Product Security & Compliance Engineer
Nabucasa · Europe - Anywhere · 2026-08-26
About this role
ABOUT NABU CASA
Nabu Casa, Inc was founded in 2018 by the founders of both Home Assistant https://home-assistant.io/, the open source home automation platform, and Home Assistant OS https://github.com/home-assistant/operating-system, the operating system that turns your device into a smart home hub powered by Home Assistant. These projects have seen an immense growth and have helped shape DIY home automation communities around the world.
After being involved in the Internet of Things industry for many years, we realized that there is a need for a cloud service that aims to put users, their privacy and their data first. Such a cloud can only be built as an extension to a platform that does the same: Home Assistant.
With Nabu Casa we are building this cloud service and we’re calling it Home Assistant Cloud.
We are a profitable company with no external investors. Our funding comes directly from users who subscribe to Home Assistant Cloud and purchase Home Assistant hardware, ensuring our only stakeholders are our employees and our users. We also support other open-source projects, including those focused on hardware, standards, and voice technology.
THE ROLE
Nabu Casa is looking for a full-time Product Security & Compliance Engineer to help ensure that our connected hardware and cloud services are secure, resilient, and compliant with the regulatory requirements that apply to them.
Home Assistant is one of the world's largest open-source smart home platforms, and Nabu Casa supports its development while also bringing connected hardware and cloud services to users around the world. As our product portfolio grows, so does the importance of building security and regulatory compliance into our products from the start.
This is a deliberately hybrid role combining hands-on product security engineering with cybersecurity compliance. You will work across connected devices, firmware, networking, and cloud services: building threat models, performing security validation, managing vulnerability and software-supply-chain risks, and turning that technical work into the evidence required for product conformity.
You will also help Nabu Casa navigate evolving product cybersecurity requirements such as the EU Radio Equipment Directive (RED), EN 18031, and the Cyber Resilience Act (CRA).
We don't expect you to arrive as an expert in every security and regulatory domain. We are looking for someone with strong technical security foundations who is comfortable learning, interpreting requirements, taking ownership, and working across engineering and compliance boundaries.
WHAT YOU ARE GOING TO DO
- Own the cybersecurity aspects of regulatory compliance for Nabu Casa's connected hardware products, including RED cybersecurity requirements and EN 18031.
- Help prepare Nabu Casa's products and processes for the EU Cyber Resilience Act (CRA), including vulnerability handling, security updates, SBOMs, support periods, and incident reporting.
- Create and maintain architecture and data-flow diagrams for connected products and services.
- Perform threat modeling and translate identified risks into security requirements and controls.
- Perform hands-on product security validation, including vulnerability and dependency scanning, SAST/DAST, firmware analysis, network and service exposure assessment, and targeted penetration testing.
- Generate and maintain Software Bills of Materials (SBOMs) and help monitor software dependencies for known vulnerabilities.
- Validate security mechanisms such as authentication, secure boot, and signed software or firmware updates.
- Translate security assessments and test results into structured compliance evidence, technical documentation, conformity assessments, and Declarations of Conformity.
- Work closely with hardware, firmware, cloud, and product teams to ensure security and compliance requirements are considered early in product development.
- Coordinate with our ODMs and external certification bodies where required, while owning Nabu Casa's cybersecurity evidence internally.
- Work with the Open Home Foundation to ensure security information, vulnerability handling, and software-related documentation flow effectively between open-source projects and Nabu Casa's commercial products.
- Keep track of product conformity status, security support periods, regulatory deadlines, and changes that may require reassessment.
- Provide privacy-by-design input for significant changes to our cloud services when needed.
WHAT YOU NEED TO HAVE
- Strong hands-on technical experience in at least one of the following areas: embedded/firmware security, network security, application security, or cloud security.
- Experience creating architecture or data-flow diagrams and performing threat modeling for real products or systems.
- Practical experience with security testing and tooling, such as vulnerability scanning, SAST/DAST, software composition analysis, SBOM tooling, network security testing, firmware analysis, or penetration testing.
- Experience working with connected products, IoT, embedded systems, firmware, or systems that combine hardware and software/cloud services.
- Experience translating technical security findings into structured documentation, evidence, risk assessments, or compliance requirements.
- Knowledge of product cybersecurity standards or regulations, such as EN 18031, RED cybersecurity requirements, the Cyber Resilience Act, ETSI EN 303 645, IEC 62443, or comparable frameworks.
- Ability to independently interpret technical requirements, identify gaps, and work with engineering teams to implement appropriate solutions.
- Comfortable working autonomously across multiple technical domains in a distributed organization.
- Strong written and verbal communication skills.
- Fluent in English, both written and spoken.
IT WOULD BE GREAT IF YOU ALSO HAVE
- Personal experience using Home Assistant…
Skills asked for
- cybersecurity
- penetration testing
- ci/cd
- python
Your next role is already in here.
Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.