Role Overview
Join a Platform Engineering team as a security tools engineer, focusing on static code analysis, to help developers find and fix vulnerabilities before shipping. The team is responsible for security-related tooling, including vulnerability scanning and management, supply chain evaluation, and static code analysis.
What You Will Do
Configure and refine Coverity's static analysis capabilities, support AXIS OS developers in using static code analysis effectively, and evaluate and introduce new features and capabilities related to static code analysis.
Why It Might Be a Fit
The role requires a security mindset, experience with software development, and a genuine interest in application security and code quality. The team values teamwork, collaboration, and open communication.
Requirements
- University degree in Computer Science or a comparable qualification
- Professional experience with software development, with a genuine interest in application security and code quality
- Solid understanding of software development process and life cycle with focus on Continuous Integration (CI)
- Hands-on experience with static code analysis tools, e.g. Coverity, SonarQube, or similar
- Knowledge of C and C++ development, secure coding practices, and standards such as CERT C/C++ or MISRA C
- Experience with vulnerability management, supply chain security, or compliance work, e.g. the EU Cyber Resilience Act (CRA) or ISO 27001
- An understanding of embedded development
- Experience with git and code review tools, e.g. Gerrit
Benefits
- Dental insurance
- Vision insurance
- Work/life balance
- Social activities with colleagues
- Opportunities for growth and development