SENIOR CYBERSECURITY ENGINEER (REMOTE)
About the role
SENIOR CYBERSECURITY ENGINEER (REMOTE PORTUGAL)
Portuguese company hires for remote position
Location: Portugal (Supporting a client based in Luxembourg)
️ Only candidates already based in Portugal will be considered
Work Model: Remote (Occasional travel to the client's site may be required)
️ Language Requirements: English C1 (Mandatory)
Seniority: Senior (8+ years)
Sector: Automotive
Rate Between €2400 - 3500 RV
️ Instructions: Please send your CV in English and make sure to include all skills and experience that match the requirements of the opportunity. This will significantly increase your chances of success
Your Mission
As a Senior Cybersecurity Engineer, you will act as a cybersecurity expert responsible for identifying, assessing, and mitigating security risks across embedded and IoT systems.
Working from an offensive security perspective, you will analyze firmware, hardware interfaces, communication protocols, and connected environments to discover vulnerabilities before attackers do. You will also lead Threat Analysis and Risk Assessment (TARA) activities while contributing to secure architecture design for next-generation embedded platforms.
Key Responsibilities
Analyze embedded and IoT systems from an attacker perspective to identify vulnerabilities and attack paths.
Assess attack surfaces across firmware, hardware components, and communication interfaces.
Perform vulnerability analysis on embedded devices and connected products.
Evaluate risks related to physical and hardware attacks, including JTAG, SWD, bus sniffing, and debug interfaces.
Review firmware architecture and system design from a cybersecurity standpoint.
Assess Ethernet communication stacks and networking protocols (TCP/IP, UDP).
Identify cybersecurity threats affecting edge computing and connected environments.
Conduct Threat Analysis and Risk Assessment (TARA) for embedded and industrial systems.
Apply ISO 27005 risk assessment methodologies.
Define threat scenarios, attack vectors, security risks, and mitigation strategies.
Produce cybersecurity documentation, including risk assessments, attack surface analyses, and mitigation plans.
Collaborate with hardware, firmware, software, and system engineering teams to integrate security-by-design principles.
Required Skills & Experience
Professional Experience
8+ years of experience in Cybersecurity Engineering.
Proven experience securing Embedded Systems, IoT platforms, or Industrial Systems.
Strong background in offensive security and vulnerability assessment.
Embedded & Hardware Security
Strong understanding of embedded architectures and firmware.
Knowledge of ARM-based processors or equivalent architectures.
Experience with hardware interfaces:
SPI
I2C
Parallel interfaces
Experience with debugging interfaces:
JTAG
SWD
Cybersecurity Expertise
Embedded vulnerability analysis.
Firmware security assessment.
Hardware attack surface analysis.
Physical attack techniques.
Hardware security evaluation.
Threat modeling.
Attack surface analysis.
Risk assessment methodologies.
Networking
Ethernet architecture.
TCP/IP.
UDP.
Communication security.
Risk Assessment
Threat Analysis and Risk Assessment (TARA).
ISO 27005.
Risk identification and mitigation planning.
Security documentation and reporting.
Nice to Have
Experience with ASPICE 4.0.
Knowledge of ISO 26262 Functional Safety.
Experience within Automotive or Safety-Critical Systems.
Familiarity with embedded security testing or debugging tools.
Experience designing secure system-level architectures.
Ideal Candidate Profile
You are an experienced cybersecurity professional who naturally thinks like an attacker while designing secure solutions.
You enjoy reverse engineering complex systems, identifying hidden vulnerabilities, and working closely with multidisciplinary engineering teams to build resilient embedded platforms.
You combine deep technical expertise in embedded security with strong analytical skills and are comfortable translating complex cybersecurity risks into practical mitigation strategies for both technical and business stakeholders.
Candidate Self-Assessment
Before applying, ask yourself:
Do I have at least 8 years of experience in Cybersecurity Engineering?
Have I worked with Embedded Systems, IoT devices, or Industrial Control Systems?
Am I experienced in firmware and hardware security analysis?
Have I performed Threat Analysis and Risk Assessment (TARA)?
Do I understand ISO 27005 risk assessment methodologies?
Have I analyzed attack surfaces across firmware, hardware, and communication protocols?
Am I familiar with ARM architectures, SPI, I2C, JTAG, and SWD?
Do I have strong networking knowledge, including Ethernet, TCP/IP, and UDP?
Have I worked with offensive security or vulnerability assessment methodologies?
Can I communicate effectively in English (C1 level) within international engineering teams?
Am I available to work remotely from Portugal with occasional travel to Luxembourg?
CV Keywords
Cybersecurity Engineer, Embedded Security, IoT Security, Embedded Systems, Firmware Security, Offensive Security, Vulnerability Assessment, Vulnerability Analysis, Attack Surface Analysis, Threat Modeling, Threat Analysis, TARA, Risk Assessment, ISO 27005, ARM Architecture, Firmware Analysis, Hardware Security, JTAG, SWD, SPI, I2C, Ethernet, TCP/IP, UDP, Physical Security, Bus Sniffing, Edge Computing, Industrial Cybersecurity, Automotive Cybersecurity, Embedded Architecture, Secure Design, Security Engineering, Embedded Firmware, Connected Systems, Security Risk Management, Functional Safety, ISO 26262, ASPICE, System Security Architecture
#00346313
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.