Product Security Specialist (w/m/d)
Stellenstandort:  Dietikon
Start:  tbd
Umfang:  Vollzeit

Where experience meets opportunity: Take charge, contribute, and develop your potential. 

duagon, headquartered in Switzerland, is a fast-growing global technology company specializing in embedded electronic hardware, software, and services for system-critical applications in the rail and medical market. Our innovative products in network communication, computing, and subsystem control are designed to the highest standards of safety and reliability, helping our customers accelerate their technology roadmaps and achieve optimal cost of ownership.

Stellenbeschreibung

Your Role  

You support our CRA compliance activity for embedded products across the entire process, from threat and risk analysis, through the assessment of vulnerabilities and suitable countermeasures, to compliance evaluation and its documentation. You work closely with our engineering teams and bring security methodology into
the development of mission-critical computing platforms for the rail and transportation industry.

 

Your Responsibilities 

  • Conduct and facilitate Threat and Risk Analyses (TRA) together with the engineers, including the creation and maintenance of the associated artifacts
  • Assess vulnerabilities (vulnerability assessment) and derive and evaluate suitable countermeasures in terms of effectiveness, effort, and residual risk
  • Evaluate the CRA compliance of our products and document conformity in a structured and traceable manner
  • Create and maintain the technical documentation required under the CRA (including risk assessment, SBOM, and conformity evidence)
  • Contribute to vulnerability and patch management across the product lifecycle, including the coordinated vulnerability disclosure process and reporting obligations
  • Support security-by-design and the secure development lifecycle (SDLC) in product development
  • Act as an interface to functional safety, quality, and product management; advise engineering teams on security matters
  • Prepare for and accompany audits and conformity assessments with internal and external bodies

 

Your Profile

  • Degree in computer science, electrical engineering, cyber security, or a comparable field
  • At least two years of professional experience in product or embedded security
  • Sound knowledge of threat modeling and risk analysis (e.g., STRIDE, attack-tree methods) and of vulnerability assessment (CVSS, SCA)
  • Experience with relevant standards and regulations, in particular the Cyber Resilience Act and IEC 62443; rail context (TS 50701 / EN 50701, IEC 63452) 
    is an advantage
  • Understanding of embedded systems, network and communication protocols, and secure software architectures
  • Experience with TRA documentation, tools for vulnerability tracking, and SBOM generation
  • Structured, diligent way of working and the ability to document technical matters clearly
  • Very good English skills; strong communication skills for collaboration with interdisciplinary teams

 

Nice to Have

  • Certifications such as GICSP, ISA/IEC 62443, or comparable
  • Experience in regulated industries (rail, automotive, industrial automation)
  • Knowledge of functional safety and its interaction with security

 

Recruitment agencies cannot be considered for this position.

Informationen auf einen Blick

What we offer:

 

 

 

 

 

Interested? We look forward to hearing from you!

duagon AG
HR Team