IoT Cybersecurity Researcher (m/f/d)
We are building the first software to automate IoT cybersecurity compliance. Our flagship product, Z-CMS, streamlines EN 18031 compliance for IoT manufacturers under the Radio Equipment Directive Delegated Act. We are looking for someone who genuinely cares about this problem and wants to deepen our automation capabilities.
Apply NowRole & Responsibilities
As an IoT Cybersecurity Researcher, you will play a crucial role in further developing innovative features that automate EN 18031 compliance. Your contributions will support customers throughout their product lifecycle — from design and documentation to testing and maintenance. As a startup, your tasks will go beyond these core responsibilities and will include contributing to sales and marketing activities.
- Design software logic to enhance automation features
- Collaborate closely with customers and developers to refine the features
- Create and publish educational materials for our customers
Requirements
- Master's degree in computer science with focus on cybersecurity
- Several years of relevant industry experience in product/embedded system security, penetration testing, or applied security research
- Track record in IoT cybersecurity — publications, conference presentations, CVE disclosures, patents, or open-source contributions
- Strong understanding of IoT cybersecurity principles: network protocol security, secure boot, firmware updates, and security assessments
- Solid grasp of core CS and cybersecurity concepts: networking, Linux-based OS, cryptography, authentication & authorization, application security, and defense-in-depth
- Experience in conducting IoT penetration testing and vulnerability research
- Proficiency in Python or JavaScript, scripting (Bash), version control (Git), and familiarity with virtualization technologies
- Practical experience with firmware analyzers, traffic analyzers, and static/dynamic code analyzers
- Knowledge of threat modeling, risk analysis, and vulnerability management
- Must be located within commutable distance of Frankfurt am Main (relocation support possible, visa support not possible)
Preferred Qualifications
These are nice-to-haves. We encourage you to apply even if you do not meet all of them.
- PhD degree (or nearing graduation) in IoT cybersecurity or a related field
- Professional experience as an IoT cybersecurity tester or product security engineer
- Experience in customer-facing roles: training delivery, security guidance, advisory services
- Knowledge of IoT security standards: EN 18031, ETSI EN 303 645, IEC 62443-4-2
- Experience writing test plans and test reports
- Certifications such as OSCP, OSWE, or SANS training
Soft Skills
- Cooperative personality with excellent interpersonal skills, fostering positive relationships within the team and with stakeholders
- Quick learner with a creative approach to problem-solving and a genuine passion for automation
Benefits
Creative & Collaborative Culture
Innovate and implement your ideas within a supportive, collaborative work environment.
Real-World Impact
Work closely with IoT manufacturers to understand their challenges and develop novel solutions.
Industry Visibility
Establish yourself as an expert by publishing content on IoT cybersecurity and compliance.
Startup Experience
Gain firsthand experience building a business from the ground up — hard to find elsewhere.
Continuous Learning
O'Reilly Media subscription included, reflecting our commitment to your professional growth.
Competitive Salary
Competitive compensation with opportunities for rapid advancement based on performance.
Ready to apply?
Send your CV and a short introduction via email.