CRA Practice Lead establishing a secure software development practice in compliance with EU regulations. Leading a multidisciplinary team ensuring software products meet cybersecurity standards.
Responsibilities
Define the vision, strategy, and operating model for a CRA-aligned secure development and certification practice.
Build and lead a high-performing team across secure development, compliance testing, and DevSecOps.
Collaborate with product, legal, and security teams to interpret CRA requirements and embed them into engineering workflows.
Establish secure-by-design principles across diverse technology stacks (e.g., web, mobile, embedded, cloud-native, edge).
Drive adoption of secure SDLC practices including threat modeling, secure architecture reviews, and secure coding standards.
Ensure integration of security controls across heterogeneous environments and third-party components.
Operationalize CRA-aligned testing and documentation processes across all software delivery pipelines.
Lead the implementation of automated compliance checks, SBOM generation, and vulnerability management.
Ensure traceability, audit readiness, and conformity assessment support for CRA and related regulations (e.g., NIS2, ISO 27001).
Define and implement a technology-agnostic toolchain for secure development, testing, and compliance automation.
Integrate security and compliance tooling into CI/CD pipelines across multiple platforms and languages.
Promote reuse of security patterns, templates, and automation assets across teams.
Act as the technical authority on CRA compliance for internal teams, partners, and clients.
Support pre-sales, solutioning, and proposal development for CRA-related services.
Represent the practice in regulatory, industry, and standards forums.
Requirements
10+ years of experience in software engineering, cybersecurity, or compliance, with at least 3 years in a leadership role.
Proven experience in secure software development across multiple platforms (e.g., cloud, mobile, embedded, edge).
Strong understanding of cybersecurity regulations including CRA, NIS2, and global standards (e.g., ISO/IEC 27001, ENISA guidelines).
Hands-on experience with secure SDLC, DevSecOps, and software composition analysis (SCA) tools.
Familiarity with SBOM standards (e.g., SPDX, CycloneDX) and vulnerability disclosure processes.
Excellent communication, leadership, and stakeholder management skills.
Software Development Intern transforming requirements into software according to design for maximized business value and customer satisfaction. Involves software coding, testing, and documentation practices.
Senior Power Electronics Developer designing and developing hardware for innovative subsea control systems at TechnipFMC. Join a global team focused on electrification and renewable energy technology advancements.
PKI Engineer driving enterprise PKI strategy and automation for secure certificate management. Collaborating with teams to strengthen cryptographic security and compliance for financial infrastructure.
Manufacturing Engineer optimizing piston manufacturing processes at Tenneco. Driving quality, efficiency, and cost - effectiveness in production environments of piston operations.
Co - op Engineering Student supporting heavy civil projects at Aecon, a Canadian leader in infrastructure development. Engaging in site management, resource allocation, and engineering tasks.
Microsoft Dynamics Lead Developer specializing in CRM solutions for IT services. Lead design and support for a scalable integrated CRM platform in a hybrid work environment.
Industrial Engineering Intern managing AI - based market insights project at Vaisala. Collaborating with teams to create actionable insights and strategic improvements in a flexible work environment.
Software Developer enhancing innovative software solutions in an agile team at blue:solution, a specialist in software for the skilled trades. Contributing to future developments in a supporting role.