About the role
From December 2027, products with digital elements sold in the EU must meet the essential requirements of the Cyber Resilience Act. Machine builders, medical device makers and consumer electronics firms around Munich are preparing now. This role works with their engineering teams. You run threat modelling for devices and their back ends, define security requirements for hardware and firmware, and prepare the technical documentation needed for conformity assessment. You work with our supply-chain and DevSecOps colleagues.
What you will do
- Run threat modelling and risk assessments for connected devices, gateways and companion apps
- Define requirements for secure boot, firmware signing, secure update and key provisioning
- Review hardware and firmware designs with client engineering teams
- Prepare CRA technical documentation, vulnerability handling processes and SBOM practices
- Advise on relevant standards such as IEC 62443-4-1/4-2, ETSI EN 303 645 and EN 18031
What you bring
- 6+ years in embedded systems development or product security
- Good knowledge of microcontroller and embedded Linux platforms
- Experience with secure elements, TPMs or hardware security modules
- Understanding of applied cryptography for device identity and updates
- Degree in electrical engineering, computer engineering or a comparable field
Good to have
- Experience with medical device security under MDR or FDA guidance
- Knowledge of the Radio Equipment Directive delegated act
Languages
English (C1), German (B1) an advantage