security product engineer
We're preparing a cloud platform for IEC 62443-4-1 certification and we're looking for someone to lead its product security — from threat modeling through design review all the way to verification. You'll build the SDL processes from scratch and have the mandate to substantively challenge architectural decisions. You don't need to know the IEC 62443 standard — what matters to us is experience with product security; you'll get up to speed on 62443 along the way.
What Will Be Your Job
Threat modeling (STRIDE) and defining security requirements with traceability in JIRA
Security design review of the product architecture and preparation of the Security Concept
Coordinating verification activities — security requirements testing, threat mitigation testing, vulnerability testing, penetration testing
Code review process for security-critical parts of the code, SBOM and supply chain security (Dependency Track)
Running PSIRT, patch management and security advisories toward customers
SDL governance, training the team and preparing the product for the IEC 62443-4-1 certification audit
who we´re looking for
Experience defining and managing security requirements throughout software development (SDL, secure SDLC or a similar framework)
Practical knowledge of web application security (OWASP Top 10, authentication, authorization, cryptography)
Ability to communicate security topics clearly to both developers and management
WHAT WILL EARN YOU EXTRA POINTS
Knowledge of IEC 62443 (esp. 4-1 and 4-2) or experience with OT/ICS/IIoT environments
Experience with vulnerability management, CVE triage and penetration testing
Experience compiling SDL certification documentation
Knowledge of SBOM tools (Dependency Track, Syft, Grype) and DAST tools (OWASP ZAP, Burp Suite)
Experience implementing PSIRT, knowledge of NIS2 / Cyber Resilience Act, ISO/IEC 27017
Interested? Send us your CV and let’s talk! :)


