Product Software Security Architecture
(m / f / d)
Freelance / Contracting project Göttingen / Remote Start date : asap Reference number : 861979 / 1
Diesen Job teilen oder drucken
Responsibilities
- Translate cyber security requirements for software applications and embedded software systems into actionable, architectural, product-level security requirements
- Define and maintain secure design patterns, guidelines and reference architectures that can be used across products and solutions
- Evaluate and propose technical options for implementation of secure authentication & authorization, identity management, secure communication, key and secret management, secure Software updates as well as data integrity and confidentiality
- Define and maintain architecture principles aligned with industry’s best practices (e. g. CRA essential product requirements, IEC 62443, BSI) for secure product software
- Develop security architecture, run security architecture reviews and risk assessments and support security testing ( Pentests)
- Drive and monitor progress on continuous security improvements and assess the tradeoffs of different technological alternatives
- Project-related coordination as part of the secure development process and in accordance with defined processes
Profile
IEC 62443 (z. B. IEC 62443-3-3 / 4-2 und IEC 62443-4-1)Secure Software Development Lifecycle (SSDLC) und Secure Product Development Frameworks (SPDF)The product software is local and not cloud basedSecure coding & secure design principles, cryptography (PKI, certificates, key management), Linux- and Windows-based systems security, network security for industrial protocols (e. g. OPC UA, Modbus, TCP, Profinet) and OWASP guidelinesAPI Security and data protectionAutomation ( PLC, Tia Portal) Scada / OT systeme or laboratory equipmentThreat modeling methodologies ( STRIDE, DREAD, PASTA, Linddun) (optional)Benefits
Possibility of extending the project