Responsibilities
• Act as the primary expert on cybersecurity regulations, including the EU Cyber Resilience Act (EU CRA), NERC CIP, SOCI and others
• Translate regulatory obligations into practical requirements for commercial product design, manufacturing, and support services
• Lead regulatory gap analyses and provide remediation guidance for product teams and compliance stakeholders
• Prepare advisory briefs for executive stakeholders regarding regulatory proposals, industry trends, and enforcement actions
• Provide subject matter expertise for high‑stakes customer‑facing regulatory discussions
• Maintain a centralized regulatory knowledge base and contribute to the development of AI‑assisted regulatory analysis tools
Requirements
• 10+ years in cybersecurity, with a focus on regulatory compliance, policy interpretation, or standards work within the industrial or energy sector
• Deep knowledge of at least two of the following: EU CRA, NERC CIP, NIS2, or IEC 62443
• Proven ability to interpret complex legal texts and translate them into actionable engineering and commercial guidance
• 10+ years of experience with operational technology, IC… SCADA, or industrial energy management systems
• Exceptional ability to produce authoritative documentation and executive‑level briefings
• Bachelor's degree in Cybersecurity, Engineering, Computer Science, Law, or a related discipline
• Active participation in industry regulatory bodies (preferred)
• Experience with EU product certification or conformity assessments (preferred)
• Professional certifications (e.g., GICSP, CISSP, CISM, ISA/IEC 62443) (preferred)
• Advanced degree (JD, LL.M., or Master's in Cybersecurity, Engineering, or Policy) (preferred)