- Define and maintain the security architecture of the tester software platform, primarily focusing on Linux workstation software.
- Translate Cyber Resilience Act (CRA) essential cybersecurity requirements into concrete software development practices and product requirements.
- Perform threat modeling and security risk analysis for the software architecture, interfaces, and external integrations.
- Identify and analyze security vulnerabilities in the software stack (C++, Java, Linux environment).
- Establish and maintain secure development practices, including:
- secure coding guidelines
- security-focused code reviews
- use of static and dependency security analysis tools
- Monitor security advisories and vulnerability databases (e.g. CVEs) for third-party libraries, Linux components, and external dependencies used by the product.
- Investigate reported vulnerabilities or security incidents affecting the software and coordinate root cause analysis and remediation with development teams.
- Define and maintain processes for vulnerability handling and disclosure, including tracking, prioritization, and remediation.
- Support development teams in implementing security controls, such as:
- authentication and authorization mechanisms
- secure use of cryptographic functions
- protection against common software vulnerabilities
- Define requirements and concepts for secure software updates and software integrity protection.
- Contribute to security documentation required for CRA compliance, including risk assessments and security-related product documentation.
- Act as security advisor for development teams, helping them design and implement secure solutions.
- Assess security implications of executing customer-provided test programs and define safeguards such as sandboxing, permissions, or execution isolation.
Security Analyst / Product Security Engineer (Software) (m/f/d)
Advantest • Böblingen
-
Full-time
Böblingen
Your duties
Your profile
Software Security:
- Strong understanding of secure software design and architecture
- Experience with secure development practices for large software systems
- Knowledge of common software vulnerabilities and mitigation techniques (e.g. OWASP Top 10, memory safety issues)
- Familiarity with security aspects of C++ and Java development
- Understanding of Linux operating system security concepts
Security Engineering:
- Experience with threat modeling and security risk analysis
- Familiarity with security testing techniques, such as static analysis, dependency scanning, and vulnerability analysis
- Ability to analyze vulnerability reports and determine product impact
- Experience with investigating software defects and root causes
Standards and Compliance:
- Understanding of Cyber Resilience Act (CRA) requirements for software products
- Knowledge of secure development lifecycle (SDL) practices
- Familiarity with industry security standards and guidelines (e.g. OWASP, NIST, ISO/IEC security practices)
Collaboration - Ability to work closely with software architects and development teams
- Ability to translate security and regulatory requirements into practical development guidelines
- Strong analytical and problem-solving skills
- Ability to communicate security risks and recommendations clearly
What we offer
At Advantest, you enjoy flexibility
Life is often unpredictable, and there are always surprises along the way. So, we offer you a variety of options that allow you to work flexibly, in line with your current situation – to help you respond to unforeseen events or to plan long-term for a new chapter in your life!
Safeguards for whatever life brings.
No one knows what tomorrow will bring. But what we can do is ensure that you are prepared for anything life throws your way. A company pension, (paid) leaves of absence, and a variety of insurance offerings mean you can look to the future with peace of mind.
Working with us is worth it.
At Advantest, you can be sure of an attractive salary that is reviewed on a yearly basis. In addition, we offer you the chance to share in the company’s success, plus a wide range of meaningful financial benefits.
Grow with us.
Learning is a lifelong process. Whether you are a school or university student, a graduate, or an experienced professional – you are always growing. We offer you diverse ways to broaden your horizons and to take your career at Advantest forward.
Stay fit and healthy with us.
We want you to feel well at Advantest. That is why we offer a wide range of fitness and sport opportunities at all our sites – making it easier to be good to yourself.
Each and every one of us at Advantest makes an important contribution to our business success and plays a significant role in our further development. Working at Advantest means grasping opportunity and boldly exploring new possibilities. Would you like to know more about jobs at Advantest and about our unique team spirit? Our employees offer you their personal insights into our working environment.
Our pride and joy
Since 2017, we have regularly taken part in a comparison of the best employers in Germany. In 2021, our employees again participated in the anonymous and independent survey. The results confirm: We are a Great Place to Work! We first and foremost owe that great result to the people here at Advantest. Each and every day, they prove their dedication, take ownership, and bring passion to their work. And that makes us very proud.