D
D

CRA Implementor — EU Cyber Resilience Act Compliance

Dhyati
Remote - India
ContractHybrid4 - 5 yrs
1d ago0 view0 clicked apply

Build, Review & Tailor Your Resume with AI (Create an ATS-friendly resume, improve it, and tailor it for this job instantly.)

Location: India (Remote / Hybrid — willing to overlap with CET business hours)

Experience: 4–5 years in cybersecurity compliance, product/application security, or GRC

Function: Cyber Resilience Act (CRA) Compliance / Product Security

Reports to: Head of Security / CISO / GRC Lead

Employment type: Contractor


About the role:

We are looking for a hands-on CRA Implementor, based in India, to lead our organisation's compliance programme for the EU Cyber Resilience Act — Regulation (EU) 2024/2847 ("CRA"), 

This role will implement CRA compliance end-to-end: interpreting the essential requirements in Annexes I and II, embedding secure-development and vulnerability-handling processes across engineering teams, running and coordinating VAPT and application security testing, securing the software supply chain (including SBOM generation and management), and owning regulatory reporting to ENISA and national CSIRTs within the Act's mandated timelines. You will work closely with engineering, product, legal, and security teams distributed across India and the EU.

Key Responsibilities

  1. CRA Programme Implementation & Governance

•     Translate CRA Articles and Annex I essential requirements (cybersecurity-by-design/by-default, secure defaults, vulnerability handling) into internal policies, standards, and controls.

•     Classify company products against CRA product categories (default, important — Class I/II, critical) to determine applicable conformity assessment routes.

•     Build and maintain a CRA compliance register, gap-assessment matrix, and remediation roadmap; track progress toward the 11 September 2026 reporting-obligation deadline and the 11 December 2027 full-application deadline.

•     Prepare technical documentation required under Annex VII (risk assessment, design/development documentation, evidence of conformity) and support CE marking and Declaration of Conformity processes.

•     Coordinate with Notified Bodies where third-party conformity assessment is required for important/critical products.

•     Liaise with legal, product, and leadership teams to keep the compliance programme aligned with evolving delegated/implementing acts and harmonised standards (e.g. ENISA/CEN-CENELEC guidance).

•     Plan, scope, and coordinate periodic VAPT exercises (internal, external, network, and application layer) across in-scope products, in line with CRA vulnerability-handling requirements.

•     Work with internal red-team/pen-test vendors to validate findings, assign CVSS-based severity, and drive remediation SLAs.

•     Maintain a central vulnerability register mapped to affected products, versions, and exposure — feeding directly into the CRA reporting workflow.

•     Own and mature the application security testing programme: SAST, DAST, IAST, and secure code review across the SDLC.

•     Integrate AppSec tooling into CI/CD pipelines (e.g. gating builds on critical findings) in partnership with engineering and DevSecOps.

•     CRA's mandatory timelines.

•     Prepare early-warning, incident notification, and final-report submissions with accurate technical detail, in coordination with engineering and legal.

•     Maintain audit-ready evidence of all reported vulnerabilities/incidents and the organisation's response, for use in regulatory audits and market-surveillance requests.

Preferred Qualifications:

•     Prior experience with other EU cybersecurity/product regulations — NIS2 Directive, Radio Equipment Directive (RED) delegated act, or Machinery Regulation.

•     Familiarity with ISO/IEC 27001, ISO/IEC 62443, IEC 81001-5-1, or ETSI EN 303 645.

•     Exposure to threat modelling (STRIDE/PASTA) and secure SDLC frameworks (e.g. OWASP SAMM, BSIMM).

•     Experience working with Notified Bodies or supporting CE marking / conformity assessment processes.

•     Scripting/automation skills (Python/Bash) for building compliance dashboards or SBOM/vulnerability pipelines.


Preferred Certifications

•     CISSP, CISM, or CRISC

•     ISO/IEC 27001 Lead Implementer / Lead Auditor

•     OSCP, CEH, or equivalent offensive-security certification

Certified in Cybersecurity (ISC2) or a recognised CRA/product-security training credential

RESUME BUILDER

Build Your Resume for Free in Minutes

Create ATS-friendly resumes with modern templates and AI-powered suggestions.

ATS Friendly
Rohan SharmaMarketing Manager

Professional Summary

Experience

ATS Friendly
RESUME REVIEW

Get Your Resume
Reviewed for Free

Discover missing skills, ATS issues, and get personalized suggestions to improve your chances.

Secure
92%
ATS Score
Review SummaryGood keywordsWell-structuredAdd metrics
Improve your score with the suggestions.
RESUME TAILORING

Tailor Your Resume for This Job

Match your resume to this job's requirements in one click.

96%Match