Altera
Cyber Resilience Act (CRA) Compliance Lead
San Jose, California, United States · Senior
Stay score
odds of building a lasting career here
Sponsors, but it's cap-subject — you still face the weighted lottery (~61% per draw at Level IV). Good if you win; have a cap-exempt backup on your list.
Lottery odds assume a STEM candidate.
Personalize to your clock →Employer immigration record
from this employer's Department of Labor filings
Green-card intent detected
Files H-1B transfers
Sourced from Department of Labor LCA, PERM and prevailing-wage disclosure data. Employer matching is by name, so figures may be split across an employer's legal entities. Absence of a filing means none appears in our copy of the data, not that none exists.
Community outcomes
No reports yet — be the first to help the next applicant.
About the role
- At Altera™, our independence as the world's largest pure ‑ play FPGA solutions provider gives us the focus, speed, and agility to innovate without compromise.
- This is a senior role requiring strong knowledge of product cybersecurity regulations, semiconductor and embedded-product lifecycles, quality management systems, risk management, regulatory conformity, and cross-functional program execution.
Responsibilities
- Maintain the enterprise CRA compliance framework, governance model, policies, procedures, roles, responsibilities, and decision authorities.
- Establish traceability model between CRA requirements, cybersecurity risks, product requirements, design controls, verification activities, technical documentation, and conformity evidence.
- Partner with cross functional organization to determine product classification, critical-product applicability, conformity assessment pathways and regulatory obligations.
- Support integration of CRA requirements into product requirement management, product lifecycle management, configuration management, change control, and release-management systems.
- Define and drive CRA compliance check and evidence requirements for product concept, architecture, design, implementation, verification, validation, release, production, maintenance, and end-of-support stages.
- Partner with product security on vulnerability escalation, product non-conformity management and external communication
Requirements
- Bachelor's degree in Engineering, Computer Science, Information Systems, Cybersecurity, Quality, or a related technical field.
- 10+ years of experience in product compliance, product cybersecurity, quality systems, regulatory compliance, engineering governance, semiconductor product development, or related technical disciplines.
- 8+ years of experience interpreting and applying product cybersecurity regulations, including the EU Cyber Resilience Act (CRA) and other applicable global product security regulatory requirements.
- We use artificial intelligence to screen, assess, or select applicants for the position. Applicants must be eligible for any required U.S. export authorizations.
- Applicants must be eligible for any required U.S. export authorizations.
- 8+ years of experience leading enterprise or product compliance programs across multiple cross-functional organizations and global geographic locations.
- 8+ years of experience implementing secure product development lifecycle (Secure SDLC) processes, product cybersecurity risk management, vulnerability management, software component governance (SBOM/open-source governance), and post-market product security compliance.
- 8+ years of experience managing product lifecycle governance processes, including New Product Introduction (NPI), requirements management, configuration management, engineering change management, product release governance, audit readiness, and compliance evidence management.
- 8+ years of experience partnering with executive leadership, engineering, legal, quality, security, and product management teams to drive compliance initiatives and influence technical decisions without direct management authority.
- 8+ years of experience leading complex cross-functional programs requiring executive-level communication, data-driven decision making, stakeholder management, facilitation, and presentation of compliance strategies, risks, and program status to senior leadership.
Nice to have
- Experience within the FPGA, semiconductor, embedded systems, electronics, automotive, aerospace, defense, industrial, or technology industries.
- Experience with semiconductor hardware, embedded firmware, software development tools, intellectual property, reference designs, or complex product ecosystems.
- Working knowledge of applicable standards and frameworks, such as:
- IEC 62443, ISO/SAE 21434, ISO/IEC 27001, ISO 9001, AS9100, ISO 26262,IEC 61508
- NIST Cybersecurity and secure software development Framework, Common Criteria or related product-security assurance frameworks
- Experience with Software Bill of Materials, 3rd party and open-source software governance, vulnerability-disclosure programs, product security incident response, or cybersecurity conformity assessment.
- Experience supporting CE marking, EU product regulations, technical-file development, declarations of conformity, or market-surveillance activities.
- Shift 1 (United States of America)
Skills
- About Altera
Compensation
- The pay range below is for Bay Area California only.
- Actual salary may vary based on a number of factors including job location, job-related knowledge, skills, experiences, trainings, etc.
- We also offer incentive opportunities that reward employees based on individual and company performance.
- $149,100 - $215,925 USD
This listing is sourced directly from Altera's careers page and normalized into a canonical job model.