Назад
Company hidden
11 часов назад

Application Security Engineer (Cloud & Robotics)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Germany
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Engineer (Cloud & Robotics): Securing cloud-native robot platforms and AI/ML inference pipelines with an accent on AppSec tooling, vulnerability management, and regulatory compliance. Focus on threat modeling microservices and edge systems, reviewing secure architectures, and aligning cloud controls with embedded cybersecurity.

Location: On-site in Metzingen / Riederich, Germany

Company

hirify.global develops human-robot systems combining robotics software, hardware, safety, and certification.

What you will do

  • Secure cloud-native platforms on AWS using least-privilege IAM, network segmentation, secrets management, and policy-as-code.
  • Operate and extend SAST, DAST, SCA, container, Kubernetes, and infrastructure-as-code security scanning in GitLab CI/CD.
  • Own risk-based vulnerability management, including CVSS and exploitability triage, SLA-driven remediation, and audit-ready closure evidence.
  • Conduct STRIDE threat modeling and secure architecture reviews across microservices, edge systems, and AI/ML inference pipelines.
  • Support NIS2 documentation, incident notification workflows, supply-chain security assessments, and compliance activities.
  • Define secure coding and API standards and coordinate cloud security controls with embedded cybersecurity, certification, and audit stakeholders.

Requirements

  • Degree in Computer Science, Cybersecurity, Software Engineering, or a related field.
  • 3–5 years of hands-on application or cloud security experience in a product environment.
  • Practical knowledge of OWASP Top 10, ASVS, AWS security, and DevSecOps tooling.
  • Experience with vulnerability management, CVSS-based triage, SLA-driven remediation, and audit-ready documentation.
  • Working knowledge of NIS2, EU CRA, ISO 27001, or IEC 62443.
  • Proficiency in Python or Bash, plus container and Kubernetes security, IaC scanning, and AWS governance tools such as Config, SCPs, and GuardDuty.

Nice to have

  • OSCP or AWS Security Specialty certification.
  • Experience securing AI/ML pipelines using SageMaker, Triton, or ONNX and assessing model supply-chain risks.

Culture & Benefits

  • Work at the intersection of security, compliance, robotics, and AI.
  • Collaborate with engineering, embedded cybersecurity, certification, and external audit stakeholders.
  • Contribute to the development of safe, certifiable, and competitive human-robot systems.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →