure-by-default implementation across product development teams.
- Review authentication, authorisation, cryptography, secure communications, logging, update mechanisms and security configuration controls.
SBOM & Software Supply-Chain Security
- Establish and maintain Software Bill of Materials (SBOM) processes using formats such as CycloneDX and SPDX.
- Identify and track third-party, open-source and commercial software components used within products.
- Correlate SBOM components with CVE, CWE, CVSS and other vulnerability intelligence.
- Assess cybersecurity risks associated with third-party and open-source components.
- Support supplier cybersecurity due diligence and software supply-chain risk management.
- Establish traceability between vulnerabilities, affected components, product risks, remediation actions and released software versions.
Vulnerability Management & PSIRT
- Define and operate CRA-aligned vulnerability handling processes across the product support lifecycle.
- Support vulnerability intake, triage, severity assessment, remediation, disclosure and closure.
- Work with engineering teams to evaluate reported vulnerabilities and coordinate security fixes.
- Support PSIRT processes and vulnerability disclosure programmes.
- Maintain evidence demonstrating that vulnerabilities are identified, documented, remediated and communicated appropriately.
- Support processes for CRA regulatory reporting of actively exploited vulnerabilities and severe security incidents where applicable.
- Define product cybersecurity support-period and security-update processes.
Technical Documentation & Compliance Evidence Prepare and maintain the technical documentation required to demonstrate CRA conformity, including:
- Product description and intended use
- Product architecture and cybersecurity architecture
- Cybersecurity risk assessment
- Threat models and attack-surface analysis
- Security requirements and controls
- Secure development lifecycle evidence
- SBOM and third-party component records
- Vulnerability assessment and remediation evidence
- Security verification and validation results
- Penetration-testing evidence
- Secure update and patch-management processes
- Vulnerability disclosure and PSIRT processes
- Product support-period documentation
- User cybersecurity information and secure configuration guidance
- Traceability between regulatory requirements, engineering controls and verification evidence
Required Experience
- 3–6+ years of experience in product cybersecurity, software security, embedded cybersecurity, product compliance or a related field.
- Practical understanding of Products with Digital Elements including software, embedded systems, connected devices, cybersecurity products or cloud-connected products.
- Demonstrable experience interpreting cybersecurity regulations or standards and converting them into engineering requirements and compliance evidence.
- Experience performing cybersecurity risk assessments, threat modelling and vulnerability assessments.
- Understanding of secure software development lifecycle / Secure SDLC practices.
- Experience with vulnerability management including CVE, CWE and CVSS.
- Working knowledge of SBOM generation and software supply-chain security.
- Experience preparing technical compliance documentation, audit evidence or product certification/conformity-assessment evidence.
- Good understanding of product lifecycle cybersecurity from design through development, release, vulnerability management and end-of-support.
Technical Skills Exposure to some of the following would be beneficial:
- Linux and embedded Linux
- C/C++, Python or scripting
- REST APIs and cloud architectures
- Docker / containerised environments
- Git and CI/CD pipelines
- SAST / DAST / SCA tools
- Vulnerability scanners
- SBOM generation and analysis tools
- CycloneDX / SPDX
- CVE / CWE / CVSS
- Jira / Confluence or equivalent ALM tools
- SIEM / security monitoring platforms
- PKI, TLS and cryptographic controls
What We Are Looking For We are particularly interested in candidates who can bridge the gap between regulation and engineering . You should be comfortable reading regulatory requirements and answering:
“What engineering activity, control, document, test result or lifecycle process demonstrates that this requirement has been satisfied?”
The ideal candidate will be able to work across cybersecurity engineering, product development, vulnerability management and regulatory compliance to build a complete and auditable CRA evidence chain.
Why Join Secure Elements?
You will have the prospect to work directly on emerging European cybersecurity regulation and help build compliance into next-generation automotive and connected products. You will work across:
Cybersecurity Risk → Product Design → SBOM → Vulnerability Management → Embedded Security → Verification → PSIRT → Regulatory Compliance rather than treating compliance as a standalone documentation activity.
This role offers the opportunity to contribute directly to the development of CRISKLE™ Workspace and help create scalable tooling and methodologies for EU CRA compliance, conformity assessment and continuous product cybersecurity.
📌 Cyber Security Compliance Engineer - EU CRA (Bangalore Metropolitan Area)
🏢 Secure Elements India
📍 Bangalore Metropolitan Area