← Takaisin työpaikkoihin

Security Architect

  • Paikan päällä
  • Suomi
  • Englanti
  • Julkaistu 24.09.26 18:32

Hi, We have below 2 Roles for Finland Location - Product Security Architect and Cybersecurity Test Engineer. Permanent Employment. Onsite Working. If interested, kindly let me know which role suits you the best. Work Location in FinlandLanguage - Candidate must have strong English communication skills. Finnish language proficiency would be an added advantage. Role #1 Job Title: Senior Product Security Architect / Threat Modeling ExpertExperience: 8+ Years Role OverviewWe are seeking a highly experienced Product Security Architect with strong expertise in Threat Modeling and Application Security to assess, enhance, and validate the cybersecurity posture of complex software-enabled products. The role will focus on secure architecture reviews, threat assessments, cybersecurity compliance, and remediation planning, ensuring alignment with cybersecurity standards and EU Cyber Resilience Act (CRA) requirements. Key ResponsibilitiesThreat Modeling & Security AssessmentsReview, validate, and refine product threat models using industry-standard methodologies (STRIDE, PASTA, Attack Trees, etc.).Perform comprehensive security assessments across:Application and UI softwareLinux-based platformsContainerized environmentsREST APIs and digital interfacesFPGA-integrated systemsBuild and release environmentsProduction processes and customer-facing documentationIdentify attack surfaces, trust boundaries, and security gaps across standalone and integrated product ecosystems. Product Security ArchitectureAnalyze product architectures against internal cybersecurity standards and industry best practices.Assess hardware and software trust boundaries, including:TPM (Trusted Platform Module)TEE (Trusted Execution Environment)Secure Boot and hardware-rooted trust mechanismsReview cybersecurity aspects of multi-product solutions and interconnected systems.Evaluate container-based architectures, Linux security controls, and API security implementations. Compliance & Security GovernanceAssess product readiness against EU Cyber Resilience Act (CRA) requirements.Create and validate Cryptographic Bill of Materials (CBOM).Identify compliance gaps and recommend remediation strategies.Update security architecture and design documentation to reflect required cybersecurity controls.Remediation Planning & AdvisoryDevelop detailed action plans for remediation, categorized by engineering functions such as:UI/Application DevelopmentPlatform SoftwareLinux EngineeringFPGA DevelopmentBuild & Release TeamsProduction/Manufacturing TeamsProvide ongoing security consulting, design reviews, and implementation guidance.Review and approve security improvements implemented by development teams. Key Skills:Threat ModelingApplication Security (AppSec)Product Security Architecture ReviewsSecure SDLC & Secure-by-DesignAPI Security, Container Security, Linux SecuritySecurity Standards & Compliance ReviewsEU Cyber Resilience Act (CRA)MPSOC, FPGA SecurityHardware Security Architecture Role #2: Cybersecurity Test Engineer Key ResponsibilitiesDevelop cybersecurity test plans based on:Threat modeling outcomesProduct security assessmentsCBOM findingsInternal cybersecurity standardsIndustry best practicesPerform security validation, vulnerability assessments.Execute and document cybersecurity test results.Identify, track, and validate remediation of security findings.Support continuous cybersecurity assurance throughout the product lifecycle. Required SkillsApplication Security Testing (SAST, DAST, API Security Testing).Vulnerability Assessment and Security Validation.Threat Modeling knowledge.Linux and Container Security Testing.Test automation and CI/CD security integration.Strong reporting and technical documentation skills.