Job Description
Regulatory & Compliance Assessment
•Analyze UK PSTI requirements and determine applicability to the clients products and supporting systems.
•Evaluate the impact of the EU Cyber Resilience Act (CRA) on current and future product offerings.
•Identify regulatory obligations associated with connected devices sold in the UK and European markets.
•Conduct compliance assessments across products, services, and supporting infrastructure.
•Identify compliance gaps and prioritize associated risks.
•Develop recommendations and remediation strategies to achieve regulatory compliance.
Product & Technical Architecture Review
•Assess the clients product architecture and connectivity model.
•Evaluate backend systems, remote support infrastructure, cloud environments, and technical dependencies supporting the product.
•Review cybersecurity controls across product, infrastructure, and support systems.
•Analyze Linux-based environments and system configurations where applicable.
•Identify security weaknesses, compliance deficiencies, and technical risks.
Advisory & Remediation Guidance
•Develop a practical roadmap toward compliance.
•Provide technical recommendations that align with regulatory requirements.
•Educate internal stakeholders on compliance obligations and implementation considerations.
•Advise leadership on business risk, compliance exposure, and prioritization strategies.
•Support decision-making regarding remediation efforts and future compliance planning.
Stakeholder Collaboration
•Work closely with engineering, product, and leadership teams.
•Gather information necessary to understand the clients current environment.
•Present findings, recommendations, and implementation approaches to key stakeholders.
•Support knowledge transfer and ongoing compliance readiness efforts.
Desired Deliverables
The consultant will be expected to provide:
•Regulatory applicability assessment
•Current-state compliance review
•Gap analysis report
•Compliance risk assessment
•Prioritized remediation recommendations
•Compliance roadmap and implementation guidance
•Executive-level summary of findings
•Technical recommendations supporting compliance readiness
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com.To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/.
Required Skills & Experience
5+ years of experience in cybersecurity, product security, compliance consulting, systems security, or a related field.
Demonstrated experience with UK PSTI requirements.
Experience supporting organizations with EU Cyber Resilience Act (CRA), ETSI EN 303 645, NIS2, IEC 62443, or similar regulatory frameworks.
Strong Linux administration or Linux security background.
Experience evaluating connected products, IoT devices, embedded systems, or cyber-physical systems.
Deep understanding of cybersecurity risk management and compliance assessments.
Ability to assess technical architectures and translate regulatory requirements into practical recommendations.
Strong communication and consulting skills with the ability to work directly with executive stakeholders.
Nice to Have Skills & Experience
Experience conducting cybersecurity gap assessments and compliance readiness reviews.
Product Security Architect or IoT Security background.
Experience securing connected devices, firmware, embedded systems, and cloud-connected products.
Knowledge of secure product development lifecycle (Secure SDLC).
Experience with vulnerability management, threat modeling, and product security programs.
•
Prior consulting experience supporting companies expanding into international markets.
Experience working in a fractional, advisory, or independent consulting capacity.
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.