Cybersecurity Engineer - Cloud, Ops (human)

Posted One Month Ago
Be an Early Applicant
2 Locations
In-Office
Mid level
Robotics
The Role
Secure cloud-native platforms and AppSec toolchains, run risk-based vulnerability management, perform STRIDE threat modeling, support NIS2 compliance, define secure coding/API standards, review secure architectures (including AI/ML pipelines), and align cloud and embedded security across robot systems.
Summary Generated by Built In

Our Systems Engineering Department turns market demands into safe, certifiable, and competitive robot systems — spanning software, hardware, safety, and certification. Join us to shape the next generation of human-robot systems and find extraordinary opportunities at the intersection of security, compliance, and cutting-edge robotics.

Your Mission & Challenges

  • Secure Cloud-Native Platforms: Secure cloud-native platforms (AWS EKS, Lambda, API Gateway, IoT Core, S3) via least-privilege IAM, network segmentation, secrets management, and policy-as-code (Terraform/AWS Organizations).

  • Own the AppSec Toolchain: Operate SAST (Semgrep/SonarQube), DAST (ZAP/Burp), SCA, and container/IaC scanning in GitLab CI/CD; extend coverage to Kubernetes manifests and supply chain.

  • Drive Vulnerability Management: Run risk-based vulnerability management: CVSS + exploitability rating, SLA-driven remediation tracking, and structured closure evidence for internal KPIs and regulatory reporting.

  • Perform Threat Modeling: Conduct STRIDE threat modeling across microservices, edge, and AI/ML inference pipelines; translate findings into architecture decisions.

  • Support NIS2 Compliance: Own NIS2 Art. 21 measure documentation, incident notification workflows (24h/72h), and supply-chain security assessments for cloud dependencies.

  • Define Secure Coding Standards: Define and enforce secure coding and API standards (Python, TypeScript, C++; OAuth2/OIDC, JWT) and deliver developer-oriented remediation guidance embedded in engineering workflows.

  • Lead Secure Architecture Reviews: Lead secure architecture reviews for cloud-native and AI-adjacent systems; assess AI/ML pipeline security controls (SageMaker, Triton, ONNX) and model supply chain risks.

  • Bridge to Embedded Security: Align cloud threat models and security controls with the embedded cybersecurity team to maintain end-to-end integrity from robot controller to cloud backend.

What We Can Look Forward To

  • Education & Certification: Degree in Computer Science, Cybersecurity, or Software Engineering; OSCP or AWS Security Specialty is a differentiator.

  • Track Record: 3–5 years in application or cloud security with demonstrated ownership of AppSec tooling and vuln management in a product environment — not advisory only.

  • Security Fundamentals: Hands-on command of OWASP Top 10/ASVS, cloud security posture (AWS preferred), and DevSecOps tooling (SAST, DAST, SCA) — not just theoretical.

  • Vulnerability Management Process: Proven vuln management lifecycle: CVSS + exploitability triage, SLA-driven closure, and audit-ready documentation.

  • Regulatory Familiarity: Working knowledge of NIS2, EU CRA, ISO 27001, or IEC 62443; able to translate findings into compliance documentation for internal governance and external audit.

  • Technical Skills: Python/Bash proficiency; hands-on with container and Kubernetes security, IaC scanning, and AWS governance tooling (Config, SCPs, GuardDuty).

  • AI/ML Pipeline Exposure: Exposure to AI/ML pipeline security (SageMaker, Triton, ONNX) and model supply chain risks is a significant differentiator.

  • Collaboration & Communication: Communicates security risk clearly to engineering and management; written outputs audit-ready. Interfaces effectively with embedded security, certification, and external auditors.

Skills Required

  • Degree in Computer Science, Cybersecurity, or Software Engineering
  • OSCP or AWS Security Specialty certification
  • 3-5 years in application or cloud security with ownership of AppSec tooling and vulnerability management in a product environment
  • Hands-on knowledge of OWASP Top 10/ASVS, cloud security posture (AWS preferred), and DevSecOps tooling (SAST, DAST, SCA)
  • Proven vulnerability management lifecycle: CVSS + exploitability triage, SLA-driven closure, audit-ready documentation
  • Working knowledge of NIS2, EU CRA, ISO 27001, or IEC 62443 and ability to translate findings into compliance documentation
  • Proficiency in Python and Bash
  • Experience securing containers and Kubernetes, IaC scanning, and GitLab CI/CD pipeline security
  • Experience securing AWS cloud-native services (EKS, Lambda, API Gateway, IoT Core, S3) and using AWS governance tooling (Config, SCPs, GuardDuty)
  • Operate SAST (Semgrep/SonarQube), DAST (ZAP/Burp), SCA, and container/IaC scanning tools
  • Familiarity with OAuth2/OIDC and JWT and ability to define/enforce secure coding and API standards
  • Exposure to AI/ML pipeline security (SageMaker, Triton, ONNX) and model supply chain risks
  • Strong collaboration and communication; produce audit-ready written outputs and interface with embedded security, certification, and auditors
  • Experience performing STRIDE threat modeling across microservices, edge, and AI/ML inference pipelines
  • Experience leading secure architecture reviews for cloud-native and AI-adjacent systems
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Metzingen
180 Employees
Year Founded: 2019

What We Do

NEURA Robotics is a German high-tech company founded in 2019 in Metzingen near Stuttgart with the vision to revolutionize the world of robotics. More than 180 team members from over 30 countries are working on advanced technologies in the fields of environmental perception, drive and control technology, material science, mechanical design, and artificial intelligence. We are expanding the cognitive capabilities of robots and make breakthrough advances in a variety of areas to bring robots and humans closer together, making many areas of work more attractive, creative, and social again. That's why everything we do runs under the guiding principle "we serve humanity". In a very short period of time, NEURA Robotics has developed robots and technologies that are characterized above all by their outstanding performance as well as safe and human-centred way of working. In this way, a wide variety of application fields can be covered, from intelligent production to medical technology. All major robot components are developed and designed in-house. Imprint: https://www.neura-robotics.com/legal Privacy: https://www.neura-robotics.com/privacy

Similar Jobs

Pfizer Logo Pfizer

Sustainability Senior Manager

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote or Hybrid
30 Locations
121990 Employees
112K-207K Annually

Magna International Logo Magna International

HR Administrator (m/w/d/x)

Automotive • Hardware • Robotics • Software • Transportation • Manufacturing
Hybrid
Waldshut-Tiengen, Baden-Württemberg, DEU
171000 Employees

Hewlett Packard Enterprise Logo Hewlett Packard Enterprise

Client Delivery Lead Top Accounts

Artificial Intelligence • Cloud • Information Technology • Consulting
In-Office or Remote
7 Locations
85422 Employees

BlackLine Logo BlackLine

Enterprise Account Executive

Cloud • Fintech • Information Technology • Machine Learning • Software • App development • Generative AI
Remote or Hybrid
Germany
1810 Employees

Similar Companies Hiring

Fairly Even Thumbnail
Hardware • Robotics • Sales • Software • Hospitality
New York, NY
30 Employees
LTX Thumbnail
Robotics • Conversational AI • Generative AI
Jerusalem, Israel
200 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account