Security Engineer (human)
Neura Robotics GmbH
Metzingen, Germany
17 days ago
Role details
Contract type
Permanent contract Employment type
Full-time (> 32 hours) Working hours
Regular working hours Languages
English Experience level
IntermediateJob location
Metzingen, Germany
Tech stack
Artificial Intelligence
Software System Penetration Testing
Bash
Burp Suite
Computer Security
Information Leak Prevention
Python
NMap
Open Web Application Security
Azure
Secure Coding
SonarQube
Wireshark
Scripting (Bash/Python/Go/Ruby)
Delivery Pipeline
Backend
Information Technology
Process Control Systems
Machine Learning Operations
Static Application Security Testing
Dynamic Application Security Testing
Job description
- Perform security assessments of robot control software, including compliance with IEC 62443 standards.
- Conduct SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) for web, mobile, and backend applications.
- Evaluate the security of AI/ML services, including model exposure, data leakage, and adversarial robustness.
- Develop proof-of-concept (PoC) exploits to demonstrate real-world impact of identified vulnerabilities.
- Build custom security tools and scripts to automate assessments and implement mitigation strategies.
- Collaborate with engineering teams to integrate security into development and deployment pipelines.
- Document findings and provide actionable recommendations to stakeholders.
Requirements
Do you have a Master's degree?, * Bachelor's or Master's degree in Cybersecurity, Computer Science, Robotics, or a related field.
- 2-5 years of experience in security assessment, penetration testing, or red teaming.
- Experience with robotics platforms (e.g., ROS/ROS 2) and industrial control systems.
- Familiarity with AI/ML pipelines and associated security risks.
- Strong knowledge of IEC 62443, OWASP Top 10, and secure coding practices.
- Proficiency in scripting languages (e.g., Python, Bash) and tools like Burp Suite, Nmap, Wireshark, and custom fuzzers.
- Experience with SAST/DAST tools (e.g., SonarQube, Semgrep, ZAP, or similar).
- Ability to develop and demonstrate PoC exploits.
- Excellent problem-solving, communication, and documentation skills.