Job
- Level
- Erfahren
- Job Feld
- IT, Embedded, Security
- Anstellung
- Vollzeit
- Vertragsart
- Unbefristetes Dienstverhältnis
- Ort
- München
- Arbeitsmodell
- Onsite
Job Zusammenfassung
In dieser Position entwirfst und implementierst du sichere Architekturen für eingebettete Produkte und Netzgeräte, führst Bedrohungsmodellierungen sowie Risikoanalysen durch und unterstützt bei der Einhaltung von Sicherheitsstandards.
Job Technologien
Deine Rolle im Team
- Design and implement secure architectures for embedded products and networked devices.
- Perform threat modeling and risk analysis using frameworks such as STRIDE.
- Write security manuals for customers.
- Enforce and support secure coding practices for C/C++ and Python.
- Support implement secure boot, firmware integrity checks, and hardware root of trust.
- Support configure and harden Linux-based operating systems.
- Help conduct vulnerability assessments, penetration testing, and integrate security into CI/CD pipelines.
- Ensure compliance with IEC 62443 (4-1 and 4-2) and ISO 27001 standards.
- Collaborate with cross-functional teams to communicate risks and propose mitigations.
Unsere Erwartungen an dich
Qualifikationen
- The searched candidate will have strong technical knowledge in secure architecture, cryptography, and compliance standards, combined with good communication and problem-solving skills.
- Cryptography: Symmetric & asymmetric encryption (AES, RSA, ECC), key management, hashing algorithms (SHA-2, SHA-3), HMAC.
- Public Key Infrastructure (PKI).
- Secure Architecture & Design: Threat modeling, risk analysis, secure boot, firmware integrity, hardware root of trust.
- Implementation: Linux hardening, secure configuration of services (SSH, firewall, etc.).
- Vulnerability Assessment & Testing: Static/dynamic code analysis tools (like Coverity, BlackDuck), fuzzing, web UI security testing, CI/CD security integration.
- Standards & Compliance: IEC 62443, ISO 27001 basics.
- Soft Skills: Ability to work autonomously and manage priorities effectively.
- Strong communication skills for internal and external stakeholders.
- Proficiency in English (written and spoken).
Erfahrung
- Work Experience: Network & Communication Security: TCP/IP, UDP protocols (MQTT, SFTP, FTPS, HTTPS, NTPS, RTP, DHCP, DNS, etc.), TLS/SSL implementation.
Benefits
Gesundheit, Fitness & Fun
Mehr Netto
Work-Life-Integration
Essen & Trinken
Themen mit denen du dich im Job beschäftigst
Job Standorte
Das ist dein Arbeitgeber
QuEST GLOBAL
QuEST Global zählt zu den globalen, zuverlässigen und langfristigen Partnern von zahlreichen Unternehmen in den Bereichen: Transportation, Aerospace & Defence, Aero Engines, Industrial & Hi-Tech, Medical Devices, Oil & Gas und Power.
Description
- Gründungsjahr
- 1997
- Unternehmenstyp
- Etablierte Firma
- Arbeitsmodell
- Onsite
- Branche
- Internet, IT, Telekom