Fraunhofer-Gesellschaft logo
Fraunhofer-Gesellschaft

Angewandte Forschung seit 75 Jahren. Technologie, Innovation, Wertschöpfung.

Research Assistant – Software Security, Program Analysis

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 10,001+Since 1949H1B No SponsorCompany SiteLinkedIn

Location

Germany

Posted

58 days ago

Salary

0

Seniority

Senior

GermanEnglishJava

Job Description

Research Assistant – Software Security, Program Analysis

Fraunhofer-Gesellschaft

• Contribute to applied research projects in software security in collaboration with academic, industry, and public-sector partners • Develop and scientifically evaluate new methods for detecting, analyzing, verifying, and remediating software vulnerabilities • Conduct research on novel static and dynamic program analysis techniques, including fuzzing and the application of AI methods for vulnerability detection • Perform security analyses of real-world software systems, including: code reviews • Penetration testing and security assessments • Risk and threat analyses • Participate in publicly funded research projects and industry collaborations • Prepare project reports and scientific publications • Present research results at national and international conferences

Job Requirements

  • Completed university degree (Master's) in Computer Science, IT Security, or a related field
  • Strong interest in software security, program analysis, and security research with a focus on software-driven systems
  • Excellent programming skills (e.g., Java, C/C++), with a particular emphasis on secure coding practices
  • Experience or interest in one or more of the following areas: static/dynamic program analysis, fuzzing
  • Pentesting, exploit analysis, vulnerability research
  • Risk/threat modeling
  • Code reviews and penetration testing
  • Excellent German and English language skills, both written and spoken

Benefits

  • Work at a respected, internationally leading institute in the field of cybersecurity
  • Support for your scientific and professional development in software security, including support for a doctoral project
  • Friendly, open, and collegial working environment with a dynamic and creative atmosphere
  • Family-friendly culture with flexible working arrangements (various work-time models, flexible workplaces and hours, mobile working, subsidized public transport ticket, support services via the pme family service, etc.)
  • Company pension plan, capital-forming benefits, salary conversion options
  • Conveniently located (Darmstadt main station reachable in about a 10-minute walk), free parking and efficient EV charging infrastructure with preferential conditions for employees, alternatively a centrally located workplace in Heilbronn
  • Weekly working hours: 39 hours. This position is also available part-time.

Related Categories

Related Job Pages

More Security Engineer Jobs

Instasks App platform logo

Chef

Instasks App platform

Instasks App is a Professional Concierge Service. The app provides top-tiered professionals and clients with an online platform. Our unique approach to building an App is to give the client and the provider instant bookings and an easy process of all services. Providers receive custom requests for their specialized skills. The app takes care of all invoicing between client and provider with a detailed invoice. We track providers' locations for the client's en route to any job. We created a portal platform to guide you in listing your professions. The platform provides you with schedules, invoicing and credit card processing as part of the enhanced technology. Clients will have a choice to give the providers reviews and star ratings to ensure our elite services when booking on our app. Our mission is to help all providers strive to achieve their financial and independent goals. Opportunities to providers over the age of 18 and, by law, over the age of 21 for any tasks serving liquor.

Role Description We are looking for a chef to join our team and prepare delicious meals for our customers. Chef responsibilities include: - Studying recipes, setting up menus, and preparing high-quality dishes. - Delegating tasks to kitchen staff to ensure meals are prepared in a timely manner. - Informing the wait staff about daily specials. - Ensuring an appealing plate presentation. - Supervising cooks and assisting as needed. - Slightly modifying recipes to meet customers’ needs and requests (e.g., reduce salt, remove dairy). - Monitoring food stock and placing orders. - Checking the freshness of food and discarding out-of-date items. - Experimenting with recipes and suggesting new ingredients. - Ensuring compliance with all health and safety regulations within the kitchen area. Qualifications - Proven work experience as a Chef or cooking. - Hands-on experience with various kitchen equipment (e.g., grilles and pasta makers). - Advanced knowledge of culinary, baking, and pastry techniques. - Leadership skills. - Ability to remain calm and undertake various tasks. - Excellent time management abilities. - Up-to-date knowledge of cooking techniques and recipes. - Familiarity with sanitation regulations. - Culinary school diploma preferred. Requirements - Requires working from detailed instructions and occasional independent decision-making. - Ability to read, analyze, and interpret documents such as safety rules, operating and maintenance instructions, or procedural manuals. Benefits - Build your future with a secure & safe platform. - Be your own boss by choosing the TASKS that best suit your schedules. - Build your income to help increase your revenue. - Book tasks that are within a 15-mile radius. - Health & well-being of clients and providers are our highest priorities. Company Description Instasks App is a Professional Concierge Service. The app provides top-tiered professionals and clients with an online platform. Our unique approach to building an App is to give the client and the provider instant bookings and an easy process of all services. - Providers receive custom requests for their specialized skills. - The app takes care of all invoicing between client and provider with a detailed invoice. - We track providers' locations for the client's en route to any job. - Our mission is to help all providers strive to achieve their financial and independent goals. - We created a portal platform to guide you in listing your professions. - Clients will have a choice to give the providers reviews and star ratings to ensure our elite services. - All providers must go through a third-party background check only after you are confirmed for a job. - Each provider will go through etiquette training to ensure that every provider is a friendly and well-mannered individual.

United States
Job Closed
Full TimeRemoteTeam 51-200Since 2009H1B No Sponsor

Title: Senior Product Security Engineer Location: Remote (contiguous United States) Job Description: Salary Range:$120,000.00 To $140,000.00 Annually HistoSonics is a commercial-stage medtech company advancing the Edison System, a novel non-invasive sonic beam therapy based on histotripsy. Since receiving FDA De Novo grant for the non-invasive destruction of liver tumors in 2023, the company has progressed beyond initial market entry into commercial expansion, reimbursement momentum, and ongoing clinical and pipeline development. In addition to its current liver tumor indication, HistoSonics is pursuing future indications across multiple applications including kidney, pancreas, prostate, neuro, women's health, and other significant underserved human health areas, to realize the broader potential histotripsy across multiple disease states and medical specialties. We offer an exciting work culture where cutting-edge science meets real-world application, and each team member's contribution is important to our success in ensuring our physicians and their patients get what they need most. Location: Remote (contiguous United States) Travel: Quarterly - 3 days on site (likely Plymouth, MN) Position Summary: (Why this role matters) The Product Security Engineer will be part of a growing team responsible for contributions to the cybersecurity stature of the HistoSonics Edison Histotripsy system. The role will require you to work cross-functionally with hardware, firmware, software, quality, and regulatory teams to drive implementation of a wide array of security controls and best practices into the Edison system. Key Responsibilities: (What you'll do) - Threat Modeling and Risk Assessment: Execute and document risk assessments of the cybersecurity stature of various subsystems and components within the Edison system, in partnership with cross-functional stakeholders and subject matter experts. - Secure Design: Guide product engineering teams to drive inherent risk remediation via documenting and implementing requirements and adoption of best practices to reduce residual risk and improve the cybersecurity stature of the Edison system. Support development and documentation of verification plans to ensure control sufficiency. Analyze and document impact due to proposed changes. - Regulatory Compliance: Support FDA premarket submissions by preparing cybersecurity documentation including risk management reports, threat model, MDS2 and cybersecurity whitepaper. - Postmarket Compliance: Support cyber lifecycle management activities including vulnerability monitoring, assessment, and documentation needs. - Maintain a positive, results-oriented work environment, building partnerships and modeling teamwork, communicating to team members in an open, balanced, and objective manner. - Create/ maintain a clean, safe, and effective work environment. Qualifications and Skills: - 8 years of combined professional experience in Information Security, Risk Management, and or/IT-centric cybersecurity roles is required. - Bachelor's degree in an engineering, science, or technical discipline preferred. - In lieu of degree requirement: relevant technical, cybersecurity, or medical device on-job experience is considered. - Expertise with cybersecurity vulnerability analysis methodologies including CVSS is required. - Expertise with cybersecurity methodologies for identifying design weakness is required: (threat modeling/STRIDE, CWE) - Familiarity with cybersecurity, information security, and medical device standards regulations is required: (HIPAA, FDA, ISO 27001) - Familiarity with methodologies for assessing cybersecurity residual risk is required: (CVE analysis, review of technical design documentation, compensating controls analysis, CVSS MD rubric) - Relevant security certifications are preferred. - In-depth, systemic technical knowledge of complex, dynamic, and varying medical device systems. - Excellent written and verbal communication skills, with the ability to participate in engineering discussions. - Strong analytical, critical thinking, and problem-solving skills with an attention to detail. Benefits: We offer a comprehensive benefits package for full-time employees. This includes health, dental, and vision insurance, life, short-term and long-term disability insurance, 401(k), paid time off, and more. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. #LI-Remote

Worldwide
$120K - $140K / year
Inova Health logo

Oracle Security Administrator

Inova Health

We are Inova, Northern Virginia and the Washington, D.C. metropolitan area’s leading nonprofit healthcare provider.

Full TimeRemoteTeam 10,001+H1B Sponsor

• Meets all defined service levels and defined performance objectives within Inova IT for Supporting our Business Customers. • Serves as a leader for modifications or enhancements to use Oracle Security Architecture. • Coordinates all security designs with various Business Units. • Analyzes and implements Oracle security requirements. • Recommends and develops security measures to protect information against unauthorized modification or loss. • Works closely with both Oracle technical and functional teams to ensure the success of the overall Oracle solution. • Collaborates with Oracle Applications and business teams to design and implement technical security solutions for Oracle and associated bolt-on applications. • Adheres to and delivers ITGC controls and procedures. • Supports audits both internal and external. • Supports additional projects and duties as assigned.

District Of Columbia + 10 moreAll locations: District Of Columbia | Florida | North Carolina | Ohio | Maryland | Pennsylvania | South Carolina | Tennessee | Texas | Virginia | West Virginia
Achieve logo

Principal Security Engineer - Temporary

Achieve

A leading digital personal finance company helping everyday people move forward on the path to a better financial future

TemporaryRemoteTeam 1,001-5,000Since 2002H1B Sponsor

Job Description We are seeking a visionary Principal Security Engineer - Temporary to architect the next generation of Identity at Achieve. In the evolving Fintech landscape, Identity is no longer just a perimeter-it is our primary security fabric. You will move us beyond static governance into a world of Continuous Adaptive Trust, where identity is dynamic, risk-aware, and invisible to the end-user. As a senior technical leader within the Information Security Engineering team, you will design and build scalable systems that secure our most critical assets: our people, our customers, and our sprawling ecosystem of non-human workloads. You aren't just managing tools; you are engineering a trust platform that enables a fast-moving, cloud-native financial enterprise. This is a temporary assignment that we expect will go on for approximately one year. What you'll do: Strategy and Design - Continuous Adaptive Trust: Transition the enterprise from static, role-based access to a Risk-Based Authorization model that evaluates signals (device posture, behavior, location) in real-time. - Enhance the enterprise Identity strategy, roadmap, and architecture in alignment with business goals and security policies. - Design and architect comprehensive Identity solutions, including identity lifecycle management, non-human lifecycle management, authentication (MFA, SSO, passwordless), authorization, access governance, and Privileged Access Management (PAM). - Evaluate and select appropriate Identity technologies and platforms. - Create and maintain detailed architectural documentation for Identity solutions. - Lead the strategy and architecture for comprehensive Identity and Access Management (IAM) solutions, explicitly managing User Identities, Workload & Machine Identities (including Service Mesh, Kubernetes, Lambda, and APIs), and other non-human identities across on-premises and cloud environments to govern access rights and privileges. Implementation and Integration - Lead the implementation and integration of Identity solutions across various on-premises and cloud environments (e.g., Azure AD, AWS, GCP, Okta, Entra). - Integrate Identity systems with enterprise applications, platforms, and services using standard protocols (SAML, OAuth, OpenID Connect, SCIM). - Design and implement strategies to secure non-human machine identities, service accounts, APIs, and automation, utilizing Zero Standing Privilege principles and engineering "Just-in-Time" (JIT) access workflows to eliminate persistent administrative overhead, reduce the blast radius of potential compromises, and enforce strict, least-privilege, and Zero Trust security principles. - Develop and configure identity provisioning and de-provisioning workflows. - Partner with the SOC to build ITDR capabilities that detect and automatically neutralize identity-based attacks, such as session hijacking, token theft, and MFA fatigue. Collaboration and Leadership - Act as a "Security Partner" for engineering teams to foster secure development practices. - Drive successful adoption by collaborating with diverse stakeholders (business units, technology teams, application developers) and translating complex cryptographic and identity concepts into clear business value for product owners and executive leadership. - Provide technical leadership and guidance, championing and delivering self-service Identity APIs and SDKs to enable developers to build secure products with minimal friction (Developer Experience - DevEx). - Provide technical leadership, mentorship and guidance to Identity Engineers and other team members. Qualifications What you'll bring: Education - Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field. - A Master's degree is a plus. Experience & Mindset - 8+ years in Cybersecurity/Engineering, with a proven track record of moving legacy organizations towards a Zero Trust architecture. - Fintech/High-Growth Experience: Experience working in regulated environments where speed and compliance must coexist. - 5+ years focused on identity and access management. - Proven experience in designing and implementing enterprise-scale Identity solutions. - Drive security automation and "Builder" Mentality by architecting and implementing automation-first solutions (e.g., scripts, APIs, Infrastructure as Code) to eliminate reliance on manual governance processes and ensure security policy is enforced at scale and embedded into developer workflows. - Hands-on experience with leading IAM platforms and technologies, such as: - Identity Federation: Azure AD/Entra, Okta, Ping Identity, ADFS - IGA (Identity Governance and Administration): SailPoint, Saviynt, Oracle Identity Manager - PAM (Privileged Access Management): CyberArk, Delinea, BeyondTrust - Directory Services: Active Directory, Azure Active Directory, LDAP Skills - Technical Skills: - Deep knowledge of IAM principles, best practices, and security models. - Proficiency in scripting languages (e.g., PowerShell, Python) for automation and integration. - Understanding of network security, operating systems, and database concepts. - Familiarity with API security and microservices architecture. - Protocols: - Deep mastery of identity protocols and standards: IODC, OAuth 2.0, SAML, and SCIM, with a specific focus on mTLS and JWT security. - Cloud-Native Identity: Expert-level experience with cloud-native IAM (AWS IAM, Azure Entra ID, GCP Cloud IAM) and managing identity in distributed microservices architectures. - Infrastructure: Strong experience with Terraform and container orchestration (Kubernetes). - Soft Skills: - Excellent analytical and problem-solving skills. - Strong communication (written and verbal) and interpersonal skills. - Ability to work independently and as part of a collaborative team. - Strong project management and organizational skills. - Proven ability to strategically influence and expertly negotiate with stakeholders across all organizational levels. Certifications (Preferred but not required) - CISSP (Certified Information Systems Security Professional) - CISM (Certified Information Security Manager) - Relevant vendor certifications (e.g., Microsoft Certified: Identity and Access Administrator Associate/Expert, Okta Certified Professional/Administrator/Consultant). Additional Information All your information will be kept confidential according to EEO guidelines. Achieve well-being with: - 401 (k) with employer match - Medical, dental, and vision with HSA and FSA options - Competitive vacation and sick time off, as well as dedicated volunteer days - Access to wellness support through Employee Assistance Program, physical and mental health wellness programs - Pet care discounts for your furry family members - Financial support in times of hardship with our Achieve Care Fund - A safe place to connect and a commitment to diversity and inclusion through our six employee resource groups Join Achieve, change the future. At Achieve, we're changing millions of lives. From the single parent trying to catch up on bills to the entrepreneur needing a loan for the next phase of growth, you'll get to be a part of their journey to a better financial future. We're proud to have over 3,000 employees in mostly hybrid and 100% remote roles across the United States with hubs in Arizona, California, and Texas. We are strategically growing our teams with more remote, work-from-home opportunities every day to better serve our members. A career at Achieve is more than a job-it's a place where you can make a true impact, have a sense of belonging, establish a fulfilling career, and put your well-being first. Attention Agencies & Search Firms: We do not accept unsolicited candidate resumes or profiles. Please do not reach out to anyone within Achieve to market your services or candidates. All inquiries should be directed to Talent Acquisition only. We reserve the right to hire any candidates sent unsolicited and will not pay any fees without a contract signed by Achieve's Talent Acquisition leader. #LI-KM1 Company Description Achieve is a leading digital personal finance company. We help everyday people move from struggling to thriving by providing innovative, personalized financial solutions. By leveraging proprietary data and analytics, our solutions are tailored for each step of our member's financial journey to include personal loans, home equity loans, debt consolidation, financial tools and education. Every day, we get to help our members move their finances forward with care, compassion, and empathetic touch. We put people first and treat them like humans, not account numbers. Since 2002, Achieve has grown into one of the largest private consumer fintech unicorns in the U.S., with over $40B in enrollments for our industry-leading, tech-enabled debt resolution services business, and over $11Bn in personal and home loans originations via our banking-as-a-service partner.

Arizona