Consultant – Product Security & Regulatory Compliance (Industrial OT/AI Systems)
EPAM Systems
Job description
About the role
We are looking for a Consultant to strengthen our advisory practice for industrial operational technology (OT) and AI‑embedded product development. You will guide clients through complex regulatory landscapes, embed security into engineering delivery, and translate compliance obligations into actionable technical specifications for federated product portfolios.
Key responsibilities
- Design and maintain product security requirement frameworks, including control libraries, deviation governance, risk acceptance, and change‑propagation models.
- Translate Cyber Resilience Act (CRA) essential requirements into engineering specifications such as SBOM governance, secure‑by‑default configurations, vulnerability handling, secure update mechanisms, and CE marking documentation.
- Perform OT/ICS security level assessments, zone/conduit modeling, and component requirement mapping with evidence packages for client conformity verification.
- Lead threat‑modeling workshops using STRIDE, PASTA or MITRE ATT&CK for ICS and produce prioritized risk registers and control recommendations.
- Define and implement SDL/SSDLC programs, including OWASP ASVS compliance matrices, SAST/DAST/SCA toolchain integration, and secure coding standards for embedded and industrial software.
- Support Notified Body engagements, prepare technical documentation for CRA Class I/II products, and author security architecture documents for regulatory submissions.
- Design threat models for AI/ML or LLM‑enabled industrial products, integrate AI security controls into DevSecOps pipelines, and address EU AI Act conformity obligations.
- Conduct regulatory gap assessments across CRA, NIS2, EU AI Act and DORA, delivering remediation roadmaps and presenting findings to senior client stakeholders.
Required profile
- Strong knowledge of industrial OT/ICS security standards and regulatory frameworks (CRA, NIS2, EU AI Act, DORA).
- Proven experience in threat modeling, security requirement engineering, and SDL/SSDLC implementation.
- Ability to communicate complex security and compliance concepts to senior technical and business audiences.
Required skills
- STRIDE, PASTA, MITRE ATT&CK for ICS
- OWASP ASVS, OWASP LLM Top 10
- SAST, DAST, SCA toolchains
- SBOM governance, AI SBOM, model provenance
- CI/CD and MLOps security gates
- Secure‑by‑default configuration, secure update mechanisms
- Zone/conduit modeling, risk acceptance procedures
- Notified Body engagement and technical documentation preparation
What we offer
- Flexibility to work remotely from anywhere in Latvia or from our Riga office.
- Opportunity to work on cutting‑edge industrial OT and AI security projects.
- Collaborative environment with senior security and regulatory experts.
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches for Latvija.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published pirms 5 dienām
Expires pēc 1 mēneša
19 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
EPAM Systems