Location: Remote-friendly (Germany-based preferred, occasional on-site time appreciated)
Employment type: Full-time
About the Role
On behalf of our client, a growing IoT hardware company building connected smart home products that combine embedded devices, mobile apps, and cloud infrastructure, we're looking for their first-ever dedicated product security hire. This is a true opportunity to build the security function from the ground up.
Our client is seeking a senior, hands-on professional for a role with broad scope: acting as a security overlay across their development teams (no dedicated security team exists yet), setting the secure-by-design foundation for everything from RF communication and embedded firmware to cloud APIs and infrastructure, working closely with a strong development team.
What You'll Do
- Act as the go-to security expert across both embedded/firmware and cloud/API domains, an unusually broad remit by design
- Drive secure-by-design practices across teams building wireless-connected hardware, mobile apps, and cloud services
- Lead threat modeling and security risk assessments for existing and new system architectures, including for products that haven't had formal threat modeling before
- Own the company's approach to CRA and NIS2 compliance: translate regulatory requirements into concrete technical and organizational guidelines, and help formalize documentation that today exists mostly as tribal knowledge
- Assess and guide the use of wireless communication protocols, cryptographic implementations, and secure boot/firmware update practices
- Oversee (not necessarily perform) penetration testing and vulnerability assessments, ensuring findings are understood, prioritized, and remediated
- Introduce and mature security tooling: SAST, SCA, dependency and container scanning, secret detection, SBOM automation, and vulnerability management, tooling choices are not fixed, and this person will help shape them
- Standardize security practices across teams that originated from different companies and currently work in somewhat different ways
- Advise and upskill developers who are sharp and security-conscious, but don't yet have deep security expertise
- Spend the first months assessing current maturity, identifying the biggest gaps, and setting priorities accordingly
What You Bring
- Several years of hands-on experience in product/application security, covering embedded systems, firmware, or IoT, plus cloud/API security
- Solid understanding of wireless communication security, cryptography, and secure firmware/update mechanisms
- Practical experience with CRA, NIS2, or comparable regulatory frameworks, and the ability to turn them into engineering requirements
- Real threat modeling and architecture risk assessment experience
- Familiarity with security tooling: SAST, SCA, dependency/container scanning, secret detection
- A secure-by-design mindset that goes beyond compliance checklists, genuine care about products being secure, not just documented as secure
- Strong communication skills: comfortable working closely with multiple development teams and translating security concepts for technical and non-technical audiences
- Ability to still write code and engage technically with developers, this isn't a pure governance/audit role
- Comfort with ambiguity: tooling, process, and even parts of the role itself are still being defined
What's On Offer
- A genuine greenfield opportunity to shape a security function and culture from scratch
- Remote-friendly setup with flexibility on where the person is based within Germany
- An ambitious team with a start up feel, still actively shaping how they want to work together
- Real influence: this role reports closely to leadership and has genuine air cover to drive change