A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
Overview Element is seeking a CRA Device Test Engineer to join our lab in Fremont, CA. Element offers end-to-end product Cybersecurity testing and certification services to ensure your IoT product is safe, secure and compliant with PSTI, RED, and CRA. In this role, you will design and implement highly secure technical solutions to protect against cyber threats and potential cyber-attacks. If you are not currently authorized to work in the US without sponsorship, Element Materials Technology will not consider your job application. Any candidate must be lawfully eligible to work in the US as a US Citizen or Permanent Resident of the United States.
Salary range:
$120 - 160K/year Responsibilities Detailed working knowledge of
EN 303 645, EN18031
(series) and other relevant cybersecurity test standards Maintain 'state-of-art-art' knowledge of product-based cybersecurity requirements within Element Materials Technology and ensure this information is shared and trained across the business Provide cybersecurity assessments of products to ensure they meet the applicable standards Provide training and mentoring of cybersecurity test engineers to ensure that they become and maintain competent for testing of cybersecurity to the applicable standards Create and maintain cybersecurity test procedures against the applicable standards and ensure that the appropriate requirements of
ISO 17025
are met Technically lead and support cybersecurity test audits from external and internal parties Be technically competent with sufficient training and experience of cyber security principles as it relates to equipment; and have sound technical and vocational training Attend customer meetings to provide technical support in regards to technical queries relating to project status or affecting progress To provide occasional technical support to the Commercial team (e.g. Sales Applications Engineers) to assist in the preparation of quotations specific to cyber security To ensure that commercial confidentiality is maintained To carry out any other reasonable duty as directed by the line manager Skills / Qualifications Relevant Degree or equivalent, plus minimum 5 years' experience A highly self-motivated individual with positive mindset & can-do attitude, and a strong believer of "Security as an enabler" to support business growth Strong intellectual agility, with the ability to apply it to a wide range of business contexts Experience with EN 18031 and
ETSI EN 303 645
cybersecurity standards for connected devices, including risk assessment, vulnerability management, and compliance for EU market access Confident ability to write and review designs, reports, procedures and standards Experience with EU Cyber Resilience Act (CRA) is a plus Must possess strong communicative skills and the ability to translate technical findings to a non-technical audience #LI-TF1 Diversity Statement At Element, we always take pride in putting our people first. We are an equal opportunity employer that recognizes diversity and inclusion as fundamental to our Vision of becoming "the world's most trusted testing partner". All suitably qualified candidates will receive consideration for employment on the basis of objective work related criteria and without regard for the following: age, disability, ethnic origin, gender, marital status, race, religion, responsibility of dependents, sexual orientation, or gender identity or other characteristics in accordance with the applicable governing laws or other characteristics in accordance with the applicable governing laws.