Cyber Resilience Act (CRA) Compliance Lead

Posted One Month Ago
Be an Early Applicant
San Jose, CA, USA
In-Office
149K-216K Annually
Expert/Leader
Artificial Intelligence • Internet of Things • Machine Learning
The Role
Lead enterprise compliance for the EU Cyber Resilience Act by translating regulatory obligations into product lifecycle processes, governance, conformity evidence, and metrics. Coordinate cross-functional activities across security, engineering, quality, legal, and product teams; define SBOM and software-component traceability, vulnerability and post-market processes, conformity-assessment frameworks, training, and audit readiness. Monitor regulatory developments and support product classification, technical documentation, and executive reporting.
Summary Generated by Built In
Job Details:

Job Description:

About Altera

At Altera™, our independence as the world’s largest pureplay FPGA solutions provider gives us the focus, speed, and agility to innovate without compromise. With more than four decades of industryleading FPGA expertise, our singular mission is to deliver the programmable technologies that help customers differentiate, innovate, and scale across rapidly evolving markets like AI, cloud, networking, and edge. As an independent company, we move faster, invest deeper, and partner more closely—empowering our teams to drive breakthrough innovation and shape the future of the FPGA industry.

About the Role

We are seeking for a Cyber Resilience Act (CRA) Compliance Lead who will establish, govern, and drive the company-wide compliance framework for the European Union Cyber Resilience Act and related product cybersecurity regulatory requirements.

Reporting within the Quality & Reliability organization, this role will serve as the enterprise CRA compliance lead and will coordinate cross-functional activities. The role is responsible for translating regulatory obligations into scalable product lifecycle processes, compliance requirements, governance mechanisms, objective evidence, and conformity documentation. The CRA Compliance Lead will provide independent oversight of compliance while partnering with technical organizations responsible for cybersecurity architecture, product, software and firmware development, vulnerability management, security testing, incident response, vendor management and implementation of cybersecurity controls.

This is a senior role requiring strong knowledge of product cybersecurity regulations, semiconductor and embedded-product lifecycles, quality management systems, risk management, regulatory conformity, and cross-functional program execution.

Key Responsibilities:

CRA Compliance Strategy & Governance

  • Maintain the enterprise CRA compliance framework, governance model, policies, procedures, roles, responsibilities, and decision authorities.

  • Establish traceability model between CRA requirements, cybersecurity risks, product requirements, design controls, verification activities, technical documentation, and conformity evidence.

  • Coordinate alignment with applicable standards and frameworks, including ISO/IEC 27001, IEC 62443, ISO/SAE 21434, ISO 26262, vulnerability management standards, emerging CRA harmonized standards and Altera security requirements.

  • Monitor regulatory developments, delegated acts, implementing guidance, harmonized standards, and industry interpretations that may affect company products or compliance obligations.

  • Partner with cross functional organization to determine product classification, critical-product applicability, conformity assessment pathways and regulatory obligations.

  • Support integration of CRA requirements into product requirement management, product lifecycle management, configuration management, change control, and release-management systems.

  • Establish governance requirements for Software Bill of Materials management and CRA-related software-component traceability.

  • Coordinate assessment of third-party software, intellectual property, software components, and external dependencies that may affect product compliance.

  • Lead development and governance of the CRA conformity-assessment framework, and maintenance of required CRA technical documentation and conformity evidence.

  • Define and drive CRA compliance check and evidence requirements for product concept, architecture, design, implementation, verification, validation, release, production, maintenance, and end-of-support stages.

CRA Compliance Operations & Enablement:

  • Partner with product security on vulnerability escalation, product non-conformity management and external communication

  • Establish CRA compliance metrics, dashboards, risk indicators, and management-reporting mechanisms.

  • Integrate CRA compliance monitoring into applicable QMS audit, management-review, risk-management, and corrective-action processes.

  • Develop CRA training, awareness, role-based competency requirements, and implementation guidance to promote a sustainable compliance culture.

  • Facilitate resolution of complex regulatory, technical, process, and organizational compliance issues.

Salary Range

The pay range below is for Bay Area California only. Actual salary may vary based on a number of factors including job location, job-related knowledge, skills, experiences, trainings, etc. We also offer incentive opportunities that reward employees based on individual and company performance.

$149,100 - $215,925 USD

We use artificial intelligence to screen, assess, or select applicants for the position. Applicants must be eligible for any required U.S. export authorizations.

#LI-MD1

Qualifications:

Minimum Qualifications

  • Bachelor's degree in Engineering, Computer Science, Information Systems, Cybersecurity, Quality, or a related technical field.

  • 10+ years of experience in product compliance, product cybersecurity, quality systems, regulatory compliance, engineering governance, semiconductor product development, or related technical disciplines.

  • 2+ years of experience interpreting and applying product cybersecurity regulations, including the EU Cyber Resilience Act (CRA) and other applicable global product security regulatory requirements.

  • 8+ years of experience leading enterprise or product compliance programs across multiple cross-functional organizations and global geographic locations.

  • 8+ years of experience implementing secure product development lifecycle (Secure SDLC) processes, product cybersecurity risk management, vulnerability management, software component governance (SBOM/open-source governance), and post-market product security compliance.

  • 8+ years of experience managing product lifecycle governance processes, including New Product Introduction (NPI), requirements management, configuration management, engineering change management, product release governance, audit readiness, and compliance evidence management.

  • 8+ years of experience partnering with executive leadership, engineering, legal, quality, security, and product management teams to drive compliance initiatives and influence technical decisions without direct management authority.

  • 8+ years of experience leading complex cross-functional programs requiring executive-level communication, data-driven decision making, stakeholder management, facilitation, and presentation of compliance strategies, risks, and program status to senior leadership.

Preferred Qualifications

  • Experience within the FPGA, semiconductor, embedded systems, electronics, automotive, aerospace, defense, industrial, or technology industries.

  • Experience with semiconductor hardware, embedded firmware, software development tools, intellectual property, reference designs, or complex product ecosystems.

  • Working knowledge of applicable standards and frameworks, such as:

    • IEC 62443, ISO/SAE 21434, ISO/IEC 27001, ISO 9001, AS9100, ISO 26262,IEC 61508

    • NIST Cybersecurity and secure software development Framework, Common Criteria or related product-security assurance frameworks

  • Experience with Software Bill of Materials, 3rd party and open-source software governance, vulnerability-disclosure programs, product security incident response, or cybersecurity conformity assessment.

  • Experience supporting CE marking, EU product regulations, technical-file development, declarations of conformity, or market-surveillance activities.

Job Type: Regular

Shift:Shift 1 (United States of America)

Primary Location:San Jose, California, United States

Additional Locations:

Posting Statement:All qualified applicants will receive consideration for employment without regard to race, color, religion, religious creed, sex, national origin, ancestry, age, physical or mental disability, medical condition, genetic information, military and veteran status, marital status, pregnancy, gender, gender expression, gender identity, sexual orientation, or any other characteristic protected by local law, regulation, or ordinance.

Skills Required

  • Bachelor's degree in Engineering, Computer Science, Information Systems, Cybersecurity, Quality, or related technical field.
  • 10+ years of experience in product compliance, product cybersecurity, quality systems, regulatory compliance, engineering governance, or semiconductor product development.
  • 8+ years interpreting and applying product cybersecurity regulations, including the EU Cyber Resilience Act and other global product security requirements.
  • 8+ years leading enterprise or product compliance programs across multiple cross-functional organizations and global locations.
  • 8+ years implementing secure product development lifecycle (Secure SDLC), product cybersecurity risk management, vulnerability management, and software component governance (SBOM/open-source governance).
  • 8+ years managing product lifecycle governance processes including NPI, requirements management, configuration/change management, release governance, audit readiness, and compliance evidence management.
  • 8+ years partnering with executive leadership, engineering, legal, quality, and product teams to drive compliance initiatives and influence technical decisions without direct authority.
  • 8+ years leading complex cross-functional programs requiring executive-level communication, stakeholder management, facilitation, and senior leadership presentation.
  • Experience within the FPGA, semiconductor, embedded systems, electronics, automotive, aerospace, defense, industrial, or technology industries.
  • Experience with semiconductor hardware, embedded firmware, software development tools, intellectual property, reference designs, or complex product ecosystems.
  • Working knowledge of applicable standards and frameworks (IEC 62443, ISO/SAE 21434, ISO/IEC 27001, ISO 9001, AS9100, ISO 26262, IEC 61508, NIST frameworks, Common Criteria).
  • Experience with Software Bill of Materials, third-party/open-source software governance, vulnerability-disclosure programs, product security incident response, or cybersecurity conformity assessment.
  • Experience supporting CE marking, EU product regulations, technical-file development, declarations of conformity, or market-surveillance activities.

Altera (altera.com) Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Altera (altera.com) and has not been reviewed or approved by Altera (altera.com).

  • Retirement Support Feedback suggests retirement programs are robust, with offerings such as a 401(k) and a pension. This breadth supports long-term financial security.
  • Leave & Time Off Breadth Feedback suggests time-off policies are generous, including PTO, paid sick days, and paid holidays. Wellness initiatives like gym memberships further support balance.
  • Parental & Family Support Feedback suggests parental leave is generous. Family-building support, including fertility benefits and adoption reimbursement, is highlighted as part of the package.

Altera (altera.com) Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Jose, California
1,612 Employees
Year Founded: 1983

What We Do

Altera: Accelerating Innovators Altera provides leadership programmable solutions that are easy-to-use and deploy in applications from cloud to edge, offering limitless AI possibilities. Our end-to-end broad portfolio of products including FPGAs, CPLDs, Intellectual Property, development tools, System on Modules, SmartNICs and IPUs provide the flexibility to accelerate innovation. Altera is helping to shape the future through pioneering innovation that unlocks extraordinary possibilities for everyone on the planet.

Similar Jobs

General Motors Logo General Motors

Senior Software Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Hybrid
Sunnyvale, CA, USA
165000 Employees
129K-198K Annually

General Motors Logo General Motors

Staff Software Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Hybrid
2 Locations
165000 Employees
172K-300K Annually

General Motors Logo General Motors

Software Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Hybrid
Sunnyvale, CA, USA
165000 Employees
123K-190K Annually

General Motors Logo General Motors

Site Reliability Engineer

Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Hybrid
2 Locations
165000 Employees
172K-300K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account