Product Security Officer* at TOMRA
5MK, Rheinland-Pfalz, Germany -
Full Time


Start Date

Immediate

Expiry Date

18 May, 25

Salary

0.0

Posted On

18 Feb, 25

Experience

0 year(s) or above

Remote Job

No

Telecommute

No

Sponsor Visa

No

Skills

Vulnerability, Nist, Communication Protocols, Penetration Testing, Iso, Threat Modeling, Encryption, Software Development, Authentication, Iec, Testing Tools, Computer Science, Scanning

Industry

Information Technology/IT

Description

Company Description
TOMRA Recycling is a global leader in automated sensor-based waste sorting and a pioneer in this field - currently TOMRA Recycling has an installed base of almost 6,460 units in more than 40 markets.
With our deep application knowledge, powerful machine learning software and a variety of in-house developed sensors, we offer our customers state-of-the-art, high-performance sorting solutions for maximum purity and yield.
At TOMRA, we want people to innovate, be passionate about their work and take responsibility. We encourage the freedom to innovate and take risks that lead to breakthroughs that challenge the status quo. We value passion that is focussed and committed to success. We believe in a responsible and safe mindset that takes care of our customers, products and employees.
Join the Resource Revolution!
Job Description
As a Product Security Officer, you will play a key role in ensuring the security of our industrial sorting machines from design to deployment. You will work cross-functionally with engineering, product development, and operational teams to integrate security best practices and safeguard our products against evolving threats.

Qualifications

  • Background in computer science with expertise in cybersecurity.
  • Understanding of industrial control systems (ICS) and embedded systems security.
  • Experience in secure software development, threat modeling, and risk management.
  • Knowledge of encryption, authentication, and secure communication protocols.
  • Familiarity with security testing tools, penetration testing, and vulnerability scanning.
  • Ability to communicate complex security concepts to non-technical stakeholders.
  • Experience with ISO 27001, IEC 62443, or similar frameworks is a big plus – willingness to become an expert is essential.
  • Strong problem-solving skills and ability to adapt to evolving security challenges.
  • Experience in the industrial manufacturing or automation industry is a plus.
  • Familiarity with GDPR, NIST, or other data protection regulations is an advantage
Responsibilities
  • Identify, assess, and prioritize security risks related to sorting machines throughout the product lifecycle.
  • Collaborate with engineering and product teams to integrate security best practices and secure design principles during the development phase.
  • Ensure products meet relevant industry security standards, regulations, and certifications (e.g., ISO, IEC).
  • Conduct regular security testing, vulnerability assessments, and audits to identify and address potential threats.
  • Lead incident response efforts in the event of security breaches, working to mitigate risks and prevent recurrence.
  • Maintain comprehensive security documentation for all products, including security protocols, testing results, and compliance records.
  • Provide ongoing security training and awareness programs for development, engineering, and operational teams.
  • Work closely with internal teams, third-party vendors, and customers to ensure product security requirements are met.
  • Oversee the implementation of security features and patches for existing products in the field.

Qualifications

  • Background in computer science with expertise in cybersecurity.
  • Understanding of industrial control systems (ICS) and embedded systems security.
  • Experience in secure software development, threat modeling, and risk management.
  • Knowledge of encryption, authentication, and secure communication protocols.
  • Familiarity with security testing tools, penetration testing, and vulnerability scanning.
  • Ability to communicate complex security concepts to non-technical stakeholders.
  • Experience with ISO 27001, IEC 62443, or similar frameworks is a big plus – willingness to become an expert is essential.
  • Strong problem-solving skills and ability to adapt to evolving security challenges.
  • Experience in the industrial manufacturing or automation industry is a plus.
  • Familiarity with GDPR, NIST, or other data protection regulations is an advantage.

Additional Information

Loading...