
Gravis Robotics
Posted 5 days ago
Cybersecurity Engineer
ZurichRemoteFull-time
AI Summary
Gravis Robotics is a startup turning heavy construction machines into intelligent and autonomous robots. Our unique combination of learning-based automation and augmented remote control enables a single operator to safely manage a fleet of earthmoving machines in a gamified environment.
About this role
Gravis Robotics is a startup turning heavy construction machines into intelligent and autonomous robots. Our unique combination of learning-based automation and augmented remote control enables a single operator to safely manage a fleet of earthmoving machines in a gamified environment. With over a decade of academic experience at the cutting edge of large-scale robotics, our team is rapidly translating this expertise into real-world deployments with industry leaders in a trillion-dollar market.
About the Role
At Gravis, we operate at the intersection of hardware, software, and real-world deployment. Our Rooftop Autonomous Control Kit (RACK) integrates sensing, compute, communication, and networking into a manufacturer-agnostic solution deployable across a wide range of construction machines.
As Cybersecurity Engineer at Gravis, you will own our digital security development across the full product lifecycle; from the embedded software stack inside the RACK hardware to our cloud infrastructure and supply chain. You will be the company's expert voice on EU Cyber Resilience Act (CRA) readiness. You will lead the security development lifecycle and embed security into our development processes from day one, mentoring the development team on best practices. As a member of the safety team, you will act as the trusted partner across engineering, product, legal, and operations. This is a high-impact individual contributor role with the mandate to build a security function as Gravis scales globally.
What You Will Do
Regulatory & Compliance
assessments against essential requirements, risk analysis, control design, and remediation
roadmaps
and policies; map to ISO 27001/27002/27036, NIST CSF, NIST SP 800-161, NIST SSDF, CIS
Controls, and OWASP
supply chain security, and GRC
Product Security
processes, vulnerability handling, coordinated vulnerability disclosure (CVD), PSIRT setup and
operations, SBOM generation, management, and vulnerability triage
strategies, metrics, and KPIs
Secure Engineering
Collaboration & Communication
plans, policies, process maps, and training materials
management.
Required Qualifications
Machinery Regulation) and GRC
CIS Controls, OWASP — including control mapping and tailored implementation
development/update pipelines) in a product or software organisation
vulnerabilities
executives
Nice To Have
Implementer/Auditor, CCSK, or CCSP
processes
mechanisms