Product Cybersecurity Engineer

Vilnius/Hybrid

Project

We are looking for a hands-on Product Cybersecurity Engineer passionate about building secure products from the ground up. In his role, you won't be staring at SIEM dashboards or managing internal IT end points. Instead, you will be directly embedded in our product lifecycle - driving security-by-design principles into platform and connected devices.

Work

You will work closely with Software Developers, System Architects, Quality, and Regulatory teams to ensure our connected platforms are secure across software, firmware, and cloud interfaces.

Key Responsibilities:

• Security Architecture & Design: Own the security-by-design lifecycle for our platform. Conduct threat modeling (STRIDE/HEAVENS) and design secure architecture for embedded devices, APIs, and backend connectivity.

• Hardware & Embedded Defense: Verify implementation of critical edge-security controls, including secure boot, cryptographic storage, secure firmware updates (OTA), and encrypted communications.

• Hands-on Assessment & Pen-Testing: Perform vulnerability assessments and hands-on security testing. Coordinate and scope penetration testing with external partners.

• Lifecycle & Vulnerability Management: Triage zero-day vulnerabilities (e.g., SBOM analysis), assess reachability, and guide developer remediation efforts.

• Regulatory Compliance Support: Translate security controls into technical risk management documentation to satisfy international safety and cybersecurity standards.

We are looking for a person with the following experience:  

• Product/DevSecOps Expertise: hands-on experience in Product Security, Application Security, Embedded Systems Security, or DevSecOps.

• Software & Hardware Defense: Practical experience securing software components, APIs, and device/embedded environments.

• AppSec & Pipeline Security: Strong background in threat modeling, secure SDLC, and SAST/SCA/SBOM management tools.

• Security Testing: Experience conducting security reviews, vulnerability analysis, and utilizing tools like Burp Suite, OWASP ZAP, or Wireshark.

• Engineering Mindset: Ability to collaborate empathetically with developers, balancing security requirements with project delivery speeds.

Nice to have:

• Regulated Industry Experience: Prior background in Medical Devices (IEC 81001-5-1, FDA Guidance, IEC 62304), Automotive (ISO 21434), Aerospace, or Industrial IoT.

• Certifications: CSSLP, CEH, Security+, CISSP, or specialized product security certifications.

• Experience with cloud security platforms (AWS / Azure) or Infrastructure-as-Code scanning.

Why Join Us?

• High Impact: Your code and security architectures directly protect life-critical devices and connected healthcare systems.

• Modern Tooling: Work with cutting-edge CI/CD automation, modern hardware-security primitives, and dedicated external penetration testing resources.

• Cross-Functional Growth: Collaborate with top-tier internal security architects, regulatory experts, and system designers.

Our Offer

• Support – You will have a Qdev buddy by your side

• Flexibility – flexible working hours, vacation schedule

• Online and offline training/workshops and other knowledge-sharing possibilities

• Additional health and personal accident insurance

• Snacks and fun activities in the office

• Additional time off

• Personal and sport budget

• Loyalty benefits and perks

• Agile, friendly and international environment

• Gross salary in a range of 4400-7500 EUR (negotiable, based on competencies)

Apply Now

Product Cybersecurity Engineer
Max file size 10MB.
Uploading...
fileuploaded.jpg
Upload failed. Max size for files is 10 MB.
Thank you! Your application has been received!
Something went wrong while submitting the form.
Ukmergės G. 322, Vilnius
12106, Lithuania
LinkedIn
Privacy Policy