C

Senior Security Architect (Cyber-Physical Systems) - EU Cyber Resilience Act Compliance

coera robotics • Germany
Visa Sponsorship Relocation
Apply
AI Summary

Lead the end-to-end security architecture for Coera Robotics' platform, ensuring compliance with EU Cyber Resilience Act (CRA), IEC 62443, and ISO/IEC 27001. Own threat modeling, incident response, and secure engineering practices while collaborating with safety engineers to integrate security and safety. Shape the security standards for a safety-certified robotic platform with direct impact on deployments with leading robotics partners.

Key Highlights
Own end-to-end security architecture for robotic platform, including supply chain, build pipeline, runtime, and updates
Ensure compliance with EU Cyber Resilience Act (CRA) Annex I, IEC 62443-4-1/-4-2, and ISO/IEC 27001 for first customer deployment
Lead threat modeling (TARA) and implement mitigations for all integrations, with direct ownership of incident response and penetration testing
Key Responsibilities
Design and implement the end-to-end security architecture for Coera’s robotic platform, covering supply chain, build pipeline, deployed runtime, and update channels
Ensure compliance with EU Cyber Resilience Act (CRA) Annex I and IEC 62443-4-1/-4-2 standards for the first customer deployment
Conduct threat modeling (TARA) for all integrations and translate findings into actionable mitigations for shipped products
Oversee incident response readiness, penetration testing relationships, and security artifacts required for customer reviews
Collaborate closely with safety engineers to ensure security and safety are treated as a unified property
Set and enforce secure engineering practices across the team, elevating the bar for security standards
Technical Skills Required
IEC 62443-4-1/-4-2 and ISO/IEC 27001 Embedded Linux and firmware security (secure boot chains) C and C++ (production code)
Benefits & Perks
Salary band: €74,000–80,000 per year
Employee incentive plan (EIP) with long-term success participation
Visa and relocation support within Europe
Nice to Have
Experience with safety-certified or functionally safe products
Published vulnerability research or speaking engagements at security conferences (e.g., Black Hat, DEF CON)
Fluency in cyber-physical attack surfaces and hardware-level threats (anti-tamper, reverse engineering)
Experience with supply-chain and code-signing frameworks
German or Farsi language proficiency

Job Description


why this role matters


A robotic agent that can be compromised is a robotic agent that cannot be trusted. Security is the shadow half of coera's safety guarantee. The EU Cyber Resilience Act is in force, reporting obligations start September 2026, and full application follows in December 2027. You will own the security architecture, the threat model, and the evidence base that lets coera pass every customer security review and every regulator briefing.


what you will own


  • Design the end-to-end security architecture of coera's platform: supply chain, build pipeline, deployed runtime, update channel.
  • Deliver CRA (Regulation (EU) 2024/2847) Annex I conformance and the IEC 62443-4-1 and -4-2 evidence base for the first customer deployment.
  • Run threat modelling (TARA) on every integration and turn findings into shipped mitigations.
  • Own incident-response readiness, penetration-testing relationships, and the security artefacts that pass customer review.
  • Work closely with the safety engineer to keep safety and security as one property.
  • Set the bar for secure engineering practice across the team.


what we look for


Must haves


  • At least five years in product or platform security, with hands-on software engineering fluency. Production code in C and C++. 
  • Hardening embedded Linux and firmware, including secure boot chains.
  • IEC 62443-4-1 and -4-2 and ISO/IEC 27001, with working literacy in CRA Annex I and TARA methodology.
  • Cloud security fluency.
  • Cryptographic primitives and PKI operated in production.


Strong signals


  • Prior work on a safety-certified or functionally safe product. The single most valuable signal for coera because it means you already treat security and safety as one property.
  • Published vulnerability research, CVEs, or speaking record at Black Hat, DEF CON, Pwn2Own, OffensiveCon, CCC, or Troopers.
  • Cyber-physical attack surfaces and hardware-level threats: anti-tamper, reverse engineering.
  • CRA, NIS2, or Machinery Regulation 2023/1230 fluency demonstrated in shipped product.
  • AI and ML system security literacy: model weight protection, model supply chain, adversarial inputs.


Bonus


  • Supply-chain and code-signing frameworks.
  • German or Farsi in addition to English.


what we offer


A core-team role with real ownership over what we build and how. Direct line to deployments with leading robotics partners from day one. Post-thesis, pre-scale: the window where the work you do actually compounds.


All employees are offered the opportunity to participate in the company's long-term success through our employee incentive plan (EIP). The specific terms of your stake are agreed individually as part of your compensation package.


Salary band: €74,000–80,000 per year.


how we work


Small, senior, deliberate. We write more than we meet. We ship the core of the product before we ship the edges. We care about craft in code, policy design, and how we engage with customers. The bar is high, and the stakes are high: the safety layer of the robotics revolution is being built now, and we intend to be the one that defines it.


process and small print


Hiring process. A short intro call, a technical conversation tailored to the role, a deeper-dive session (onsite or remote), and an offer. Typical time from application to offer is two to three weeks. We move fast when we meet the right person.


Visa and relocation. We support visa sponsorship and relocation within Europe where it makes the difference between hiring the right person and not.


Equal opportunity. We hire on the strength of the work. We do not discriminate on the basis of ethnic origin, gender, religion or belief, disability, age, sexual identity, or anything else unrelated to the job. We explicitly welcome applications from people with disabilities and give them equal consideration. 


Your data. We process your application data under the GDPR to run this hiring process. If we do not hire you, we keep your data for up to six months afterwards so we can respond to any questions or legal claims, then delete it. If you would like us to keep your details longer for future roles, we will ask for your separate consent. You can ask us to delete your data at any time.


Similar Jobs

Explore other opportunities that match your interests

Senior Security Engineer

Cyber Security
•
1d ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

Helsing

Germany

Senior Information Security Manager

Cyber Security
•
3d ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Orbem

Germany

IT Security Manager

Cyber Security
•
6d ago
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

Raisin

Germany

Subscribe our newsletter

New Things Will Always Update Regularly