Compliance Tpm - Device Security

Verkada Verkada · Enterprise · Bayoffice · Security

Verkada is seeking a Compliance TPM for their Device Security team to build and own the company's device security compliance program, enabling import and sale to new markets and customers. This role involves cross-functional collaboration with legal, product management, and hardware teams to align on compliance frameworks, manage a compliance tracker, bootstrap an internal product security compliance team with an automation-first approach, and coordinate remediation efforts.

What you'd actually do

  1. Own and build Verkada’s device security compliance program, allowing the company to import and sell to new markets and customers.
  2. Work cross-functionally with legal, product management, hardware, and executive stakeholders to align on required device security compliance frameworks & timelines, such as EU RED 3.3 (d)(e)(f) and the EU Cyber Resilience Act.
  3. Own the device security compliance tracker across product lines, geographies, customer segments, and timelines.
  4. Bootstrap Verkada’s internal product security compliance team, taking an automation-first approach to validating product compliance with cybersecurity regulations.
  5. Prepare and file required technical documentation to prove compliance with cybersecurity regulations.

Skills

Required

  • Exceptional organization & interpersonal communication skills.
  • Ability to multi-task, prioritize work, and meet deadlines in a fast-paced work environment.
  • Ability to effectively and autonomously accomplish outcomes despite ambiguous situations.
  • At least 5 years of experience working on regulatory compliance for IoT, OT, ICS, or similar domains.
  • Have worked in an agile team environment.

Nice to have

  • Prior experience managing other compliance schemes such as FCC or UL a plus.
  • Knowledge of product cybersecurity certifications for IoT/OT domains, such as ETSI EN 303 645 or ISO/IEC 62443.
  • Experience with scripting languages such as Python.

What the JD emphasized

  • regulatory compliance for IoT, OT, ICS, or similar domains