📢 New: get today's jobs on our WhatsApp Channel
Jobiglo

No results.

Product Security Technical Consultant

EPAM Systems

New Remote
Remote Senior 🇬🇧 English
CRA IEC 62443 NIS2 STRIDE PASTA MITRE ATT&CK OWASP ASVS SAST DAST SCA AI/ML security OWASP LLM Top 10 AI SBOM MLOps CI/CD DevSecOps

Job description

About the role

We are seeking a Product Security Technical Consultant to guide industrial product development teams on security requirements, regulatory compliance, and AI‑driven secure development practices across large, federated product portfolios. The role can be performed remotely from anywhere in Latvia, with optional collaboration at our Riga office.

Key responsibilities

  • Design and maintain security requirement frameworks, including control libraries, deviation governance, and risk acceptance procedures.
  • Translate Cyber Resilience Act requirements into engineering specifications covering SBOM governance, secure‑by‑default configurations, and vulnerability handling.
  • Conduct OT/ICS security assessments, gap analyses, zone/conduit modeling, and component mapping.
  • Lead threat‑modeling workshops using STRIDE, PASTA, or MITRE ATT&CK for industrial control systems.
  • Define and implement SDL/SSDLC programs, integrating OWASP ASVS compliance, SAST/DAST/SCA toolchains, and secure coding standards.
  • Support Notified Body engagements and prepare technical documentation for CRA Class I and II products.
  • Design threat models for AI/ML‑enabled products and apply OWASP LLM Top 10 mitigations.
  • Integrate AI security controls into DevSecOps pipelines, including model provenance, AI SBOM, and MLOps security gates.
  • Perform regulatory gap assessments across CRA, NIS2, EU AI Act, and DORA, delivering remediation roadmaps.
  • Present compliance posture and security architecture findings to senior stakeholders and facilitate cross‑functional workshops.

Required profile

  • 5+ years of product security advisory experience for industrial product development.
  • Deep knowledge of CRA, IEC 62443, and NIS2 frameworks.
  • Proven expertise in threat‑modeling methodologies (STRIDE, PASTA, MITRE ATT&CK) for ICS.
  • Strong background in secure SDLC practices, OWASP ASVS, and SAST/DAST/SCA integration.
  • Familiarity with AI/ML security, OWASP LLM Top 10, and AI SBOM governance.
  • Experience with DevSecOps pipelines, CI/CD compliance checks, and MLOps security gates.
  • Excellent stakeholder communication skills, capable of presenting to CISOs and engineering VPs.
  • Advanced English proficiency (C1) with strong written and verbal abilities.

Required skills

  • CRA
  • IEC 62443
  • NIS2
  • STRIDE
  • PASTA
  • MITRE ATT&CK
  • OWASP ASVS
  • SAST
  • DAST
  • SCA
  • AI/ML security
  • OWASP LLM Top 10
  • AI SBOM
  • MLOps
  • CI/CD
  • DevSecOps

Questions fréquentes

Le salaire n'est pas communiqué publiquement par le recruteur. Vous pouvez postuler et négocier directement avec EPAM Systems.
Cliquez sur "Postuler maintenant" en haut de la page. Vous pouvez importer votre CV en 1 clic — Jobiglo extrait automatiquement vos informations et postule pour vous.

Why are you reporting this job?

Thank you for your report. We will review this job.

Explore further

Salaries, guides and searches in Latvia.

Salaries by job title

Apply in 30 seconds

Enter your email to apply. An account will be created automatically.

By continuing, you accept our terms of use.

Already have an account? Login

💬 Chat with us on Telegram Chat on WhatsApp

Published 4 days ago

Expires 1 month from now

14 views · 0 interested

Boost your chances

Upload your CV — we will match you with relevant openings.

Analyzing your CV...

EPAM Systems