You integrate security into the software development process by conducting risk assessments, providing guidance to teams, and staying updated on the latest threats and solutions.
Anforderungen
- •Strong knowledge of software development life-cycle
- •Proven experience in software security analysis
- •Deep experience as C++ developer in security
- •Very good ability to read and analyze source code
- •Proven knowledge of encryption-related concepts
- •Ideally experience with automotive systems
Deine Aufgaben
- •Support security throughout the software development life-cycle.
- •Conduct threat analysis and risk assessments.
- •Align on identified risks and implement countermeasures.
- •Provide security input to development teams and gather feedback.
- •Integrate and adapt code to meet security requirements.
- •Stay updated on industry security threats and solutions.
Original Beschreibung
## (Senior) Software Security Analyst (f/m/d)
###### Permanent employee, Full-time ·Karlsruhe, Germany,Budapest, Hungary
---
##### Position Description
As a Senior Software Security Analyst C/C++, you will support our development teams to develop our software components securely. You will analyze existing software according to security requirements, upgrade and document security guide lines. In this role, you will be part of the Automotive Security Team and work closely with our other engineering teams in Hungary and in Germany.
##### In this role, you will:
* Provide support regarding security in the whole software development life-cycle
* Perform threat analysis and risk assessments for software components
* Align about identified risks and drive the implementation of countermeasures
* Provide input to the software development teams about security related topics and collect feedback
* Occasionally integrate and adapt code to security requirements
* Keep yourself up to date about security threats and solutions known in the industry
##### What you will need to succeed:
* Strong knowledge of software development life-cycle and security methodologies
* Proven experience in software security analysis (TARA, vulnerabilities analysis, etc.)
* Deep experience as C++ developer in the security field, ideally targeting embedded Linux platforms
* A very good ability to read, analyze and understand existing source code, coming from a C++ developer background
* Proven knowledge of encryption-related concepts, standards and (network) protocols (e.g. Public Key Systems, AES, HTTPS, SSL/TLS, X.509, JWT/JWK)
* Ideally experience with automotive systems and related standards like ISO 21434 and ASPICE