Cyber Security Expert – Product Development
We are looking for an experienced Cyber Security Expert to support the development of several new products with high requirements on cybersecurity, secure software development and compliance with the EU Cyber Resilience Act (CRA).
In this role, you will drive cybersecurity activities throughout the product development lifecycle and provide hands-on support to developers and other technical stakeholders. The assignment combines cybersecurity expertise with software development, secure architecture and implementation.
The products include both desktop applications and embedded systems, with technologies ranging from hardware-near firmware to real-time operating systems and PC-based software.
Key Responsibilities
Analyse current cybersecurity maturity and support compliance with the EU Cyber Resilience Act (CRA).
Perform cybersecurity risk assessments and follow up on implementation activities with relevant stakeholders.
Drive and coordinate cybersecurity activities within product development projects.
Perform and coordinate security testing, including DSAC testing.
Conduct attack surface analyses and threat modeling.
Review security-critical source code.
Support system hardening, including Windows images.
Ensure compliance with internal cybersecurity requirements and Secure Development Lifecycle (SDLC) processes.
Identify and drive improvements within secure development practices.
Participate in the requirements process and define appropriate security requirements.
Design and implement security solutions for desktop applications and embedded systems.
Drive security updates, vulnerability management and remediation processes.
Prepare cybersecurity documentation covering areas such as architecture, manuals, processes and agreements.
Prepare development projects for cybersecurity and security reviews.
Monitor relevant vulnerabilities, threats and security updates.
Support assessments of suppliers' compliance with cybersecurity requirements.
Collaborate with internal and global cybersecurity stakeholders.
Technical Environment
Experience within one or several of the following areas is highly relevant:
Embedded systems and firmware
C / C++
VHDL / Assembler
Real-time operating systems (RTOS)
C# / Java
Windows-based applications and environments
Secure software architecture and implementation
Vulnerability management and security testing
Your Profile
We are looking for someone with solid experience in Cyber Security within product development, ideally combined with a background in software development, software architecture or embedded systems.
You should have practical experience working with secure development processes and be comfortable supporting development teams in areas such as security requirements, secure design, implementation, testing and vulnerability management.
Strong collaboration and communication skills are essential, as the role involves working with a wide range of technical stakeholders in both local and international environments.
Experience with CRA compliance, Secure Development Lifecycle (SDLC), threat modeling, security testing and security architecture is highly meritorious.
This is a full-time consultant position through Incluso, starting in Mid-October. It is a five-month contract.
We will review applications on an ongoing basis.
Application deadline: 25 September.
For more information about this role, please contact Karin Persson