> Markdown version of [/jobs/ext/1646787-senior-security-architect-human](https://www.wearedevelopers.com/jobs/ext/1646787-senior-security-architect-human). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Architect (Human) - **Company:** Neura Robotics GmbH - **Location:** Metzingen, Germany - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Training Data, Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Cloud Computing Security, Cyber Security, Continuous Integration, Firmware, Identity and Access Management, IT Management, Information Technology Operations, Key Management, Cloud Services, Zero Trust Network Access, Software Vulnerability Management, Software Security, Information Technology, U-Boot, IoT Security, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 12, 2026 - **Apply:** https://de.indeed.com/viewjob?jk=c636a282dda2c31d ## About the Role * 7+ years in cybersecurity, with a track record that spans both IT infrastructure security and product or application security - you are comfortable on both sides * Hands-on experience with threat modelling methodologies such as STRIDE or PASTA, and the ability to run sessions independently with engineering teams * Strong working knowledge of DevSecOps tooling: SAST, DAST, secrets scanning, software composition analysis, and CI/CD pipeline integration * Experience designing or assessing cloud security architecture on AWS, Azure, or GCP * Solid understanding of embedded and IoT security principles: secure boot, firmware integrity, OTA update security, and hardware trust anchors * Working knowledge of relevant frameworks and regulations: ISO 27001, IEC 62443, NIS2, and the EU Cyber Resilience Act * The communication range to explain a risk register to the CEO and a threat model to an embedded engineer - in the same day * Degree in Computer Science, IT Security, Electrical Engineering, or a comparable field - or equivalent demonstrated experience * CISSP, CISM, or a comparable certification is a strong plus * Experience in robotics, industrial automation, connected hardware, or AI system environments is particularly welcome * Awareness of emerging AI and ML security risks - adversarial inputs, model theft, training data integrity - is a differentiator at NEURA ## Description * Shape and evolve security architecture across IT and product - reviewing designs, identifying weaknesses, and driving hands-on improvements across embedded systems, cloud services, and enterprise IT * Develop and maintain reference architectures for the highest-risk areas: secure OTA update pipelines, Zero Trust network design, cloud-native security, embedded and firmware security, IAM, and secrets management * Lead threat modelling for high-impact initiatives across product verticals and IT infrastructure - producing prioritised risk maps, not lengthy audit reports * Own and maintain the organisation-wide security risk register, translating technical findings into business-relevant assessments that leadership can act on * Establish the security standards every team is expected to meet and drive adoption without creating friction for developers - guardrails, not gates * Integrate security into the development lifecycle: select and tune SAST/DAST tooling, secrets scanning, and dependency scanning across CI/CD pipelines * Own vulnerability management: CVE triage process, remediation SLAs, and coordination across product verticals and IT operations * Map NEURA's product and IT landscape against regulatory requirements - EU Cyber Resilience Act, NIS2, ISO 27001, IEC 62443 - and close gaps proactively * Define the security bar for third-party components, libraries, and vendor integrations entering the supply chain * Scope and coordinate external penetration tests; validate that findings are remediated, not just acknowledged * Define what good looks like for future Product Security Engineers embedded in our product verticals - shaping their hiring profiles, mandates, and onboarding * Serve as the technical bridge between security and engineering: review major architectural decisions, communicate trade-offs, and translate risk into terms both developers and leadership can act on ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Frontend Developer Salary in Germany [2023]](https://www.wearedevelopers.com/magazine/195-frontend-developer-salary-in-germany-2023) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)