As a Cybersecurity Engineer, you will be responsible for designing, implementing, and validating security features for embedded devices with web-based interfaces. You will work closely with software, firmware, and hardware teams to ensure our products are resilient against attacks while maintaining performance and usability.
Requirements:
- Assess and mitigate security risks in embedded systems with web interfaces.
- Develop and implement secure boot, firmware signing, and update mechanisms.
- Harden embedded Linux, RTOS, and bare-metal environments against cyber threats.
- Analyze and secure web-based management interfaces for embedded devices.
- Conduct threat modeling, penetration testing, and vulnerability assessments.
- Implement cryptographic protocols, secure communication (TLS, SSH, MQTT, etc.), and authentication mechanisms.
- Ensure compliance with global and EU security standards such as NIST, ISO 27001, IEC 62443, FIPS 140-2 and 140-3, up to “Level 3”, ETSI EN 303 645, and EU Cybersecurity Act.
- Collaborate with software and hardware teams to integrate security best practices.
- Monitor emerging threats and contribute to security incident response.
Desirable Skills and Experience:
- Strong understanding of web security (OWASP Top 10, CSRF, XSS, SQL Injection, etc.).
- Experience with secure firmware development and update mechanisms.
- Proficiency in C, C++, Python, and embedded Linux security tools.
- Knowledge of secure networking protocols (TLS, DTLS, VPN, Zero Trust architectures, etc.).
- Hands-on experience with penetration testing, fuzzing, and security hardening.
- Familiarity with EU cybersecurity regulations and compliance frameworks such as ETSI EN 303 645, GDPR security requirements, and the EU Cyber Resilience Act.
- Experience with IoT security frameworks and threat modeling.
- Familiarity with container security (Docker, Podman) and runtime protection.
- Understanding of hardware security features (TPM, HSM, ARM TrustZone, Secure Enclaves, etc.).
- Contributions to open-source security tools or published research in cybersecurity.
- Security certifications (e.g., CISSP, OSCP, CEH, GIAC, or similar).
Required Education and Experience:
- BS/MS in Cybersecurity, Computer Science, Electrical Engineering, or related field.
- 5+ years of experience in embedded security, cybersecurity engineering, or related roles.
This is a full-time position with competitive pay and benefits. The base salary for this position is $131,961 – 219,507. This range reflects base salary only, and does not include additional compensation or benefits. Individual base pay is determined by various factors such as relevant experience, education, training and skills, and the scope and responsibilities of the position.
Email resumes to: jobs@aja.com