Now hiring

Software Threat Modelling Specialist (m/f/d) (congatec Deggendorf, DE) @ Congatec AG

congatec Deggendorf, DEOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<p><strong>Your tasks:</strong></p> <p> </p> <ul> <li>Perform systematic threat-modelling for our software products; e.g. web applications, firmware implementations (UEFI, bootloader,…), relevant other software implementations of congatec products</li> <li>Apply established threat-modelling methods (e.g. STRIDE) and maintain architecture and data flow diagrams as a basis</li> <li>Identify and document threats, evil user stories/ attack paths, assumptions and corresponding security controls for our products</li> <li>Integrate threat-modelling into the product and engineering lifecycle (e.g. new features, major architectural changes, new integrations)</li> <li>Make recommendations and derive security requirements and acceptance criteria for user stories in close collaboration with Product Management and Engineering</li> <li>Support design reviews and influence security-related design decisions for our software architecture</li> <li>Assess identified threats in terms of business impact, customer impact and compliance requirements</li> <li>Prioritize risks together with Product Management and translate them into actionable items in product backlogs and roadmaps</li> <li>Define and track mitigation measures (e.g. hardening steps, design changes, additional security controls) and verify their effectiveness</li> <li>Develop and refine a threat modelling framework tailored to our software products, including reusable templates and patterns</li> <li>Conduct workshops and training on secure design and threat modelling techniques for development, architecture and product teams</li> <li>Act as a key advocate for “Security by Design” and “Product Security” across the organization</li> </ul> <p> </p> <p><strong>Your profile:</strong></p> <p> </p> <ul> <li>Degree in Computer Science, Software Engineering, Information Security or a comparable qualification</li> <li>Several years of proven experience in threat-modelling software products or platforms</li> <li>Strong background in collaborating with product, architecture and software development teams in an agile environment</li> <li>In-depth knowledge of at least one threat modelling methodology (e.g. STRIDE, LINDDUN, PASTA) and its practical application in real projects</li> <li>Very good understanding of modern software architecture (e.g. CPU partitioning)</li> <li>Solid understanding of common security threats and vulnerabilities (e.g. OWASP Top 10)</li> <li>Familiarity with relevant standards and frameworks (e.g. OWASP ASVS, NIST, ISO 27001, IEC62443) in the context of software product security is an advantage</li> <li>Experience with at least one programming language (e.g. Java, C#, C++, Go, Python, JavaScript/TypeScript) to understand implementation details</li> <li>Hands-on experience with threat-modelling documentation practices and common tooling (e.g. Git, CI/CD pipelines, ticketing and documentation systems)</li> <li>Structured, analytical and solution-oriented way of working with strong communication skills towards technical and non-technical stakeholders</li> <li>Confident in running workshops and moderating discussions in cross-functional teams</li> <li>Fluent in English and German; additional languages are an advantage</li> </ul>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores