via ats_lever · 9. Juni 2026 ·vor 4 Tagen

Cybersecurity Engineer

gravisrobotics
Zurich Vollzeit
4 Jobs in Zurich — und mehr im Umkreis.
Lad deinen CV hoch und sieh, welche wirklich zu dir passen.
CV hochladen

Gravis Robotics is a startup turning heavy construction machines into intelligent and autonomous robots. Our unique combination of learning-based automation and augmented remote control enables a single operator to safely manage a fleet of earthmoving machines in a gamified environment. With over a decade of academic experience at the cutting edge of large-scale robotics, our team is rapidly translating this expertise into real-world deployments with industry leaders in a trillion-dollar market.
About the Role
At Gravis, we operate at the intersection of hardware, software, and real-world deployment. Our Rooftop Autonomous Control Kit (RACK) integrates sensing, compute, communication, and networking into a manufacturer-agnostic solution deployable across a wide range of construction machines.

As Cybersecurity Engineer at Gravis, you will own our digital security development across the full product lifecycle; from the embedded software stack inside the RACK hardware to our cloud infrastructure and supply chain. You will be the company's expert voice on EU Cyber Resilience Act (CRA) readiness. You will lead the security development lifecycle and embed security into our development processes from day one, mentoring the development team on best practices. As a member of the safety team, you will act as the trusted partner across engineering, product, legal, and operations. This is a high-impact individual contributor role with the mandate to build a security function as Gravis scales globally.

What You Will Do

Regulatory & Compliance

  • Lead CRA readiness for Gravis products with digital elements: scoping, product classification, gap

assessments against essential requirements, risk analysis, control design, and remediation
roadmaps
  • Translate CRA, NIS2, and Machinery Regulation requirements into actionable control frameworks

and policies; map to ISO 27001/27002/27036, NIST CSF, NIST SP 800-161, NIST SSDF, CIS
Controls, and OWASP
  • Maintain comprehensive technical documentation to support conformity assessments, CE marking, and engagement with Notified Bodies

  • Stay current on emerging threats, regulatory changes, and best practices in product security,

supply chain security, and GRC

Product Security

  • Establish and mature product security capabilities: secure development lifecycle, secure update

processes, vulnerability handling, coordinated vulnerability disclosure (CVD), PSIRT setup and
operations, SBOM generation, management, and vulnerability triage
  • Conduct risk assessments and threat modelling for products and suppliers; define mitigation

strategies, metrics, and KPIs
  • Participate in incident and alert response reviews; propose and implement improvement actions

  • Assess and improve the security hardening of enterprise and embedded solutions
Secure Engineering
  • Write secure code for critical system components in C, C++, Python, and/or Rust

  • Conduct manual and automated code reviews with a strict focus on security vulnerabilities (OWASP Top 10, CWE)

  • Define and enforce secure coding guidelines and SAST/DAST tooling across engineering teams

  • Mentor and upskill engineers on secure development best practices
Collaboration & Communication
  • Collaborate cross-functionally with security, engineering, product, operations, legal, and compliance teams; facilitate workshops and drive change

  • Produce clear, high-quality deliverables: assessment reports, control designs, implementation

plans, policies, process maps, and training materials
  • Regularly monitor and report on security metrics, security posture, and compliance status to

management.
  • Explain complex security topics clearly to both technical and non-technical stakeholders
Required Qualifications
  • 3+ years of security experience with direct focus on EU regulatory compliance (CRA, NIS2,

Machinery Regulation) and GRC
  • Strong familiarity with industrial or embedded cybersecurity standards, particularly IEC 62443

  • Broad knowledge of security frameworks — ISO 27001, NIST CSF, NIST SP 800-161, NIST SSDF,

CIS Controls, OWASP — including control mapping and tailored implementation
  • Demonstrable experience establishing product security capabilities (PSIRT, CVD, SBOM, secure

development/update pipelines) in a product or software organisation
  • Proficiency writing secure code in one or more of: C, C++, Python, Rust

  • Experience conducting manual and automated code reviews focused on identifying security

vulnerabilities
  • Deep understanding of common vulnerability classes (OWASP Top 10, CWE) and proven mitigation strategies

  • Strong written and verbal communication skills; comfortable engaging both engineers and

executives

Nice To Have

  • Relevant cybersecurity certifications: CISSP, CISM, CISA, CRISC, ISO 27001 Lead

Implementer/Auditor, CCSK, or CCSP
  • Practical experience with conformity assessments, technical documentation, and CE marking

processes
  • Experience with penetration testing and vulnerability assessments

  • Hands-on experience with SAST and DAST tooling

  • Experience engaging with Notified Bodies through the conformity assessment process

  • Knowledge of cryptography, secure boot processes, and secure over-the-air (OTA) update

mechanisms
  • Background in industrial automation, robotics, or embedded systems environments

Der Markt für diese Art von Stelle

Ähnliche Angebote
4
Ingenieurwesen in Zurich
Vollzeit
69%
der Ingenieurwesen-Angebote in der Schweiz
Remote möglich
25%
der Ingenieurwesen-Angebote
gravisrobotics

11 offene Stellen · Zurich

📊 Ingenieurwesen · der Schweiz
511
aktive Stellen
24.9%
Remote
Ø 3d
Ø online
Gefragte Skills
ExcelERPISOPythonAWSCI/CDSQLAzureAgileLean

Häufige Fragen

Wie viele Ingenieurwesen-Jobs gibt es in Zurich?
Aktuell 4 Stellen im Bereich Ingenieurwesen in Zurich auf AlmostHired, bei 1 verschiedenen Unternehmen. Unsere Daten werden täglich aktualisiert.
Bieten Ingenieurwesen-Stellen Home Office an?
25% der Ingenieurwesen-Angebote in der Schweiz erlauben Remote-Arbeit, teilweise oder vollständig. Um gezielt nach Remote-Stellen zu filtern, nutze AlmostHired.
Wie erfahre ich, ob ich für diese Stelle passe?
Lad deinen CV hoch — unsere KI vergleicht dein Profil mit den Stellenanforderungen und zeigt dir einen präzisen Match-Score, inklusive passender und fehlender Skills.