The mission of Complear is to build the AI-native compliance infrastructure that becomes the operating system for safety- and security-critical products around the world — the verification layer that turns innovation into market access.
We want to make it easy for teams building medical devices, aircraft and space systems, autonomous vehicles and defence platforms to become compliant from day 1, while driving business strategy decisions supported by solid regulatory information. Our platform, Complear OS, replaces document silos and manual audits with real-time verification embedded directly into the development lifecycle, so companies can enter the market faster and stay aligned with regulations that never stop evolving — from the Cyber Resilience Act, NIS2 and DORA to TISAX, ISO/IEC 27001 and GDPR.
As an AppSec and GRC Engineer you own client security and compliance engagements end to end: understanding a client's products, risks and regulatory exposure, designing the program that gets them compliant, and staying with them until it holds up in an audit. You are the person the client calls, and the person our product team listens to about what security and compliance really demand.
One idea runs through the whole job: every engagement should make the product smarter. For the client, you lead gap assessments, risk analyses and threat modeling workshops, map their products and processes to the Cyber Resilience Act (CRA), NIS2, DORA, TISAX, GDPR and sector-specific standards, and build the remediation roadmap, policies and controls that close the gaps. For Complear OS, you turn what you see across engagements into security requirements and control frameworks our product team can automate and scale — so a control you design for one client can be checked continuously for all of them.
This is a client- and advisory-focused role, not a heads-down developer role. Most of your time goes to understanding a client's reality, advising on secure design and incident response readiness, preparing them for audits and certifications, and guiding what our product team builds next. The technical slice is real but different in shape from an engineering job: reviewing architectures, challenging threat models and assessment results, reading SAST/DAST, SBOM and vulnerability reports critically, and knowing when a control that looks compliant on paper won't work in practice. That last skill is the scarce one.
The Cyber Resilience Act changes the game for every manufacturer placing products with digital elements on the EU market. Secure-by-design requirements, vulnerability handling, SBOMs and incident reporting are becoming legal obligations across the product lifecycle, and most companies don't yet know what that means for how they build, ship and maintain their products. Helping them get there — and shaping the infrastructure that keeps them there — is at the heart of this role.
We are looking for people who can lead client engagements with a high degree of autonomy, but who are eager learners and gather every kind of input before forming an opinion on a risk call. As the company grows, your scope grows with it.
If sitting with a client until their real risk is on the table, mapping a regulation clause by clause into controls their teams can actually implement, walking into an audit knowing the evidence is there, and shaping a product that makes all of this easier for the next client would make your day, then this job is for you.
You will learn the security and regulatory requirements of the most demanding sectors (CRA, NIS2, DORA, TISAX, ISO/IEC 27001, GDPR, and the standards specific to defence and critical infrastructure) and help clients turn them into a competitive advantage. While we deploy our product, you'll be immersed in the operational realities of regulated industries — every day is a day to learn from the best.
We offer a competitive salary, flexible working hours, and a vital role in making safety- and security-critical technology trustworthy. Our company is based in Portugal, but we work fully remote, so you can live anywhere in the world. Our team gathers often to eat well and work together.
ExpectationsLearn every day. We don't expect you to know every regulation, every standard, or every client's industry. We expect you to be eager to learn whatever a successful engagement requires. You won't be alone: our core team and our network of security experts are there for you.
Own the client, end to end. You lead security and compliance engagements from scoping to delivery — gap assessments, risk analyses, remediation roadmaps, audit and certification readiness. You are accountable for the outcome the client bought, not for a list of findings.
Start with the risk, not the checklist. Clients arrive asking for a certificate or a policy; the job is to find the product, process, or supply-chain risk underneath it. Threat modeling workshops and architecture reviews come before paperwork.
Turn regulation into controls. You map client products and organizations to the CRA, NIS2, DORA, TISAX, GDPR and sector-specific standards, and design the policies and controls that close the gaps. Every control should be something an engineering team can implement and an auditor can verify.
Advise with evidence. You are the trusted security voice for client and internal teams on secure design, secure development practices, vulnerability management and incident response readiness. When something needs to change, you say so — and show why.
Keep the evidence audit-ready. You help clients monitor and improve their security posture and prepare the evidence that audits and certifications require — captured as the work happens, never reconstructed after the fact.
Be the two-way channel to product. You are the face of our security expertise to clients, and the voice of clients inside our product team. You define the security requirements and control frameworks Complear OS automates, help prioritize what gets built, and verify that what ships actually meets the regulatory bar. What you learn on an engagement should change what we build next; you'll be expected to say so, with evidence.
Be part of an exciting team building the compliance infrastructure for the cyber-physical economy. We are a startup in the fast-paced world of enterprise tech, working as both expert consultants and product builders. This is the future, and our team is already part of it.
Excellent for a security and compliance consultant who wants their expertise to scale beyond one client at a time — into a product the most demanding industries rely on.
Cybersecurity Manager / Information Security Manager
Day Translations
Staff Parser/Compiler Research Engineer
dottxt
Senior Software Engineer (Node.js/Python)
Opinov8
Staff Rust Developer
dottxt
Unity Technical Artist, Event Pipeline
VRChat
platform eng databricks
quantori