AppSec and GRC Engineer — Cybersecurity & Defence

Complear

Portugal

Teletrabalho

EUR 90 000 - 130 000

Tempo integral

há 39 horas
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Uma candidatura feita para esta oferta — um currículo e uma carta de apresentação personalizados que vão ao encontro do anúncio.

Ultrapassa os filtros ATS

Resumo da oferta

Complear, a Portugal-based cybersecurity startup with a remote-first approach, is seeking an AppSec and GRC Engineer to own client engagements end to end, helping clients become compliant while informing product direction.

You will lead gap assessments, risk analyses and threat modeling, map products to CRA, NIS2, DORA, GDPR, and drive remediation through policies and controls, advising on secure design and audit readiness.

Qualificações

  • Experience leading cybersecurity/GRC client engagements.
  • Ability to map products to CRA, NIS2, DORA, GDPR and industry standards.
  • Proven track record in risk assessments and threat modeling sessions.
  • Experience turning regulatory requirements into concrete security controls.

Responsabilidades

  • Lead gap assessments, risk analyses and threat modeling workshops.
  • Map client products/ processes to CRA, NIS2, DORA, TISAX, GDPR and related standards.
  • Develop remediation roadmaps, policies and controls to close gaps.
  • Advise on secure design and incident response readiness for audits.
  • Translate client findings into security requirements for the product team.

Conhecimentos

Threat modeling
Regulatory knowledge
Client advisory
Risk analysis
Security design
SAST/DAST
SBOM analysis
Vulnerability mgmt
Cybersecurity strategy

Ferramentas

SAST/DAST scanners
SBOM analysis
Vulnerability management

Descrição da oferta de emprego

AppSec and GRC Engineer — Cybersecurity & Defence

Cybersecurity & GRC Advisory

Remote (Worldwide)

Full-time

The Company

The mission of Complear is to build the AI-native compliance infrastructure that becomes the operating system for safety- and security-critical products around the world — the verification layer that turns innovation into market access.

We want to make it easy for teams building medical devices, aircraft and space systems, autonomous vehicles and defence platforms to become compliant from day 1, while driving business strategy decisions supported by solid regulatory information. Our platform, Complear OS, replaces document silos and manual audits with real-time verification embedded directly into the development lifecycle, so companies can enter the market faster and stay aligned with regulations that never stop evolving — from the Cyber Resilience Act, NIS2 and DORA to TISAX, ISO/IEC 27001 and GDPR.

The Job

As an AppSec and GRC Engineer you own client security and compliance engagements end to end: understanding a client’s products, risks and regulatory exposure, designing the program that gets them compliant, and staying with them until it holds up in an audit. You are the person the client calls, and the person our product team listens to about what security and compliance really demand.

One idea runs through the whole job: every engagement should make the product smarter. For the client, you lead gap assessments, risk analyses and threat modeling workshops, map their products and processes to the Cyber Resilience Act (CRA), NIS2, DORA, TISAX, GDPR and sector-specific standards, and build the remediation roadmap, policies and controls that close the gaps. For Complear OS, you turn what you see across engagements into security requirements and control frameworks our product team can automate and scale — so a control you design for one client can be checked continuously for all of them.

This is a client- and advisory-focused role, not a heads-down developer role. Most of your time goes to understanding a client’s reality, advising on secure design and incident response readiness, preparing them for audits and certifications, and guiding what our product team builds next. The technical slice is real but different in shape from an engineering job: reviewing architectures, challenging threat models and assessment results, reading SAST/DAST, SBOM and vulnerability reports critically, and knowing when a control that looks compliant on paper won’t work in practice. That last skill is the scarce one.

The Cyber Resilience Act changes the game for every manufacturer placing products with digital elements on the EU market. Secure-by-design requirements, vulnerability handling, SBOMs and incident reporting are becoming legal obligations across the product lifecycle, and most companies don’t yet know what that means for how they build, ship and maintain their products. Helping them get there — and shaping the infrastructure that keeps them there — is at the heart of this role.

We are looking for people who can lead client engagements with a high degree of autonomy, but who are eager learners and gather every kind of input before forming an opinion on a risk call. As the company grows, your scope grows with it.

If sitting with a client until their real risk is on the table, mapping a regulation clause by clause into controls their teams can actually implement, walking into an audit knowing the evidence is there, and shaping a product that makes all of this easier for the next client would make your day, then this job is for you.

You will learn the security and regulatory requirements of the most demanding sectors (CRA, NIS2, DORA, TISAX, ISO/IEC 27001, GDPR, and the standards specific to defence and critical infrastructure) and help clients turn them into a competitive advantage. While we deploy our product, you’ll be immersed in the operational realities of regulated industries — every day is a day to learn from the best.

We offer a competitive salary, flexible working hours, and a vital role in making safety- and security-critical technology trustworthy. Our company is based in Portugal, but we work fully remote, so you can live anywhere in the world. Our team gathers often to eat well and work together.

Learn every day. We don’t expect you to know every regulation, every standard, or every client’s industry. We expect you to be eager to learn whatever a successful engagement requires. You won’t be alone: our core team and our network of security experts are there for you.

Own the client, end to end. You lead security and compliance engagements from scoping to delivery — gap assessments, risk analyses, remediation roadmaps, audit and certification readiness. You are accountable for the outcome the client bought, not for a list of findings.

Start with the risk, not the checklist. Clients arrive asking for a certificate or a policy; the job is to find the product, process, or supply-chain risk underneath it. Threat modeling workshops and architecture reviews come before paperwork.

Turn regulation into controls. You map client products and organizations to the CRA, NIS2, DORA, TISAX, GDPR and sector-specific standards, and design the policies and controls that close the gaps. Every control should be something an engineering team can implement and an auditor can verify.

Advise with evidence. You are the trusted security voice for client and internal teams on secure design, secure development practices, vulnerability management and incident response readiness. When something needs to change, you say so — and show why.

Keep the evidence audit-ready. You help clients monitor and improve their security posture and prepare the evidence that audits and certifications require — captured as the work happens, never reconstructed after the fact.

Be the two-way channel to product. You are the face of our security expertise to clients, and the voice of clients inside our product team. You define the security requirements and control frameworks Complear OS automates, help prioritize what gets built, and verify that what ships actually meets the regulatory bar. What you learn on an engagement should change what we build next; you’ll be expected to say so, with evidence.

Be part of an exciting team building the compliance infrastructure for the cyber-physical economy. We are a startup in the fast-paced world of enterprise tech, working as both expert consultants and product builders. This is the future, and our team is already part of it.

The Absolute Unicorn Candidate
  • Consultancy track record. Proven experience in cybersecurity, application security or GRC consultancy. You’ve led client engagements from scoping to delivery, run workshops with CISOs and engineering leads, disagreed with a client productively, and kept multi-month programs on track.
  • Audits and certifications, delivered. Experience designing and maintaining control frameworks, performing risk assessments, and taking organizations through audits and certifications (e.g. ISO/IEC 27001, TISAX) to the finish line.
  • Regulatory and standards savvy. Strong knowledge of the CRA, NIS2, DORA, TISAX, ISO/IEC 27001/27002 and industry-specific security requirements — and of how they overlap, so clients don’t solve the same problem twice.
  • Application security fluency. Enough depth in secure software development, threat modeling and common vulnerabilities (e.g. OWASP Top 10) to review an architecture, challenge an engineering team, and judge a finding’s real impact. You don’t need to write the fix; you need to know whether it’s right.
  • Privacy and security by design. Understanding of data protection frameworks (e.g. GDPR, HIPAA), and the ability to bring privacy-by-design and security-by-design principles into a client’s products from the start.
  • Tooling literacy. Familiarity with SAST/DAST scanners, dependency and SBOM analysis, SIEM platforms and vulnerability management tools — enough to read their output critically and advise clients on how to use them well.
  • Product sense. You can turn recurring client problems into clear requirements, help prioritize them, and work with a product team to get them built. You enjoy seeing a method you’ve refined across engagements become a feature.
  • Excellent writing and communication. The assessment report a board acts on, the policy an auditor accepts, and the requirement a product team builds from — all three land.
  • Defence experience is a plus. Work with defence, space or dual-use clients, or familiarity with their security and supply-chain requirements, will set you apart.
  • We often seek people with diverse profiles ready to jump into new projects and challenges well beyond a traditional university curriculum or day job.
Obtém a tua avaliação gratuita e confidencial do currículo.

ou arrasta e larga o ficheiro aqui.

Similar jobs

Ofertas semelhantes que vale a pena comparar

Software Engineer (FullStack)
Software Engineer (FullStack)

Complear • Portugal

Presencial
EUR 40 000 - 60 000
Competitive salary
Flexible working hours
Opportunity for professional growth
Regulatory Affairs / Quality Affairs Consultant (Senior)
Regulatory Affairs / Quality Affairs Consultant (Senior)

Complear • Portugal

Presencial
EUR 40 000 - 60 000
Devoteam Cyber Trust | Lead Cloud Security Consultant - Microsoft Focus
Devoteam Cyber Trust | Lead Cloud Security Consultant - Microsoft Focus

Devoteam • Portugal

Presencial
EUR 65 000 - 85 000
Equal opportunity employer
Promotion based on merit
Cybersecurity Expert
Cybersecurity Expert

Consort Group • Lisboa

Presencial
EUR 43 000 - 52 000
Hybrid work
Competitive salary and HR package
Cyber Security Program Analyst
Cyber Security Program Analyst

Consort Group • Porto

Híbrido
EUR 35 000 - 52 000
Cryptography Cybersecurity Expert
Cryptography Cybersecurity Expert

Novartis • Lisboa

Híbrido
EUR 43 000 - 52 000
Cyber Security Senior Officer
Cyber Security Senior Officer

Consort Group • Portugal

Presencial
EUR 50 000 - 75 000
Health insurance
Pension plan
Continuous training opportunities
+1
Remote AppSec & GRC Engineer — Compliance Strategy
Remote AppSec & GRC Engineer — Compliance Strategy

Complear • Portugal

Teletrabalho
EUR 90 000 - 130 000
Senior Product Manager – Defence
Senior Product Manager – Defence

Critical Software • Lisboa, Coimbra, Viseu, Porto

Teletrabalho
EUR 90 000 - 130 000
Private health insurance
Employee assistance programme
Home office support
+4
Security & Compliance Engineer / Architect (Azure & OCI) (f/m)
Security & Compliance Engineer / Architect (Azure & OCI) (f/m)

GRUPO SOLUTIO • Lisboa

Presencial
EUR 96 000 - 165 000
Collaborative work environment
Professional growth opportunities
Leading company in seafood industry