Insight Global logo

Product Security & Cyber Compliance Consultant

Insight Global

Dennis, MAJobNo compensation foundTracked 4w agoSeen in employer's feed 4 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

At a glance

Compensation
No compensation found
Location
Dennis, MA
Work Authorization
Not specified

Job overview

Insight Global is hiring a Product Security & Cyber Compliance Consultant. The Product Security & Cyber Compliance Consultant will analyze regulatory requirements, evaluate their impact on client products, and conduct compliance assessments. This role involves reviewing product and technical architectures, identifying security weaknesses, and providing remediation guidance. The consultant will also collaborate with engineering, product, and leadership teams to ensure compliance readiness and support decision-making.

Key focus areas include Analyze UK PSTI requirements and determine applicability to client products, Evaluate the impact of the EU Cyber Resilience Act (CRA) on product offerings, and Identify regulatory obligations for connected devices in UK and European markets.

Successful candidates bring 5+ Years Of Experience In Cybersecurity, Product Security, Compliance Consulting, Systems Security, Or A Related Field. Important skills include UK PSTI Requirements, Linux, Linux Security, Cybersecurity Risk Management, Compliance Assessments, and Technical Architecture Assessment. Preferred (not required): Firmware Security, Embedded Systems Security, and Cloud-Connected Products Security.

Skills & qualifications

RequiredNice to have

Skills

UK PSTI RequirementsLinuxLinux SecurityCybersecurity Risk ManagementCompliance AssessmentsTechnical Architecture AssessmentRegulatory Requirements TranslationCommunicationConsultingCybersecurity Gap AssessmentsCompliance Readiness ReviewsEU Cyber Resilience ActETSI en 303 645NIS2IEC 62443Product Security ArchitectIoT SecuritySecuring Connected DevicesFirmware SecurityEmbedded Systems SecurityCloud-Connected Products SecuritySecure Product Development LifecycleVulnerability ManagementThreat ModelingProduct Security Programs

Qualifications

5+ Years Cybersecurity Experience5+ Years Product Security Experience5+ Years Compliance Consulting Experience5+ Years Systems Security ExperienceExperience With UK PSTI RequirementsExperience Evaluating Connected ProductsExperience Evaluating IoT DevicesExperience Evaluating Embedded SystemsExperience Evaluating Cyber-Physical SystemsExperience Working With Executive StakeholdersExperience With EU Cyber Resilience ActExperience With ETSI en 303 645

Full job description

Job Description

Regulatory & Compliance Assessment

•Analyze UK PSTI requirements and determine applicability to the clients products and supporting systems.

•Evaluate the impact of the EU Cyber Resilience Act (CRA) on current and future product offerings.

•Identify regulatory obligations associated with connected devices sold in the UK and European markets.

•Conduct compliance assessments across products, services, and supporting infrastructure.

•Identify compliance gaps and prioritize associated risks.

•Develop recommendations and remediation strategies to achieve regulatory compliance.

Product & Technical Architecture Review

•Assess the clients product architecture and connectivity model.

•Evaluate backend systems, remote support infrastructure, cloud environments, and technical dependencies supporting the product.

•Review cybersecurity controls across product, infrastructure, and support systems.

•Analyze Linux-based environments and system configurations where applicable.

•Identify security weaknesses, compliance deficiencies, and technical risks.

Advisory & Remediation Guidance

•Develop a practical roadmap toward compliance.

•Provide technical recommendations that align with regulatory requirements.

•Educate internal stakeholders on compliance obligations and implementation considerations.

•Advise leadership on business risk, compliance exposure, and prioritization strategies.

•Support decision-making regarding remediation efforts and future compliance planning.

Stakeholder Collaboration

•Work closely with engineering, product, and leadership teams.

•Gather information necessary to understand the clients current environment.

•Present findings, recommendations, and implementation approaches to key stakeholders.

•Support knowledge transfer and ongoing compliance readiness efforts.

Desired Deliverables

The consultant will be expected to provide:

•Regulatory applicability assessment

•Current-state compliance review

•Gap analysis report

•Compliance risk assessment

•Prioritized remediation recommendations

•Compliance roadmap and implementation guidance

•Executive-level summary of findings

•Technical recommendations supporting compliance readiness

We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to [email protected] learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.

Skills and Requirements

5+ years of experience in cybersecurity, product security, compliance consulting, systems security, or a related field.

Demonstrated experience with UK PSTI requirements.

Experience supporting organizations with EU Cyber Resilience Act (CRA), ETSI EN 303 645, NIS2, IEC 62443, or similar regulatory frameworks.

Strong Linux administration or Linux security background.

Experience evaluating connected products, IoT devices, embedded systems, or cyber-physical systems.

Deep understanding of cybersecurity risk management and compliance assessments.

Ability to assess technical architectures and translate regulatory requirements into practical recommendations.

Strong communication and consulting skills with the ability to work directly with executive stakeholders. Experience conducting cybersecurity gap assessments and compliance readiness reviews.

Product Security Architect or IoT Security background.

Experience securing connected devices, firmware, embedded systems, and cloud-connected products.

Knowledge of secure product development lifecycle (Secure SDLC).

Experience with vulnerability management, threat modeling, and product security programs.

Prior consulting experience supporting companies expanding into international markets.

Experience working in a fractional, advisory, or independent consulting capacity.

You've read the whole posting — now see how you match it.