security engineer
генерация резюме под вакансию
сопроводительное письмо
описание
Eagle Wireless is a connectivity company delivering secure, reliable, and scalable cellular modules and solutions for automotive and IoT applications.
задачи
- Monitor CVE feeds and security advisories relevant to component stacks across all product lines;
- Triage incoming CVEs against maintained SBOMs, assess exploitability, and determine applicability per product;
- Author and deliver VEX documents to customers within required timelines;
- Maintain component inventory as products evolve through their lifecycle;
- Operate and maintain vulnerability management tooling;
- Generate and maintain accurate SBOMs for all 20+ product lines;
- Integrate SBOM generation into CI/CD pipelines so artifacts are produced automatically at build time;
- Deliver SBOMs to customers in required formats on agreed cadences;
- Track third-party component updates, license changes, and EOL status across the product portfolio;
- Work with platform and DevOps engineers to integrate security tooling into build pipelines;
- Deploy and maintain source code static analysis tools and binary analysis tools;
- Implement and manage code signing and binary signing workflows for firmware and software releases, including key management and certificate lifecycle;
- Define and enforce security gates in the pipeline;
- Support secret scanning, dependency checking, and licence compliance tooling in CI;
- Maintain reproducible, containerised analysis environments so tooling runs consistently across dev, CI, and ad-hoc investigation contexts;
- Perform or coordinate binary firmware analysis to identify vulnerabilities, hardcoded credentials, and insecure configurations;
- Conduct or support source code security review of C/C++ and embedded codebases, identifying memory safety issues, unsafe function usage, and logic flaws;
- Assess hardware debug interfaces for exposure and insecure defaults, document findings, and work with hardware engineers on mitigations;
- Evaluate boot security: secure boot, chain-of-trust, and firmware signing enforcement;
- Identify and triage vulnerabilities specific to cellular module threat models;
- Produce structured technical findings reports from firmware and hardware analysis;
- Write Python scripts and tooling to automate vulnerability report generation for customer delivery;
- Build and maintain containerised analysis workflows that can be run reliably across different environments;
- Produce clear, accurate security reports suitable for both technical and non-technical customer contacts;
- Maintain dashboards and metrics for internal tracking of vulnerability status across the product portfolio;
- Produce technical security data packages for customer delivery;
- Provide technical input to penetration test scoping and support findings review;
- Work with firmware and software engineers to communicate vulnerability findings clearly and track remediation;
- Ensure outputs meet the technical requirements of CRA.
требования
- 3+ Years in a product security, application security, or security engineering role;
- Hands-on Python development experience;
- Practical experience with SBOM formats and VEX;
- Working knowledge of CVE, CVSS, and vulnerability triage methodology;
- Experience with container-based workflows;
- Familiarity with CI/CD systems and integrating security tooling into pipelines;
- Experience with source code static analysis tools;
- Hands-on experience with binary firmware analysis tooling and reverse engineering;
- Practical understanding of hardware debug interfaces;
- Understanding of code signing, certificate management, and PKI as applied to firmware or software releases;
- Strong written communication skills;
- Nice to have: Experience in an embedded systems, firmware, or hardware product company, familiarity with cellular module threat models, experience with Finite State or similar commercial platforms, reverse engineering experience with IDA Pro, experience testing hardware debug interfaces in a lab setting, knowledge of EU Cyber Resilience Act requirements, experience with Dependency-Track or similar open-source platforms, exposure to OpenVEX, understanding of firmware supply chain security concepts, relevant certifications such as GREM or GPEN, comfortable working in a lab environment.
условия
- No conditions specified
навыки
Если просят войти через iCloud, отправить коды из SMS, запустить код, что-то установить, перевести деньги или сделать что угодно, связанное с деньгами, не соглашайтесь: это признаки мошенничества.