Back to search
duagon Linkedin · Posted 26d ago

Product Security Specialist (w/m/d)

Switzerland

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Your Role

You support our CRA compliance activity for embedded products across the entire process, from threat and risk analysis, through the assessment of vulnerabilities and suitable countermeasures, to compliance evaluation and its documentation. You work closely with our engineering teams and bring security methodology into the development of mission-critical computing platforms for the rail and transportation industry.



Your Responsibilities

  • Conduct and facilitate Threat and Risk Analyses (TRA) together with the engineers, including the creation and maintenance of the associated artifacts
  • Assess vulnerabilities (vulnerability assessment) and derive and evaluate suitable countermeasures in terms of effectiveness, effort, and residual risk
  • Evaluate the CRA compliance of our products and document conformity in a structured and traceable manner
  • Create and maintain the technical documentation required under the CRA (including risk assessment, SBOM, and conformity evidence)
  • Contribute to vulnerability and patch management across the product lifecycle, including the coordinated vulnerability disclosure process and reporting obligations
  • Support security-by-design and the secure development lifecycle (SDLC) in product development
  • Act as an interface to functional safety, quality, and product management; advise engineering teams on security matters
  • Prepare for and accompany audits and conformity assessments with internal and external bodies



Your Profile

  • Degree in computer science, electrical engineering, cyber security, or a comparable field
  • At least two years of professional experience in product or embedded security
  • Sound knowledge of threat modeling and risk analysis (e.g., STRIDE, attack-tree methods) and of vulnerability assessment (CVSS, SCA)
  • Experience with relevant standards and regulations, in particular the Cyber Resilience Act and IEC 62443; rail context (TS 50701 / EN 50701, IEC 63452) is an advantage
  • Understanding of embedded systems, network and communication protocols, and secure software architectures
  • Experience with TRA documentation, tools for vulnerability tracking, and SBOM generation
  • Structured, diligent way of working and the ability to document technical matters clearly
  • Very good English skills; strong communication skills for collaboration with interdisciplinary teams



Nice to Have

  • Certifications such as GICSP, ISA/IEC 62443, or comparable
  • Experience in regulated industries (rail, automotive, industrial automation)
  • Knowledge of functional safety and its interaction with security


What we offer:

  • A highly interesting growth and development perspective in the market of embedded systems for railway technology
  • A challenging and varied job with a lot of freedom and practical tasks
  • An innovative freedom to develop solutions and implement them independently or in small teams
  • A pleasant working environment and a team-oriented working culture
  • Flexible working hours


Recruitment agencies cannot be considered for this position.

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search