JobRaahGet matched free

Jobs

cybersecurity engineer (m/w/d)

coera GmbH · Berlin · Germany · On-site

Posted Jul 6, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

why this role matters A robotic agent that can be compromised is a robotic agent that cannot be trusted. Security is the shadow half of coera's safety guarantee. The EU Cyber Resilience Act is in force, reporting obligations start September 2026, and full application follows in December 2027. You will own the security architecture, the threat model, and the evidence base that lets coera pass every customer security review and every regulator briefing. what you will own Design the end-to-end security architecture of coera's platform: supply chain, build pipeline, deployed runtime, update channel. Deliver CRA (Regulation (EU) 2024/2847) Annex I conformance and the IEC 62443-4-1 and -4-2 evidence base for the first customer deployment. Run threat modelling (TARA) on every integration and turn findings into shipped mitigations. Own incident-response readiness, penetration-testing relationships, and the security artefacts that pass customer review. Work closely with the safety engineer to keep safety and security as one property. Set the bar for secure engineering practice across the team. what we look for Must have At least five years in product or platform security, with hands-on software engineering fluency. Production code in C and C++.  Hardening embedded Linux and firmware, including secure boot chains. IEC 62443-4-1 and -4-2 and ISO/IEC 27001, with working literacy in CRA Annex I and TARA methodology. Cloud security fluency. Cryptographic primitives and PKI operated in production. Strong signals Prior work on a safety-certified or functionally safe product. The single most valuable signal for coera because it means you already treat security and safety as one property. Published vulnerability research, CVEs, or speaking record at Black Hat, DEF CON, Pwn2Own, OffensiveCon, CCC, or Troopers. Cyber-physical attack surfaces and hardware-level threats: anti-tamper, reverse engineering. CRA, NIS2, or Machinery Regulation 2023/1230 fluency demonstrated in shipped product. AI and ML system security literacy: model weight protection, model supply chain, adversarial inputs. Bonus Supply-chain and code-signing frameworks. German or Farsi in addition to English. what we offer A core team role with real ownership over what we build and how. Direct line to deployments with leading robotics partners from day one. Post-thesis, pre-scale: the window where the work you do actually compounds. All employees are offered the opportunity to participate in the company's long-term success through our employee incentive plan (EIP). The specific terms of your stake are agreed individually as part of your compensation package. how we work Small, senior, deliberate. We write more than we meet. We ship the core of the product before we ship the edges. We care about craft in code, policy design, and how we engage with customers. The bar is high, and the stakes are high: the safety layer of the robotics revolution is being built now, and we intend…