обновлено 1 месяц назад
Principal Embedded Security Vulnerability Analyst (Embedded Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Embedded Security Vulnerability Analyst (Embedded Security): Leading deep vulnerability analysis of embedded software, boot flows, privilege boundaries, and security-critical components with an accent on low-level systems, exploitability assessment, and security certification strategies. Focus on building scalable static and dynamic analysis, fuzzing, and AI-assisted agentic workflows while translating findings into systemic architectural mitigations.
Location: Gratkorn, Austria
Company
develops security-critical semiconductor and embedded system technologies.
What you will do
- Lead in-depth vulnerability analysis of bare-metal software, RTOS components, trusted execution environments, boot flows, and privilege boundaries.
- Investigate security-critical components such as cryptographic libraries, key-handling mechanisms, and isolation systems.
- Own root cause analysis, exploitability assessment, and evaluation of systemic impact.
- Define security evaluation strategies for PSA, SESIP, Common Criteria, and related certifications.
- Architect scalable analysis methodologies and tooling using static analysis, dynamic analysis, fuzzing, automation, and AI-assisted workflows.
- Lead PSIRT incident analysis, influence product architecture, and mentor engineers in vulnerability research methods.
Requirements
- Degree in Electrical Engineering, Computer Science, Mathematics, or a related field, or equivalent practical experience.
- Expert understanding of low-level system behavior, including memory layout, interrupts, privilege levels, and concurrency.
- Extensive C programming experience and strong familiarity with ARM and/or RISC-V architectures.
- Strong experience with assembly-level debugging and low-level system analysis.
- Ability to lead complex technical investigations, communicate security risks clearly, influence technical direction, and mentor engineers.
- Security-related work may fall within the scope of security certifications and requires a conscious, reliable working approach.
Nice to have
- Experience in vulnerability research, reverse engineering, exploit development, static or dynamic analysis, fuzzing, or symbolic execution.
- Knowledge of memory corruption, logic flaws, side channels, and exploitation techniques.
- Experience with JTAG, trace, GDB, scalable analysis pipelines, distributed systems, or agent-based approaches.
- Experience operationalizing AI-assisted vulnerability discovery tools and workflows.
- Rust experience or a strong interest in memory-safe system design.
Culture & Benefits
- Opportunity to influence the security architecture of next-generation products and silicon.
- Collaboration across hardware, firmware, and applied security research.
- Environment focused on deep technical expertise and offensive security thinking.
- Home office options and flexible working time.
- Market-competitive compensation benchmarked against the Austrian electronics and semiconductor industry, plus meal benefits and other employee benefits.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →