CRA Practice Lead establishing a secure software development practice in compliance with EU regulations. Leading a multidisciplinary team ensuring software products meet cybersecurity standards.
Responsibilities
Define the vision, strategy, and operating model for a CRA-aligned secure development and certification practice.
Build and lead a high-performing team across secure development, compliance testing, and DevSecOps.
Collaborate with product, legal, and security teams to interpret CRA requirements and embed them into engineering workflows.
Establish secure-by-design principles across diverse technology stacks (e.g., web, mobile, embedded, cloud-native, edge).
Drive adoption of secure SDLC practices including threat modeling, secure architecture reviews, and secure coding standards.
Ensure integration of security controls across heterogeneous environments and third-party components.
Operationalize CRA-aligned testing and documentation processes across all software delivery pipelines.
Lead the implementation of automated compliance checks, SBOM generation, and vulnerability management.
Ensure traceability, audit readiness, and conformity assessment support for CRA and related regulations (e.g., NIS2, ISO 27001).
Define and implement a technology-agnostic toolchain for secure development, testing, and compliance automation.
Integrate security and compliance tooling into CI/CD pipelines across multiple platforms and languages.
Promote reuse of security patterns, templates, and automation assets across teams.
Act as the technical authority on CRA compliance for internal teams, partners, and clients.
Support pre-sales, solutioning, and proposal development for CRA-related services.
Represent the practice in regulatory, industry, and standards forums.
Requirements
10+ years of experience in software engineering, cybersecurity, or compliance, with at least 3 years in a leadership role.
Proven experience in secure software development across multiple platforms (e.g., cloud, mobile, embedded, edge).
Strong understanding of cybersecurity regulations including CRA, NIS2, and global standards (e.g., ISO/IEC 27001, ENISA guidelines).
Hands-on experience with secure SDLC, DevSecOps, and software composition analysis (SCA) tools.
Familiarity with SBOM standards (e.g., SPDX, CycloneDX) and vulnerability disclosure processes.
Excellent communication, leadership, and stakeholder management skills.
Software Developer working with the Federation of Quebec Municipalities on .NET applications. Engaging in design, programming, and improving systems while mentoring team members.
GIS Developer designing and building automated GIS solutions for telecommunications projects. Collaborating with teams to improve data quality, efficiency, and delivery outcomes nationwide.
Operations Research/Engineering Intern researching uncertainty quantification and decision making under uncertainty at AMA. Quantifying epistemic uncertainty and performing design using optimization techniques.
Mechanical/Aerospace Engineering Intern focusing on GNC support at AMA. Involves developing architectures for guidance, navigation, and control systems for aircraft.
Talent Development Lead managing talent development strategies and initiatives for Flutter Entertainment's Cluj hub. Collaborating closely with HR leaders while leveraging data and AI for improvements.
Developers at Ingeno design cloud applications incorporating AI for diverse industries. Work in a stimulating and collaborative environment with cutting - edge technologies.
Technical expert in Parenteral Technologies focusing on inspection equipment at a global healthcare leader. Partnering with sites to provide technical support and compliance in manufacturing operations.
Senior Developer integrating and developing web - based solutions for CBC/Radio - Canada's Corporate Services team. Collaborating with cross - functional teams on software application development and architecture.
Palantir Expert implementing and scaling enterprise data and AI platforms using Palantir Foundry. Leadership in data pipelines, AI/ML use cases, and complex data applications.