Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics

Riederich

Vor Ort

EUR 75.000 - 110.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

NEURA Robotics is seeking a Systems Security Engineer to secure cloud-native platforms, perform threat modeling, and lead secure architecture reviews across microservices and AI/ML pipelines.

You will own AppSec tooling (SAST/DAST/SCA), manage vulnerability remediation, and contribute to NIS2 compliance and incident response workflows within a highly collaborative robotics environment.

Qualifikationen

  • Degree in Computer Science, Cybersecurity, or Software Engineering.
  • Hands-on experience with cloud security and DevSecOps tooling.

Aufgaben

  • Secure cloud-native platforms (AWS) with least-privilege IAM and network segmentation.
  • Operate SAST/DAST/SCA tooling and container/IaC scanning in CI/CD.
  • Conduct STRIDE threat modeling across microservices and AI/ML pipelines.
  • Lead secure architecture reviews for cloud-native and AI-adjacent systems.
  • Support NIS2 compliance and incident response workflows with proper documentation.

Kenntnisse

Python/Bash
Container security
Kubernetes security
IaC security scanning
AWS security tooling
SAST/DAST tooling
Threat modeling
Security architecture

Ausbildung

Bachelors in CS/Cybersecurity/Software Eng

Tools

Semgrep
SonarQube
ZAP/Burp
GitLab CI/CD
SageMaker/Triton/ONNX security

Jobbeschreibung

Our Systems Engineering Department turns market demands into safe, certifiable, and competitive robot systems — spanning software, hardware, safety, and certification. Join us to shape the next generation of human-robot systems and find extraordinary opportunities at the intersection of security, compliance, and cutting-edge robotics.

Your Mission & Challenges
  • Secure Cloud-Native Platforms: Secure cloud-native platforms (AWS EKS, Lambda, API Gateway, IoT Core, S3) via least-privilege IAM, network segmentation, secrets management, and policy-as-code (Terraform/AWS Organizations).
  • Own the AppSec Toolchain: Operate SAST (Semgrep/SonarQube), DAST (ZAP/Burp), SCA, and container/IaC scanning in GitLab CI/CD; extend coverage to Kubernetes manifests and supply chain.
  • Drive Vulnerability Management: Run risk-based vulnerability management: CVSS + exploitability rating, SLA-driven remediation tracking, and structured closure evidence for internal KPIs and regulatory reporting.
  • Perform Threat Modeling: Conduct STRIDE threat modeling across microservices, edge, and AI/ML inference pipelines; translate findings into architecture decisions.
  • Support NIS2 Compliance: Own NIS2 Art. 21 measure documentation, incident notification workflows (24h/72h), and supply-chain security assessments for cloud dependencies.
  • Define Secure Coding Standards: Define and enforce secure coding and API standards (Python, TypeScript, C++; OAuth2/OIDC, JWT) and deliver developer-oriented remediation guidance embedded in engineering workflows.
  • Lead Secure Architecture Reviews: Lead secure architecture reviews for cloud-native and AI-adjacent systems; assess AI/ML pipeline security controls (SageMaker, Triton, ONNX) and model supply chain risks.
  • Bridge to Embedded Security: Align cloud threat models and security controls with the embedded cybersecurity team to maintain end-to-end integrity from robot controller to cloud backend.
What We Can Look Forward To
  • Education & Certification: Degree in Computer Science, Cybersecurity, or Software Engineering; OSCP or AWS Security Specialty is a differentiator.
  • Track Record: 3–5 years in application or cloud security with demonstrated ownership of AppSec tooling and vuln management in a product environment — not advisory only.
  • Security Fundamentals: Hands-on command of OWASP Top 10/ASVS, cloud security posture (AWS preferred), and DevSecOps tooling (SAST, DAST, SCA) — not just theoretical.
  • Vulnerability Management Process: Proven vuln management lifecycle: CVSS + exploitability triage, SLA-driven closure, and audit-ready documentation.
  • Regulatory Familiarity: Working knowledge of NIS2, EU CRA, ISO 27001, or IEC 62443; able to translate findings into compliance documentation for internal governance and external audit.
  • Technical Skills: Python/Bash proficiency; hands-on with container and Kubernetes security, IaC scanning, and AWS governance tooling (Config, SCPs, GuardDuty).
  • AI/ML Pipeline Exposure: Exposure to AI/ML pipeline security (SageMaker, Triton, ONNX) and model supply chain risks is a significant differentiator.
  • Collaboration & Communication: Communicates security risk clearly to engineering and management; written outputs audit-ready. Interfaces effectively with embedded security, certification, and external auditors.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

DevSecOps Engineer
DevSecOps Engineer

Jobtailor • Deutschland

Remote
EUR 90.000 - 140.000
Senior Security Architect (Human)
Senior Security Architect (Human)

Neura Robotics GmbH • Deutschland

Vor Ort
EUR 90.000 - 130.000
Senior Manager, Information Security Architecture – Engineering
Senior Manager, Information Security Architecture – Engineering

Jobtailor • Deutschland

Remote
EUR 120.000 - 150.000
Security Engineer
Security Engineer

Jobtailor • Deutschland

Vor Ort
EUR 80.000 - 110.000
Senior Security Architect
Senior Security Architect

Jobtailor • Deutschland

Remote
EUR 90.000 - 130.000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Jobtailor • Deutschland

Vor Ort
EUR 75.000 - 105.000
Global Product Cyber Security Expert – R&D Digital Portfolio
Global Product Cyber Security Expert – R&D Digital Portfolio

Jobtailor • Mannheim

Vor Ort
EUR 110.000 - 150.000
Senior Cloud Security Architect – Terraform
Senior Cloud Security Architect – Terraform

Jobtailor • Deutschland

Hybrid
EUR 90.000 - 130.000
IS Principal Security Architect
IS Principal Security Architect

Jobtailor • Deutschland

Hybrid
EUR 130.000 - 190.000
Cloud Security Engineer
Cloud Security Engineer

Jobtailor • Deutschland

Vor Ort
EUR 90.000 - 130.000
Security training