Cybersecurity Engineer - Cloud, Ops (human)

NEURA Robotics

Riederich

Vor Ort

EUR 80.000 - 120.000

Vollzeit

Vor 2 Tagen
Sei unter den ersten Bewerbenden

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

NEURA Robotics is seeking a Senior Application Security Engineer to turn cloud-native security into actionable controls across software, hardware, and AI/ML pipelines. You will own the AppSec toolchain, drive vulnerability management, and shape cloud security architecture.

You will conduct STRIDE threat modeling, enforce secure coding standards, and align cloud threat models with embedded security teams, ensuring NIS2 compliance and audit-ready documentation.

Qualifikationen

  • 3–5 years in application or cloud security with ownership of AppSec tooling and vulnerability management in a product environment.
  • Hands-on knowledge of OWASP Top 10/ASVS and cloud security posture.
  • Experience with NIS2, EU CRA, ISO 27001, or IEC 62443 compliance and audit-ready documentation.

Aufgaben

  • Secure cloud-native platforms and IaC pipelines with least-privilege IAM and policy-as-code.
  • Own the AppSec toolchain and extend coverage to CI/CD and Kubernetes manifests.
  • Lead vulnerability management, CVSS triage, and remediation tracking.
  • Perform STRIDE threat modeling across microservices and AI/ML pipelines.
  • Ensure NIS2 compliance and incident response workflows; coordinate with auditors.
  • Define secure coding standards (Python, Bash, TypeScript, C++) and embeddings in workflows.
  • Lead secure architecture reviews for cloud-native and AI-adjacent systems; assess model supply chain risks.
  • Bridge cloud threat models with embedded security teams for end-to-end integrity.

Kenntnisse

AppSec tooling ownership
Threat modeling STRIDE
Cloud security
Kubernetes security
SAST/DAST/SCA tooling
AWS security tooling

Ausbildung

Degree in Computer Science, Cybersecurity, or Software Engineering

Tools

SAST (Semgrep/SonarQube)
DAST (ZAP/Burp)
SCA
Terraform
AWS Config
GuardDuty

Jobbeschreibung

Our Systems Engineering Department turns market demands into safe, certifiable, and competitive robot systems — spanning software, hardware, safety, and certification. Join us to shape the next generation of human-robot systems and find extraordinary opportunities at the intersection of security, compliance, and cutting-edge robotics.

Your Mission & Challenges
  • Secure Cloud-Native Platforms: Secure cloud-native platforms (AWS EKS, Lambda, API Gateway, IoT Core, S3) via least-privilege IAM, network segmentation, secrets management, and policy-as-code (Terraform/AWS Organizations).
  • Own the AppSec Toolchain: Operate SAST (Semgrep/SonarQube), DAST (ZAP/Burp), SCA, and container/IaC scanning in GitLab CI/CD; extend coverage to Kubernetes manifests and supply chain.
  • Drive Vulnerability Management: Run risk-based vulnerability management: CVSS + exploitability rating, SLA-driven remediation tracking, and structured closure evidence for internal KPIs and regulatory reporting.
  • Perform Threat Modeling: Conduct STRIDE threat modeling across microservices, edge, and AI/ML inference pipelines; translate findings into architecture decisions.
  • Support NIS2 Compliance: Own NIS2 Art. 21 measure documentation, incident notification workflows (24h/72h), and supply-chain security assessments for cloud dependencies.
  • Define Secure Coding Standards: Define and enforce secure coding and API standards (Python, TypeScript, C++; OAuth2/OIDC, JWT) and deliver developer-oriented remediation guidance embedded in engineering workflows.
  • Lead Secure Architecture Reviews: Lead secure architecture reviews for cloud-native and AI-adjacent systems; assess AI/ML pipeline security controls (SageMaker, Triton, ONNX) and model supply chain risks.
  • Bridge to Embedded Security: Align cloud threat models and security controls with the embedded cybersecurity team to maintain end-to-end integrity from robot controller to cloud backend.
What We Can Look Forward To
  • Education & Certification: Degree in Computer Science, Cybersecurity, or Software Engineering; OSCP or AWS Security Specialty is a differentiator.
  • Track Record: 3–5 years in application or cloud security with demonstrated ownership of AppSec tooling and vuln management in a product environment — not advisory only.
  • Security Fundamentals: Hands-on command of OWASP Top 10/ASVS, cloud security posture (AWS preferred), and DevSecOps tooling (SAST, DAST, SCA) — not just theoretical.
  • Vulnerability Management Process: Proven vuln management lifecycle: CVSS + exploitability triage, SLA-driven closure, and audit-ready documentation.
  • Regulatory Familiarity: Working knowledge of NIS2, EU CRA, ISO 27001, or IEC 62443; able to translate findings into compliance documentation for internal governance and external audit.
  • Technical Skills: Python/Bash proficiency; hands-on with container and Kubernetes security, IaC scanning, and AWS governance tooling (Config, SCPs, GuardDuty).
  • AI/ML Pipeline Exposure: Exposure to AI/ML pipeline security (SageMaker, Triton, ONNX) and model supply chain risks is a significant differentiator.
  • Collaboration & Communication: Communicates security risk clearly to engineering and management; written outputs audit-ready. Interfaces effectively with embedded security, certification, and external auditors.
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Senior Security Architect (Human)
Senior Security Architect (Human)

Neura Robotics GmbH • Deutschland

Vor Ort
EUR 90.000 - 130.000
Security Engineer
Security Engineer

Jobtorob • Deutschland

Vor Ort
USD 80.000 - 120.000
Creative Freedom and Agility
Attractive Compensation
Professional Growth
+2
Senior Security Engineer – Cloud Security
Senior Security Engineer – Cloud Security

Jobtailor • Deutschland

Hybrid
EUR 90.000 - 130.000
Cybersecurity Engineer
Cybersecurity Engineer

Leonardo • Darmstadt

Hybrid
EUR 50.000 - 70.000
Application Security & VIPR Expert
Application Security & VIPR Expert

Armis • Deutschland

Vor Ort
EUR 120.000 - 160.000
Senior Network Security Engineer
Senior Network Security Engineer

Alexander Daniels Global • Berlin

Vor Ort
EUR 90.000 - 150.000
VSOP / equity participation
Modern Berlin office location
Monthly vouchers
+2
Senior Cloud Security Engineer
Senior Cloud Security Engineer

EngineersOfAI • Berlin

Vor Ort
EUR 90.000 - 140.000
Senior Product Security Engineer
Senior Product Security Engineer

LanceDB • Deutschland

Remote
EUR 80.000 - 110.000
Security Solutions Architect
Security Solutions Architect

https:/www.scheurer.org/careers/ • Deutschland

Remote
EUR 70.000 - 100.000
Sr./Staff Security Engineer
Sr./Staff Security Engineer

Oscilar • Deutschland

Remote
EUR 80.000 - 110.000
100% Medical/Dental for you and dependents
Stock options
Caju Card for monthly meal allowance
+2