- Company Name
- BrainPower
- Job Title
- Ingénieur Sécurité R&D senior
- Job Description
-
**Job Title:** Senior R&D Security Engineer
**Role Summary:**
Lead the integration of cybersecurity requirements across all product lines within a telecom and networking environment. Apply Security‑by‑Design principles throughout the agile development cycle, ensuring compliance with ISO 27001, Common Criteria, and other industry standards.
**Expectations:**
- Deliver end‑to‑end security solutions for embedded Linux systems, virtualization, IP routing, and optical transport technologies.
- Drive security strategy, policy implementation, and continuous improvement in a multicultural, international setting.
- Mentor teams, influence product architecture, and act as a trusted security advisor to clients and senior stakeholders.
**Key Responsibilities:**
- Define and enforce the R&D security strategy and internal security policies.
- Embed DevSecOps practices into CI/CD pipelines (SAST, DAST, SBOM, etc.).
- Conduct regular security audits and vulnerability assessments; maintain active monitoring of open‑source components (NVD, Debian repositories).
- Support pre‑sales activities (RFIs/RFPs) with security documentation and threat modeling.
- Participate in security incident investigations, including forensic analysis.
- Engage with clients’ CISOs to reinforce trust and align on security posture.
- Stay current on regulatory changes and emerging threats, updating controls accordingly.
**Required Skills:**
- 10+ years in software development, embedded Linux, and networking.
- Deep knowledge of cybersecurity frameworks: ISO 27001, Common Criteria, NIST, OWASP.
- Expertise in DevSecOps tools: SAST, DAST, SBOM, CI/CD, containerization, and orchestration.
- Proficiency with embedded Linux build systems (Yocto, Buildroot) and programming languages (C, C++, Python, Shell).
- Experience with virtualization and cloud platforms (Azure, GCP, AWS).
- Strong communication, leadership, analytical thinking, autonomy, and adaptability.
**Required Education & Certifications:**
- Bachelor’s + 5 (Master’s/Engineer’s) degree in Computer Science, Information Technology, or Telecommunications.
- Certifications such as ISO 27001 Lead Implementer, Certified Ethical Hacker (CEH), or equivalent are preferred.
---