Cybersecurity Engineer

Gravisrobotics · Zürich

Gravisrobotics, a startup transforming heavy construction machines into autonomous robots, seeks a Senior Cybersecurity Engineer in Zürich. The role involves leading digital security development across embedded systems, cloud infrastructure, and supply chain, with a focus on EU Cyber Resilience Act (CRA) readiness and secure development lifecycle integration.

Gravisrobotics is a startup that turns heavy construction machines into intelligent, autonomous robots using learning-based automation and augmented remote control. This role is central to building the company’s security function, ensuring digital safety across the entire product lifecycle—from embedded software in RACK hardware to cloud systems and supply chain. The engineer will lead CRA readiness and embed security into development from day one, acting as the company’s expert voice on regulatory compliance and security best practices.

Responsibilities

  • Lead EU Cyber Resilience Act (CRA) readiness for Gravis products, including scoping, product classification, gap analysis, risk assessments, control design, and remediation planning
  • Translate CRA, NIS2, and Machinery Regulation requirements into practical security controls and policies, aligning with ISO 27001/27002/27036, NIST CSF, NIST SP 800-161, NIST SSDF, CIS Controls, and OWASP
  • Maintain detailed technical documentation to support conformity assessments, CE marking, and interactions with Notified Bodies
  • Track emerging threats, regulatory updates, and best practices in product and supply chain security, as well as GRC
  • Build and improve product security capabilities, including secure development lifecycle, secure update processes, vulnerability handling, coordinated vulnerability disclosure (CVD), PSIRT operations, SBOM generation, and vulnerability triage
  • Perform risk assessments and threat modeling for products and suppliers, defining mitigation strategies, metrics, and KPIs
  • Participate in incident and alert response reviews, and recommend improvements
  • Enhance security hardening for enterprise and embedded systems
  • Write secure code for critical components in C, C++, Python, or Rust
  • Conduct manual and automated code reviews focused on security flaws (OWASP Top 10, CWE)
  • Define and enforce secure coding standards and SAST/DAST tooling across engineering teams
  • Support engineers with training and guidance on secure development practices
  • Collaborate with security, engineering, product, operations, legal, and compliance teams, leading workshops and driving security integration
  • Create clear deliverables such as assessment reports, control designs, implementation plans, policies, process maps, and training materials
  • Monitor and report security metrics, posture, and compliance status to management
  • Communicate complex security topics clearly to both technical and non-technical audiences

Requirements

  • 3+ years of cybersecurity experience with a focus on EU regulatory compliance (CRA, NIS2, Machinery Regulation) and GRC
  • Strong knowledge of industrial or embedded cybersecurity standards, especially IEC 62443
  • Broad understanding of security frameworks including ISO 27001, NIST CSF, NIST SP 800-161, NIST SSDF, CIS Controls, and OWASP, with experience in control mapping and implementation
  • Proven experience in establishing product security capabilities such as PSIRT, CVD, SBOM, and secure development/update pipelines in a product or software organization
  • Proficiency in writing secure code in C, C++, Python, or Rust
  • Experience conducting manual and automated code reviews to detect security vulnerabilities
  • Deep understanding of common vulnerability types (OWASP Top 10, CWE) and effective mitigation techniques
  • Strong written and verbal communication skills, able to engage with both technical and executive stakeholders

Nice to have

  • Cybersecurity certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Auditor, CCSK, or CCSP
  • Experience with conformity assessments, technical documentation, and CE marking processes
  • Background in penetration testing and vulnerability assessments
  • Hands-on use of SAST and DAST tools
  • Experience working with Notified Bodies during conformity assessments
  • Knowledge of cryptography, secure boot, and secure over-the-air (OTA) update mechanisms
  • Experience in industrial automation, robotics, or embedded systems

What the company offers

  • Gravisrobotics offers a fair market salary
  • Work location in Zurich, a vibrant and dynamic city
  • Opportunity to join a fast-growing startup revolutionizing heavy construction with intelligent robotics
  • Flexible work arrangements with emphasis on work-life balance; preferred model can be discussed during interviews

About the company

Gravisrobotics is a startup pioneering the transformation of heavy construction machines into intelligent, autonomous robots. By combining learning-based automation and augmented remote control, the company enables a single operator to manage fleets of earthmoving machines in a gamified environment. The team brings over a decade of academic expertise in large-scale robotics and operates as an international group focused on solving global challenges.

  • Innovative approach to transforming construction machinery with AI and autonomy
  • Gamified remote operation of earthmoving fleets for enhanced efficiency
  • Team with deep academic roots in large-scale robotics
  • International team dedicated to solving global-scale problems

How to apply

Documents to submit:

  • CV

Application language: English

Auf Firmen-Website bewerben

Ähnliche Stellen

Quelle: öffentlich zugängliche Karriereseite des Arbeitgebers. Batchly ist nicht der Arbeitgeber und steht nicht notwendigerweise in einem Vertragsverhältnis mit dem Unternehmen.