Location: India (Remote / Hybrid — willing to overlap with CET business hours)
Experience: 4–5 years in cybersecurity compliance, product/application security, or GRC
Function: Cyber Resilience Act (CRA) Compliance / Product Security
Reports to: Head of Security / CISO / GRC Lead
Employment type: Contractor
About the role:
We are looking for a hands-on CRA Implementor, based in India, to lead our organisation's compliance programme for the EU Cyber Resilience Act — Regulation (EU) 2024/2847 ("CRA"),
This role will implement CRA compliance end-to-end: interpreting the essential requirements in Annexes I and II, embedding secure-development and vulnerability-handling processes across engineering teams, running and coordinating VAPT and application security testing, securing the software supply chain (including SBOM generation and management), and owning regulatory reporting to ENISA and national CSIRTs within the Act's mandated timelines. You will work closely with engineering, product, legal, and security teams distributed across India and the EU.
Key Responsibilities
1. CRA Programme Implementation & Governance
• Translate CRA Articles and Annex I essential requirements (cybersecurity-by-design/by-default, secure defaults, vulnerability handling) into internal policies, standards, and controls.
- Classify company products against CRA product categories (default, important — Class I/II, critical) to determine applicable conformity assessment routes.
- Build and maintain a CRA compliance register, gap-assessment matrix, and remediation roadmap; track progress toward the 11 September 2026 reporting-obligation deadline and the 11 December 2027 full-application deadline.
- Prepare technical documentation required under Annex VII (risk assessment, design/development documentation, evidence of conformity) and support CE marking and Declaration of Conformity processes.
- Coordinate with Notified Bodies where third-party conformity assessment is required for key/critical products.
- Liaise with legal,
product, and leadership teams to keep the compliance programme aligned with evolving delegated/implementing acts and harmonised standards (e.g. ENISA/CEN-CENELEC guidance).
- Plan, scope, and coordinate periodic VAPT exercises (internal, external, network, and application layer) across in-scope products, in line with CRA vulnerability-handling requirements.
- Work with internal red-team/pen-test vendors to validate findings, assign CVSS-based severity, and drive remediation SLAs.
- Maintain a central vulnerability register mapped to affected products, versions, and exposure — feeding directly into the CRA reporting workflow.
- Own and mature the application security testing programme: SAST, DAST, IAST, and secure code review across the SDLC.
- Integrate AppSec tooling into CI/CD pipelines (e.g. gating builds on critical findings) in partnership with engineering and DevSecOps.
- CRA's mandatory timelines.
- Prepare early-warning, incident notification, and final-report submissions with accurate technical detail, in coordination with engineering and legal.
- Maintain audit-ready evidence of all reported vulnerabilities/incidents and the organisation's response, for use in regulatory audits and market-surveillance requests.
Preferred Qualifications:
- Prior experience with other EU cybersecurity/product regulations — NIS2 Directive, Radio Equipment Directive (RED) delegated act, or Machinery Regulation.
- Familiarity with ISO/IEC 27001, ISO/IEC 62443, IEC 81001-5-1, or ETSI EN 303 645.
- Exposure to threat modelling (STRIDE/PASTA) and secure SDLC frameworks (e.g. OWASP SAMM, BSIMM).
- Experience working with Notified Bodies or supporting CE marking / conformity assessment processes.
- Scripting/automation skills (Python/Bash) for building compliance dashboards or SBOM/vulnerability pipelines.
Preferred Certifications
- CISSP, CISM, or CRISC
- ISO/IEC 27001 Lead Implementer / Lead Auditor
- OSCP, CEH, or equivalent offensive-security certification
Certified in Cybersecurity (ISC2) or a recognised CRA/product-security training credential
📌 CRA Implementor — EU Cyber Resilience Act Compliance (India)
🏢 Dhyati
📍 India