CRA Practice Lead establishing a secure software development practice in compliance with EU regulations. Leading a multidisciplinary team ensuring software products meet cybersecurity standards.
Responsibilities
Define the vision, strategy, and operating model for a CRA-aligned secure development and certification practice.
Build and lead a high-performing team across secure development, compliance testing, and DevSecOps.
Collaborate with product, legal, and security teams to interpret CRA requirements and embed them into engineering workflows.
Establish secure-by-design principles across diverse technology stacks (e.g., web, mobile, embedded, cloud-native, edge).
Drive adoption of secure SDLC practices including threat modeling, secure architecture reviews, and secure coding standards.
Ensure integration of security controls across heterogeneous environments and third-party components.
Operationalize CRA-aligned testing and documentation processes across all software delivery pipelines.
Lead the implementation of automated compliance checks, SBOM generation, and vulnerability management.
Ensure traceability, audit readiness, and conformity assessment support for CRA and related regulations (e.g., NIS2, ISO 27001).
Define and implement a technology-agnostic toolchain for secure development, testing, and compliance automation.
Integrate security and compliance tooling into CI/CD pipelines across multiple platforms and languages.
Promote reuse of security patterns, templates, and automation assets across teams.
Act as the technical authority on CRA compliance for internal teams, partners, and clients.
Support pre-sales, solutioning, and proposal development for CRA-related services.
Represent the practice in regulatory, industry, and standards forums.
Requirements
10+ years of experience in software engineering, cybersecurity, or compliance, with at least 3 years in a leadership role.
Proven experience in secure software development across multiple platforms (e.g., cloud, mobile, embedded, edge).
Strong understanding of cybersecurity regulations including CRA, NIS2, and global standards (e.g., ISO/IEC 27001, ENISA guidelines).
Hands-on experience with secure SDLC, DevSecOps, and software composition analysis (SCA) tools.
Familiarity with SBOM standards (e.g., SPDX, CycloneDX) and vulnerability disclosure processes.
Excellent communication, leadership, and stakeholder management skills.
Engineering Intern focusing on data analysis and modelling tools for Rotor Sails at Anemoi. Collaborating with a professional engineering team in a hybrid working environment.
Engineering Intern contributing to Rotor Sail technology at Anemoi. Focused on data analysis, technical documentation, and CAD modelling for fuel - saving assessments.
Lead Developer responsible for the software architecture of a non - profit software firm. Managing a small team and enhancing a digital ERP platform for NGOs and charities.
Software Developer at a Berlin healthcare startup focused on modern E - Health solutions. Involves working on interface programming and improvement for customer systems.
Electrical Engineering Technician supporting Substation projects at Black & Veatch. Contributing to power systems design and drafting deliverables for critical infrastructure.
Senior Autonomy Engineering Specialist defining robotic needs and leading software solutions at Caterpillar. Collaborating on innovative robotics software interfacing with existing technology and hardware.
Director of Engineering overseeing engineering function for growth - focused EPC microgrid company. Leading design efforts for distributed energy projects including solar PV and battery systems.
Chemical Engineering Intern at Westlake providing real - life work experience in plant manufacturing activities. Working with a mentor to enhance skills in safety and engineering practices.
SharePoint Developer designing, building, and maintaining SharePoint sites for effective collaboration. Engaging with stakeholders to gather requirements and improve workflow efficiency.