NEURA Robotics builds cognitive robots and AI systems that operate in the real world — and the security surface that comes with that is as complex as the products themselves. You will join and strengthen a growing cybersecurity team, providing technical guidance to product engineers and security specialists across our verticals while helping expand our horizontal InfoSec function into a mature, enterprise-wide capability. Working across IT and product engineering, you will refine what is already in place, raise the bar where it matters, and make security a genuine competitive advantage rather than a bottleneck.
Your mission & challenges
Shape and evolve security architecture across IT and product — reviewing designs, identifying weaknesses, and driving hands-on improvements across embedded systems, cloud services, and enterprise IT
Develop and maintain reference architectures for the highest-risk areas: secure OTA update pipelines, Zero Trust network design, cloud-native security, embedded and firmware security, IAM, and secrets management
Lead threat modelling for high-impact initiatives across product verticals and IT infrastructure — producing prioritised risk maps, not lengthy audit reports
Own and maintain the organisation-wide security risk register, translating technical findings into business-relevant assessments that leadership can act on
Establish the security standards every team is expected to meet and drive adoption without creating friction for developers — guardrails, not gates
Integrate security into the development lifecycle: select and tune SAST/DAST tooling, secrets scanning, and dependency scanning across CI/CD pipelines
Own vulnerability management: CVE triage process, remediation SLAs, and coordination across product verticals and IT operations
Map NEURA's product and IT landscape against regulatory requirements — EU Cyber Resilience Act, NIS2, ISO 27001, IEC 62443 — and close gaps proactively
Define the security bar for third-party components, libraries, and vendor integrations entering the supply chain
Scope and coordinate external penetration tests; validate that findings are remediated, not just acknowledged
Define what good looks like for future Product Security Engineers embedded in our product verticals — shaping their hiring profiles, mandates, and onboarding
Serve as the technical bridge between security and engineering: review major architectural decisions, communicate trade-offs, and translate risk into terms both developers and leadership can act on
What we can look forward to
7+ years in cybersecurity, with a track record that spans both IT infrastructure security and product or application security — you are comfortable on both sides
Hands-on experience with threat modelling methodologies such as STRIDE or PASTA, and the ability to run sessions independently with engineering teams
Strong working knowledge of DevSecOps tooling: SAST, DAST, secrets scanning, software composition analysis, and CI/CD pipeline integration
Experience designing or assessing cloud security architecture on AWS, Azure, or GCP
Solid understanding of embedded and IoT security principles: secure boot, firmware integrity, OTA update security, and hardware trust anchors
Working knowledge of relevant frameworks and regulations: ISO 27001, IEC 62443, NIS2, and the EU Cyber Resilience Act
The communication range to explain a risk register to the CEO and a threat model to an embedded engineer — in the same day
Degree in Computer Science, IT Security, Electrical Engineering, or a comparable field — or equivalent demonstrated experience
CISSP, CISM, or a comparable certification is a strong plus
Experience in robotics, industrial automation, connected hardware, or AI system environments is particularly welcome
Awareness of emerging AI and ML security risks — adversarial inputs, model theft, training data integrity — is a differentiator at NEURA
Skills Required
- 7+ years in cybersecurity spanning IT infrastructure and product/application security
- Hands-on experience with threat modelling methodologies such as STRIDE or PASTA and ability to run sessions independently
- Experience with DevSecOps tooling: SAST, DAST, secrets scanning, software composition analysis, and CI/CD integration
- Experience designing or assessing cloud security architecture on AWS, Azure, or GCP
- Solid understanding of embedded and IoT security principles: secure boot, firmware integrity, OTA update security, hardware trust anchors
- Working knowledge of ISO 27001, IEC 62443, NIS2, and the EU Cyber Resilience Act
- Degree in Computer Science, IT Security, Electrical Engineering, or equivalent demonstrated experience
- Strong communication skills to translate technical risk to leadership and engineering teams
- Experience with vulnerability management: CVE triage, remediation SLAs, cross-team coordination
- CISSP, CISM, or a comparable certification
- Experience in robotics, industrial automation, connected hardware, or AI system environments
- Awareness of emerging AI/ML security risks (adversarial inputs, model theft, training data integrity)
What We Do
NEURA Robotics is a German high-tech company founded in 2019 in Metzingen near Stuttgart with the vision to revolutionize the world of robotics. More than 180 team members from over 30 countries are working on advanced technologies in the fields of environmental perception, drive and control technology, material science, mechanical design, and artificial intelligence. We are expanding the cognitive capabilities of robots and make breakthrough advances in a variety of areas to bring robots and humans closer together, making many areas of work more attractive, creative, and social again. That's why everything we do runs under the guiding principle "we serve humanity". In a very short period of time, NEURA Robotics has developed robots and technologies that are characterized above all by their outstanding performance as well as safe and human-centred way of working. In this way, a wide variety of application fields can be covered, from intelligent production to medical technology. All major robot components are developed and designed in-house. Imprint: https://www.neura-robotics.com/legal Privacy: https://www.neura-robotics.com/privacy









