Job
- Level
- Experienced
- Job Field
- IT, Embedded, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Location
- Munich
- Working Model
- Onsite
Job Summary
In this role, you design and implement secure architectures for embedded products and networked devices, perform threat modeling and risk analyses, and ensure compliance with security standards.
Job Technologies
Your role in the team
- Design and implement secure architectures for embedded products and networked devices.
- Perform threat modeling and risk analysis using frameworks such as STRIDE.
- Write security manuals for customers.
- Enforce and support secure coding practices for C/C++ and Python.
- Support implementing secure boot, firmware integrity checks, and hardware root of trust.
- Support configuring and hardening Linux-based operating systems.
- Help conduct vulnerability assessments, penetration testing, and integrate security into CI/CD pipelines.
- Ensure compliance with IEC 62443 (4-1 and 4-2) and ISO 27001 standards.
- Collaborate with cross-functional teams to communicate risks and propose mitigations.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- The searched candidate will have strong technical knowledge in secure architecture, cryptography, and compliance standards, combined with good communication and problem-solving skills.
- Cryptography: Symmetric & asymmetric encryption (AES, RSA, ECC), key management, hashing algorithms (SHA-2, SHA-3), HMAC.
- Public Key Infrastructure (PKI).
- Secure Architecture & Design: Threat modeling, risk analysis, secure boot, firmware integrity, hardware root of trust.
- Implementation: Linux hardening, secure configuration of services (SSH, firewall, etc.).
- Vulnerability Assessment & Testing: Static/dynamic code analysis tools (like Coverity, BlackDuck), fuzzing, web UI security testing, CI/CD security integration.
- Standards & Compliance: IEC 62443, ISO 27001 basics.
- Soft Skills: Ability to work autonomously and manage priorities effectively.
- Strong communication skills for internal and external stakeholders.
- Proficiency in English (written and spoken).
Experience
- Work Experience: Network & Communication Security: TCP/IP, UDP protocols (MQTT, SFTP, FTPS, HTTPS, NTP, RTP, DHCP, DNS, etc.), TLS/SSL implementation.
This text has been machine translated. Show original
Benefits
Health, Fitness & Fun
More net
Work-Life-Integration
Food & Drink
Topics that you deal with on the job
Job Locations
This is your employer
QuEST GLOBAL
QuEST Global is one of the global, reliable and long-term partners of numerous companies in the fields of: Transportation, Aerospace & Defence, Aero Engines, Industrial & Hi-Tech, Medical Devices, Oil & Gas and Power.
Description
- Founding year
- 1997
- Company Type
- Established Company
- Working Model
- Onsite
- Industry
- Internet, IT, Telecommunication