Camlin logo

DevSecOps - Embedded Software Security Engineer

Hiring from
Poland
Work type
Hybrid
Posted
May 27, 2026
Is this job info correct?

About Camlin

Camlin is a global technology leader that operates with the vision of bringing revolutionary products to life for a wide range of industries, including power and rail, and also has interests in a number of R&D projects in a variety of scientific sectors.


At Camlin we believe in high quality engineering and design, allowing us to develop market leading products and services. In short, we love creating value for our customers by solving difficult problems. As of now, Camlin operates in over 20 countries worldwide.🌐


We are looking for a Engineer Embedded Software Security Engineer to strengthen our Embedded Systems Unit.


In this role, you will collaborate closely with embedded development teams and our Information Security Management System (ISMS) team to build security into the product lifecycle and demonstrate compliance with the Cyber Resilience Act (CRA), the Radio Equipment Directive (RED), and IEC 62443.

You will apply ISMS-defined security policies in day-to-day product engineering rather than create governance processes. Your focus will be embedded software, firmware, product interfaces, secure updates, vulnerability handling, and security evidence throughout development and release.


You will support the secure development and release lifecycle of embedded products, including firmware, Embedded Linux platforms, device communications, and associated security tooling.

IMPORTANT NOTE: Although this role offers hybrid and remote-friendly working, at least ONE INTERVIEW in the selection process will take place onsite in our Kraków office.

Responsibilities

Secure Development & Compliance

  • Apply ISMS-defined secure development workflows and support engineering teams with threat modelling, security requirements, secure design reviews, secure coding, access control, secure update mechanisms, and product security documentation aligned with CRA, RED, and IEC 62443.

Vulnerability Scanning & Reporting

  • Configure and run SCA, SAST, and other appropriate security analysis tools for embedded software, firmware, and build outputs.
  • Triage findings, assess exploitability and product impact, support remediation, and prepare actionable vulnerability records aligned with CRA and IEC 62443 vulnerability-handling requirements.
  • Monitor relevant vulnerability disclosures affecting third-party components and coordinate product impact assessments.

Security Testing

  • Perform or coordinate white-box and grey-box security testing of firmware, Embedded Linux systems, device interfaces, communication protocols, and update mechanisms.
  • Validate security controls against product requirements, RED Article 3.3(d/e/f), and applicable IEC 62443 component requirements.
  • Document reproducible findings, work with developers on remediation, and verify fixes before release.

Software License & SBOM Reporting

  • Generate, validate, and maintain Software Bills of Materials (SBOMs) for embedded product releases.
  • Review third-party and open-source components for known vulnerabilities, provenance, and licence obligations, and maintain evidence required for CRA compliance and supply-chain transparency.

Product Trust, Secure Boot & Provisioning

  • Support secure boot, firmware signing, image verification, anti-rollback, and secure update mechanisms.
  • Support certificate provisioning, device identity, key-management tooling, and secure device onboarding in accordance with ISMS-defined controls.
  • Review the secure handling of secrets and protected configuration across development, manufacturing, and field-service workflows.

Required Skills & Qualifications

Technical Skills

  • Experience developing, testing, or securing embedded software in C or C++ and scripting in Python.
  • Experience with Embedded Linux and Yocto, including package composition, build artefacts, and update mechanisms.
  • Practical knowledge of secure boot, firmware signing, cryptographic key handling, device identity, and secure firmware updates.
  • Experience with SCA and SAST tools such as SonarQube, Black Duck, or equivalent, including investigation and remediation of findings.
  • Understanding of SBOM formats and workflows, including CycloneDX or SPDX.
  • Ability to analyse embedded attack surfaces, debug security issues, and communicate actionable findings to software engineers.
  • Working knowledge of Git-based development and automated build pipelines as they relate to secure, traceable product releases.


Cybersecurity & Standards

  • Strong understanding of embedded cybersecurity principles, including least privilege, defence in depth, secure defaults, trust boundaries, and attack-surface reduction.
  • Working knowledge of CRA, RED cybersecurity requirements, and IEC 62443, including secure development lifecycle and component-level security concepts.
  • Experience applying secure SDLC practices such as threat modelling, security requirements, design review, vulnerability management, security testing, and release evidence.
  • Knowledge of secure communication protocols and applied cryptography, including TLS, certificates, authentication, encryption, and key lifecycle considerations.

Desired Qualifications (Nice‑to‑Have)

  • Experience with hardware-backed security features such as TPMs, secure elements, trusted execution environments, or microcontroller security functions.
  • Experience with embedded penetration testing, protocol analysis, fuzzing, or firmware reverse engineering.
  • Familiarity with CVE/CVSS, coordinated vulnerability disclosure, and product security incident response.
  • Experience producing security assurance evidence for regulated or industrial products.
  • Relevant product security or embedded security certification.


Benefits:

  • Employment contract with competitive salary
  • Work in small, self-organized and autonomous development teams with the ability to choose technologies and best practices
  • Hybrid work model (office in Kraków)
  • Company Pension & Life Assurance Schemes
  • On-site parking (car and bike)
  • UoP with 80% author’s rights tax relief
  • MyBenefit system with Multisport membership, private healthcare (Medicover)
  • Wellness programmes


Our Values

  • We work together
  • We believe in people
  • We won’t accept the ‘way it has always been done’
  • We listen to learn
  • We’re trying to do the right thing


Equal Employment Opportunity Statement

Individuals seeking employment at Camlin are considered without regards to race, colour, religion, national origin, age, sex, marital states, ancestry, physical or mental disability, gender identity or sexual orientation.

Similar jobs

Apply for this job