Cybersecurity Regulations Engineer , Sear

Apple Apple · Big Tech · Paris, Ile-de-France, France · Software and Services

This role focuses on understanding and ensuring compliance with cybersecurity regulations, including the EU AI Act, for Apple products. It involves analyzing regulations, developing compliance strategies, and collaborating with various internal and external stakeholders to demonstrate product security robustness.

What you'd actually do

  1. Analyzing cybersecurity regulations to assess their impact on Apple products and identifying compliance strategies that build or leverage technical evidence and processes
  2. Proactively driving Apple's cybersecurity regulation strategy in collaboration with Legal and Government Affairs teams
  3. Working cooperatively with other parts of Apple on cross-functional technologies and their security strategies
  4. Collaborating with industry representatives, evaluation labs, governmental bodies, and regulatory authorities
  5. Driving certifications and regulations of complex products from beginning to end

Skills

Required

  • Significant understanding of security engineering principles
  • Experience with cybersecurity regulatory frameworks (e.g., EU Cyber Resilience Act, EU Cybersecurity Act, EUCC, EUDIW, EU AI Act and/or equivalent regional cybersecurity regulations)
  • Passion for high quality deliverables, thriving for efficiency
  • Ability to work cross-functionally with other software, hardware, marketing, legal, government affairs, and support teams to demonstrate security robustness of Apple's products

Nice to have

  • Working knowledge of Common Criteria and FIPS 140-2/3 certifications, or strong willingness to learn
  • Experience writing product security profiles for evaluation scoping (Security Target, Protection Profile, or other product security definition)
  • Experience in security certifications and/or cybersecurity regulations and associated external stakeholders (certification bodies, regulators and evaluation laboratories)
  • Experience analyzing cybersecurity regulations and translating regulatory requirements into compliance strategies leveraging existing technical evidence
  • Ability to monitor and assess the impact of emerging cybersecurity regulations across multiple jurisdictions (EU, US, Asia-Pacific)
  • An effective communicator and engaging presenter who can influence multiple audiences from engineering teams to senior leadership
  • Excellent teamwork skills and ability to represent Apple and your organization in conversations with authorities
  • Strong written and verbal communication skills in English; proficiency in other languages (e.g., German, French, Spanish) nice to have.

What the JD emphasized

  • cybersecurity regulations
  • EU Cyber Resilience Act
  • EU Cybersecurity Act
  • EU AI Act