Vacancy catalog
EPAM
Open role

Security Compliance Expert (CRA Compliance)

EPAMArmenia; Georgia; Kazakhstan
Work model
Remote
Experience
5+ years
Employment
Not specified
Compensation
Not disclosed
Technology signal
4 tags

Technology context

4

Parsed from the vacancy text; ordered by relevance to this role.

CybersecurityLinuxCompliance AssuranceSecurity Compliance Assurance

Full listing

Role description

We are seeking a Security Compliance Expert to perform a high-level CRA (Cyber Resilience Act) compliance gap analysis against the OS Vertical requirements for enterprise-grade Linux products. In this role, you will identify compliance gaps, assess the feasibility of compliance, and provide input for future technical investigations, working with enterprise-grade Linux OS on the x86/x86_64 platform.

Responsibilities

  • Produce a gap analysis spreadsheet/table with a requirement-by-requirement assessment
  • Identify compliance risks and high-level problem areas without diving into implementation details
  • Perform an initial feasibility assessment for non-compliant requirements
  • Provide recommendations on areas requiring deeper technical investigation
  • Review the current OS Vertical/ETSI documentation
  • Map regulatory requirements to the selected product (initially REL 10 / Liberty Linux 10.x)
  • Classify requirements as: Compliant, Potentially compliant with reasonable effort, or Not compliant/significant concern
  • Participate in knowledge-transfer sessions with stakeholders
  • Refine the analysis when newer versions of the OS Vertical become available, as the specification is still evolving and the exercise will need to be revisited

Requirements

  • 3+ years of relevant experience in Security Compliance Assurance
  • Understanding of product security and cybersecurity concepts in general
  • Background in Security/Compliance Architecture
  • Knowledge of product architecture and the lifecycle of the analyzed Linux distribution/product, along with product-level architecture understanding
  • Experience working with standards, controls, or regulatory frameworks
  • Capability to read, analyze, and interpret regulatory requirements from the OS Vertical document and map them to product capabilities
  • Proficiency in performing compliance assessments focused on gap identification rather than solution engineering or detailed implementation design
  • English level B1+ for effective communication

Nice to have

  • Familiarity with Linux platform engineering
  • Knowledge of enterprise-grade Linux OS support on x86/x86_64 platforms