About this role
<p><strong>Tasks:</strong></p> <ul> <li id="tw-target-text" dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Maintenance and further development of the existing IEC 62443 certification.Ensuring CRA compliance throughout the entire product lifecycle.Ensuring security requirements are met throughout the product lifecycle. Establishing Secure Development Lifecycle (SDL) processes.Close collaboration with R&D, QA, and the Information Security Officer (ISO 27001).Coordination of internal and external audits, penetration tests, and assessments.Monitoring of vulnerabilities (e.g., CVEs) and management of remediation measures.Point of contact for customers and sales regarding this topic.Creation of key performance indicators (KPIs) and reports for management and relevant stakeholders."><span style="font-family:arial, helvetica, sans-serif">Maintenance and further development of the existing IEC 62443 certification. Ensuring CRA compliance throughout the entire product lifecycle. </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Maintenance and further development of the existing IEC 62443 certification.Ensuring CRA compliance throughout the entire product lifecycle.Ensuring security requirements are met throughout the product lifecycle. Establishing Secure Development Lifecycle (SDL) processes.Close collaboration with R&D, QA, and the Information Security Officer (ISO 27001).Coordination of internal and external audits, penetration tests, and assessments.Monitoring of vulnerabilities (e.g., CVEs) and management of remediation measures.Point of contact for customers and sales regarding this topic.Creation of key performance indicators (KPIs) and reports for management and relevant stakeholders."><span style="font-family:arial, helvetica, sans-serif">Ensuring security requirements are met throughout the product lifecycle. </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Maintenance and further development of the existing IEC 62443 certification.Ensuring CRA compliance throughout the entire product lifecycle.Ensuring security requirements are met throughout the product lifecycle. Establishing Secure Development Lifecycle (SDL) processes.Close collaboration with R&D, QA, and the Information Security Officer (ISO 27001).Coordination of internal and external audits, penetration tests, and assessments.Monitoring of vulnerabilities (e.g., CVEs) and management of remediation measures.Point of contact for customers and sales regarding this topic.Creation of key performance indicators (KPIs) and reports for management and relevant stakeholders."><span style="font-family:arial, helvetica, sans-serif">Establishing Secure Development Lifecycle (SDL) processes. </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Maintenance and further development of the existing IEC 62443 certification.Ensuring CRA compliance throughout the entire product lifecycle.Ensuring security requirements are met throughout the product lifecycle. Establishing Secure Development Lifecycle (SDL) processes.Close collaboration with R&D, QA, and the Information Security Officer (ISO 27001).Coordination of internal and external audits, penetration tests, and assessments.Monitoring of vulnerabilities (e.g., CVEs) and management of remediation measures.Point of contact for customers and sales regarding this topic.Creation of key performance indicators (KPIs) and reports for management and relevant stakeholders."><span style="font-family:arial, helvetica, sans-serif">Close collaboration with R&D, QA, and the Information Security Officer (ISO 27001). </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Maintenance and further development of the existing IEC 62443 certification.Ensuring CRA compliance throughout the entire product lifecycle.Ensuring security requirements are met throughout the product lifecycle. Establishing Secure Development Lifecycle (SDL) processes.Close collaboration with R&D, QA, and the Information Security Officer (ISO 27001).Coordination of internal and external audits, penetration tests, and assessments.Monitoring of vulnerabilities (e.g., CVEs) and management of remediation measures.Point of contact for customers and sales regarding this topic.Creation of key performance indicators (KPIs) and reports for management and relevant stakeholders."><span style="font-family:arial, helvetica, sans-serif">Coordination of internal and external audits, penetration tests, and assessments. </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Maintenance and further development of the existing IEC 62443 certification.Ensuring CRA compliance throughout the entire product lifecycle.Ensuring security requirements are met throughout the product lifecycle. Establishing Secure Development Lifecycle (SDL) processes.Close collaboration with R&D, QA, and the Information Security Officer (ISO 27001).Coordination of internal and external audits, penetration tests, and assessments.Monitoring of vulnerabilities (e.g., CVEs) and management of remediation measures.Point of contact for customers and sales regarding this topic.Creation of key performance indicators (KPIs) and reports for management and relevant stakeholders."><span style="font-family:arial, helvetica, sans-serif">Monitoring of vulnerabilities (e.g., CVEs) and management of remediation measures. </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Maintenance and further development of the existing IEC 62443 certification.Ensuring CRA compliance throughout the entire product lifecycle.Ensuring security requirements are met throughout the product lifecycle. Establishing Secure Development Lifecycle (SDL) processes.Close collaboration with R&D, QA, and the Information Security Officer (ISO 27001).Coordination of internal and external audits, penetration tests, and assessments.Monitoring of vulnerabilities (e.g., CVEs) and management of remediation measures.Point of contact for customers and sales regarding this topic.Creation of key performance indicators (KPIs) and reports for management and relevant stakeholders."><span style="font-family:arial, helvetica, sans-serif">Point of contact for customers and sales regarding this topic. </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Maintenance and further development of the existing IEC 62443 certification.Ensuring CRA compliance throughout the entire product lifecycle.Ensuring security requirements are met throughout the product lifecycle. Establishing Secure Development Lifecycle (SDL) processes.Close collaboration with R&D, QA, and the Information Security Officer (ISO 27001).Coordination of internal and external audits, penetration tests, and assessments.Monitoring of vulnerabilities (e.g., CVEs) and management of remediation measures.Point of contact for customers and sales regarding this topic.Creation of key performance indicators (KPIs) and reports for management and relevant stakeholders."><span style="font-family:arial, helvetica, sans-serif">Creation of key performance indicators (KPIs) and reports for management and relevant stakeholders.</span></li> </ul> <p> </p> <p><strong>Profile:</strong></p> <ul> <li id="tw-target-text" dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Completed university degree (or equivalent), preferably in electrical engineering, cybersecurity, or a comparable qualificationRelevant practical experience in product security, ideally in an industrial environmentSound knowledge of IEC 62443 (especially 4-1 / 4-2)Experience with regulatory requirements such as the Cyber Resilience Act is an advantageGood knowledge of secure software development, threat modeling, and vulnerability managementExperience with certification bodies and auditsUnderstanding of hardware-related systems / embedded systems is an advantageAnalytical thinking skills as well as a structured and independent work styleStrong communication and assertiveness at all hierarchical levelsVery good German and English skills"><span style="font-family:arial, helvetica, sans-serif">Completed university degree (or equivalent), preferably in electrical engineering, cybersecurity, or a comparable qualification </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Completed university degree (or equivalent), preferably in electrical engineering, cybersecurity, or a comparable qualificationRelevant practical experience in product security, ideally in an industrial environmentSound knowledge of IEC 62443 (especially 4-1 / 4-2)Experience with regulatory requirements such as the Cyber Resilience Act is an advantageGood knowledge of secure software development, threat modeling, and vulnerability managementExperience with certification bodies and auditsUnderstanding of hardware-related systems / embedded systems is an advantageAnalytical thinking skills as well as a structured and independent work styleStrong communication and assertiveness at all hierarchical levelsVery good German and English skills"><span style="font-family:arial, helvetica, sans-serif">Relevant practical experience in product security, ideally in an industrial environment </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Completed university degree (or equivalent), preferably in electrical engineering, cybersecurity, or a comparable qualificationRelevant practical experience in product security, ideally in an industrial environmentSound knowledge of IEC 62443 (especially 4-1 / 4-2)Experience with regulatory requirements such as the Cyber Resilience Act is an advantageGood knowledge of secure software development, threat modeling, and vulnerability managementExperience with certification bodies and auditsUnderstanding of hardware-related systems / embedded systems is an advantageAnalytical thinking skills as well as a structured and independent work styleStrong communication and assertiveness at all hierarchical levelsVery good German and English skills"><span style="font-family:arial, helvetica, sans-serif">Sound knowledge of IEC 62443 (especially 4-1 / 4-2) </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Completed university degree (or equivalent), preferably in electrical engineering, cybersecurity, or a comparable qualificationRelevant practical experience in product security, ideally in an industrial environmentSound knowledge of IEC 62443 (especially 4-1 / 4-2)Experience with regulatory requirements such as the Cyber Resilience Act is an advantageGood knowledge of secure software development, threat modeling, and vulnerability managementExperience with certification bodies and auditsUnderstanding of hardware-related systems / embedded systems is an advantageAnalytical thinking skills as well as a structured and independent work styleStrong communication and assertiveness at all hierarchical levelsVery good German and English skills"><span style="font-family:arial, helvetica, sans-serif">Experience with regulatory requirements such as the Cyber Resilience Act is an advantage </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Completed university degree (or equivalent), preferably in electrical engineering, cybersecurity, or a comparable qualificationRelevant practical experience in product security, ideally in an industrial environmentSound knowledge of IEC 62443 (especially 4-1 / 4-2)Experience with regulatory requirements such as the Cyber Resilience Act is an advantageGood knowledge of secure software development, threat modeling, and vulnerability managementExperience with certification bodies and auditsUnderstanding of hardware-related systems / embedded systems is an advantageAnalytical thinking skills as well as a structured and independent work styleStrong communication and assertiveness at all hierarchical levelsVery good German and English skills"><span style="font-family:arial, helvetica, sans-serif">Good knowledge of secure software development, threat modeling, and vulnerability management </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Completed university degree (or equivalent), preferably in electrical engineering, cybersecurity, or a comparable qualificationRelevant practical experience in product security, ideally in an industrial environmentSound knowledge of IEC 62443 (especially 4-1 / 4-2)Experience with regulatory requirements such as the Cyber Resilience Act is an advantageGood knowledge of secure software development, threat modeling, and vulnerability managementExperience with certification bodies and auditsUnderstanding of hardware-related systems / embedded systems is an advantageAnalytical thinking skills as well as a structured and independent work styleStrong communication and assertiveness at all hierarchical levelsVery good German and English skills"><span style="font-family:arial, helvetica, sans-serif">Experience with certification bodies and audits </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Completed university degree (or equivalent), preferably in electrical engineering, cybersecurity, or a comparable qualificationRelevant practical experience in product security, ideally in an industrial environmentSound knowledge of IEC 62443 (especially 4-1 / 4-2)Experience with regulatory requirements such as the Cyber Resilience Act is an advantageGood knowledge of secure software development, threat modeling, and vulnerability managementExperience with certification bodies and auditsUnderstanding of hardware-related systems / embedded systems is an advantageAnalytical thinking skills as well as a structured and independent work styleStrong communication and assertiveness at all hierarchical levelsVery good German and English skills"><span style="font-family:arial, helvetica, sans-serif">Understanding of hardware-related systems / embedded systems is an advantage </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Completed university degree (or equivalent), preferably in electrical engineering, cybersecurity, or a comparable qualificationRelevant practical experience in product security, ideally in an industrial environmentSound knowledge of IEC 62443 (especially 4-1 / 4-2)Experience with regulatory requirements such as the Cyber Resilience Act is an advantageGood knowledge of secure software development, threat modeling, and vulnerability managementExperience with certification bodies and auditsUnderstanding of hardware-related systems / embedded systems is an advantageAnalytical thinking skills as well as a structured and independent work styleStrong communication and assertiveness at all hierarchical levelsVery good German and English skills"><span style="font-family:arial, helvetica, sans-serif">Analytical thinking skills as well as a structured and independent work style </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Completed university degree (or equivalent), preferably in electrical engineering, cybersecurity, or a comparable qualificationRelevant practical experience in product security, ideally in an industrial environmentSound knowledge of IEC 62443 (especially 4-1 / 4-2)Experience with regulatory requirements such as the Cyber Resilience Act is an advantageGood knowledge of secure software development, threat modeling, and vulnerability managementExperience with certification bodies and auditsUnderstanding of hardware-related systems / embedded systems is an advantageAnalytical thinking skills as well as a structured and independent work styleStrong communication and assertiveness at all hierarchical levelsVery good German and English skills"><span style="font-family:arial, helvetica, sans-serif">Strong communication and assertiveness at all hierarchical levels </span></li> <li dir="ltr" tabindex="-1" aria-label="Übersetzter Text: Completed university degree (or equivalent), preferably in electrical engineering, cybersecurity, or a comparable qualificationRelevant practical experience in product security, ideally in an industrial environmentSound knowledge of IEC 62443 (especially 4-1 / 4-2)Experience with regulatory requirements such as the Cyber Resilience Act is an advantageGood knowledge of secure software development, threat modeling, and vulnerability managementExperience with certification bodies and auditsUnderstanding of hardware-related systems / embedded systems is an advantageAnalytical thinking skills as well as a structured and independent work styleStrong communication and assertiveness at all hierarchical levelsVery good German and English skills"><span style="font-family:arial, helvetica, sans-serif">Very good English language skills</span></li> </ul>