PROSTAFF vermittelt und besetzt Informatik- und Data Science-Projekte in der Schweiz mit Freiberuflern, Freelancern, Contractors und temporären Mitarbeitern.
Full Stack Engineer – IAM Security
Location
Switzerland
Posted
10 days ago
Salary
0
Seniority
Mid Level
Job Description
Full Stack Engineer – IAM Security
PROSTAFF Schweiz GmbH
Role Description Für ein langfristiges Entwicklungsprojekt im Bereich Identity & Access Management suchen wir einen erfahrenen Senior Software Engineer Full Stack. Der Schwerpunkt der Position liegt auf der Analyse und Behebung von Security Vulnerabilities innerhalb einer modernen IAM-Anwendung. - Analyse und Behebung von Vulnerabilities im IAM-Umfeld - Weiterentwicklung und Optimierung bestehender Full-Stack-Anwendungen - Umsetzung sicherheitsrelevanter Anpassungen im Backend und Frontend - Entwicklung mit Java, Spring Boot, React und TypeScript - Betrieb und Deployment von Anwendungen auf einer OpenShift-Plattform - Zusammenarbeit mit Security-, Architektur-, DevOps- und IAM-Spezialisten - Durchführung von Code Reviews sowie nachhaltige Dokumentation der Änderungen - Sicherstellung von Qualität, Stabilität und Wartbarkeit der Software Qualifications - Mehrjährige Erfahrung in der Full-Stack-Softwareentwicklung - Sehr gute Kenntnisse in Java und Spring Boot - Fundierte Erfahrung mit React, JavaScript und TypeScript - Erfahrung mit OpenShift, Kubernetes oder vergleichbaren Containerplattformen - Kenntnisse in der Analyse und Behebung von Software-Schwachstellen - Verständnis für Secure Coding, Dependency Management und Application Security - IAM-Erfahrung ist von Vorteil, jedoch keine zwingende Voraussetzung - Selbstständige, kommunikative und lösungsorientierte Arbeitsweise - Deutschkenntnisse sind bevorzugt; sehr gute Englischkenntnisse sind ebenfalls möglich Company Description PROSTAFF vermittelt und besetzt Informatik- und Data Science-Projekte in der Schweiz mit Freiberuflern, Freelancern, Contractors und temporären Mitarbeitern.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Cybersecurity Engineer
RainFocusManage your virtual, in-person, and hybrid events seamlessly with the world’s only insight-driven platform.
• Safeguard organization's digital assets and ensure information systems' confidentiality, integrity, and availability. • Identify and mitigate security vulnerabilities. • Monitor security incidents. • Contribute to developing security policies and procedures.
• Perform holistic tabletop reviews covering both technical and non-technical risk across OT environments • Analyze for areas of negative impact, high risk, and single points of failure (SPOF) within sensitive, legacy networks • Identify vulnerabilities and weaknesses across Operational Technology environments, including Industrial Control Systems (ICS), SCADA, and field devices • Assess legacy and sensitive networks where conventional testing methods carry unacceptable operational risk • Support OT clients with security program improvements, identifying which critical controls are needed • Contribute to the maturity of Packetlabs' OT testing methodology and practice • Help raise the standard of OT security work across the firm
• Collaborate with Security Engineering and Infrastructure teams to identify, remediate, and prevent security, configuration, and architectural issues across the customer's Active Directory environment.
• Plan and execute end-to-end hardware penetration tests on embedded and IoT devices, against a defined scope and rules of engagement • Identify, access, and exploit on-board debug interfaces: JTAG, SWD, UART, and similar, to gain code execution or memory access • Extract firmware via debug ports, in-circuit flash reads (SPI / I2C / NAND), or chip-off when required, and analyze it for vulnerabilities • Intercept and analyze data on common embedded buses (SPI, I2C, UART, CAN, USB) using logic analyzers and protocol decoders • Where in scope, perform side-channel analysis and fault injection (power analysis, voltage/clock glitching) to bypass secure boot, readout protection, or authentication • Reverse engineer firmware and embedded binaries (Ghidra, IDA, Binwalk, etc.) to find logic flaws, hardcoded secrets, and exploitable conditions • Assess physical attack surface, tamper resistance, and key/secret storage • Write high-quality technical reports and present findings to client stakeholders, both technical and non-technical • Advise on practical, prioritized remediation that clients can act on • Build and maintain lab tooling, test rigs, and internal methodology • Help raise the standard of hardware security work across the firm



