> Markdown version of [/jobs/ext/3133539-security-engineer](https://www.wearedevelopers.com/jobs/ext/3133539-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # security engineer - **Company:** Vay - **Location:** Berlin, Germany (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Computer Networks, Linux on Embedded Systems, Firmware, Cyber-physical Systems, Software Engineering, Software Vulnerability Management, Cloud Platform System, Software Security, U-Boot - **Published:** September 29, 2026 - **Apply:** https://startup.jobs/senior-product-security-engineer-embedded-automotive-vay-7998734 ## About the Role As a Senior Security Engineer, you will play a critical role in shaping the cybersecurity foundation of Vay's technology platform and remote driving ecosystem. This is a highly cross-functional role that sits at the intersection of product security, systems engineering, software development, and organizational leadership. You'll work cross-functionally to ensure our products and systems are designed, developed, and validated with security at the core. Your work will directly influence how we assess risk, define mitigations, validate security requirements, and scale secure engineering practices across the company. This role is ideal for someone who can operate both strategically and hands-on. You should be comfortable driving high-level security architecture and process discussions while also diving deep into technical details when needed. Strong communication and stakeholder management skills are essential, as you'll often act as the security voice across the organization. The role can be scoped at a Senior looking for a step up or Principal level depending on your experience, technical depth, and ability to drive security topics across the organization., You are an experienced security engineer who has worked closely with engineering teams to influence secure product and system design across the development lifecycle: * Around 8+ years of experience in cybersecurity engineering, product security, application security, platform security, or related areas * Strong understanding of security architecture, secure software development, threat modelling, vulnerability management, and security risk assessment * Experience working with complex products or systems involving multiple software, infrastructure, hardware, or networking components * Ability to assess security vulnerabilities, prioritize risks, and define practical mitigations * Experience defining security requirements and working with engineering teams to implement them * Good understanding of authentication, authorization, cryptographic concepts, secure communication, and trust models * Familiarity with security standards, regulatory frameworks, or structured security processes * Strong technical depth and the ability to understand unfamiliar systems quickly * Excellent communication, planning, and stakeholder management skills * Comfortable operating both strategically and hands-on in fast-moving engineering environments, * Experience securing embedded systems, firmware, robotics, IoT, industrial technology, aerospace, medical devices, automotive systems or other cyber-physical systems. * Automotive cybersecurity or vehicle systems security experience. * Familiarity with ISO 21434, UNECE R155/R156, IEC 62443, the Cyber Resilience Act (CRA) or similar standards and regulations. * Experience conducting TARA or comparable structured security risk assessments. * Knowledge of embedded Linux, secure boot, secure software updates, hardware-backed security or device lifecycle security. ## Related Videos - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Automotive Security Challenges: A Supplier's View](https://www.wearedevelopers.com/videos/572-automotive-security-challenges-a-supplier-s-view) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) - [Cybersecurity for Software Defined Vehicles](https://www.wearedevelopers.com/videos/725-cybersecurity-for-software-defined-vehicles) ## Related Articles - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Ultimate Software Engineer Career Path Guide for 2023](https://www.wearedevelopers.com/magazine/146-the-ultimate-software-engineer-career-path-guide-for-2023) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)