368,657open jobs
9,442companies
50,883added this week
Browse all
Location
Remote/Hybrid
Seniority
Senior · 4+ years exp
Employment
Contractor
Overview
Company
Impact
Profile match
CENSUS is a Greek cybersecurity company founded in 2008 and headquartered in Chania. It performs advanced security assessments, vulnerability research and secure development consulting. The company is known internationally for its offensive security research.

About CENSUS

CENSUS LABS is a cybersecurity engineering powerhouse specializing in

securing products and organizations. Our identity is rooted in

professionalism, engineering excellence, a scientific mindset, and

hacking demeanor. We are research-driven, enabling us to deliver a

diverse range of professional services.

CENSUS is trusted to conduct high-impact product security

engagements, helping our clients secure their solutions from design to

deployment, using realistic and risk-informed approaches. Our expertise

spans end-to-end systems, including Secure Communications, IoT, Medical

Devices, Mobile, and Vehicle Computing platforms.

Learn more about CENSUS at census-labs.com.

About the Job

CENSUS’ bespoke cybersecurity services are driven by a talented team

of Security Engineers, Consultants, and Researchers whose work goes

beyond traditional security assessment. Under the mentorship of our

Engineering Managers, our consultants perform technical evaluations of

complex systems and deliver insights that drive measurable

improvements.

We are seeking a technically strong and detail-oriented Senior

Product Security Consultant to join our Cybersecurity Engineering team.

The ideal candidate will have extensive experience in product-level

security verification, threat model analysis, and product-level

testing.

You will be responsible for evaluating the security posture of

software and system products by validating architecture, threat models,

and security controls. You will participate in structured evaluation

projects aligned with industry and regulatory standards such as Common

Criteria, ISO/IEC 27002, or equivalent frameworks.

Key Responsibilities

  • Review and validate security documentation (e.g., Security Targets, threat models, trust boundaries, asset inventories).
  • Assess the completeness, accuracy, and risk coverage of various

    threat models and risk assessment frameworks (STRIDE, LINDDUN, OWASP,

    TARA, TAL, etc.).

  • Verify security requirement traceability across assets, trust boundaries, and system functions.
  • Conduct architectural and implementation-level reviews of security controls (e.g., encryption, access control, key management).
  • Perform targeted security testing (white-box and black-box) on

    system APIs, client/mobile apps, backend services, and cloud

    infrastructure.

  • Validate implementation of cryptographic controls, key lifecycle procedures, and secure communication protocols.
  • Evaluate the use of post-quantum cryptography and hybrid models in secure key management.
  • Analyze secure deployment configurations across containerized

    platforms (Docker, Kubernetes), CI/CD pipelines, and cloud services.

  • Deliver comprehensive, standards-aligned technical reports based on evaluation findings.
  • Communicate product security risks clearly to both technical and non-technical audiences.

Minimum Qualifications

  • MSc or BSc in Computer Science, Electrical/Software Engineering, Cybersecurity, or a related technical discipline.
  • 4+ years of experience in product security, software evaluation, or penetration testing.
  • Proven ability to evaluate threat models, security requirements, and mitigation effectiveness.
  • Strong technical writing and documentation skills in English.
  • Excellent analytical skills and attention to detail.

Required Skills

  • In-depth understanding of security architecture and common

    system design patterns (e.g., API gateways, microservices, message

    queues, service meshes).

  • Hands-on experience performing design-level security reviews and verifying implementation alignment with defined threat models.
  • Familiarity with structured security frameworks such as Common Criteria, FIPS 140, ISO 15408, OWASP ASVS, and MASVS.
  • Practical experience with security testing in diverse product environments (mobile, embedded, web/cloud, API).
  • Knowledge of authentication, authorization, identity, and

    secrets management technologies (e.g., OAuth2, MFA, PKI, SSO, Cloud IAM,

    HashiCorp Vault).

  • Proficiency in applied cryptography (e.g., mTLS, E2EE, AEAD, key derivation, key wrapping, remote attestation).
  • Ability to identify security vulnerabilities across platforms (e.g., OWASP Top 10, misconfigurations, transport security gaps).
  • Excellent documentation and communication skills, able to articulate technical risks and findings to diverse audiences.
  • Problem solving skills, analytical thinking, and willingness to learn/grow.

Nice-to-Have Skills

  • Ability to read and analyze source code for logic flaws in one or more language families:
  • Mobile: Swift, Obj-C, Kotlin, Java, Dart, JavaScript
  • Web/Cloud: Java, Python, Go, PHP, Ruby, C#, JavaScript
  • Native/Embedded: C, C++
  • Experience debugging or instrumenting applications across edge, embedded, or cloud platforms.
  • Familiarity with Zero Trust architectures, enclaves, and confidential computing technologies.
  • Exposure to fuzzing, symbolic execution, or static analysis techniques.
  • Experience collaborating with distributed teams across different time zones and cultures.

OUR Values & Core Competencies

Act with Integrity

We uphold the highest ethical standards and take full responsibility

in every action - whether securing systems, researching vulnerabilities,

or collaborating with clients. Trust is the foundation of our impact.

Collaborate with Trust

We bring together diverse perspectives across disciplines and

borders, knowing that collective intelligence leads to stronger, more

resilient outcomes.

Challenge with Curiosity

We question deeply, explore fearlessly, and pursue knowledge

relentlessly to uncover threats, solve root problems, and drive smarter

security decisions.

Innovate to Protect

We create with purpose - building secure, scalable, and

forward-looking solutions that safeguard people, organizations, and the

digital future.

Adapt with Precision

We move with speed and discipline - learning from failure, refining

our approach, and staying focused amid complexity and constant change.

Ready to Make an Impact?

Apply today!

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
Platform Engineer 1 day ago
$87k – $140k per year • In office • Full-Time • 3+ years exp • Berlin
Databases
PostgreSQL
Redis
DevOps
AWS
Azure
Bicep
CI/CD
Docker
GCP
GitHub Actions
Kubernetes
OpenShift
Terraform
GitHub
Apply
Founding Engineer 1 day ago
$81k – $116k per year • In office • Full-Time • Bachelor's Degree • Munich
JavaScript
Python
TypeScript
Databases
MySQL
PostgreSQL
Frontend
Next.js
React.js
Tailwind CSS
DevOps
AWS
Azure
CI/CD
Docker
GCP
Grafana
Kubernetes
OpenTelemetry
Prometheus
Apply
$123k – $251k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Dallas • Denver • Birmingham
Java
SQL
Java
Gradle
Hibernate
Maven
Spring Boot
Spring Framework
Databases
Apache Kafka
MySQL
Redis
DevOps
CI/CD
Dynatrace
Jenkins
Kubernetes
OpenShift
Cybersecurity
SonarQube
Apply
$28k – $58k per year (Estimated) • Remote/Hybrid • Full-Time • 7+ years exp • Moscow
DevOps
Ansible
CI/CD
FinOps
Kubernetes
OpenStack
SLI/SLO/SLA
Terraform
VMWare
Apply
$230k – $260k per year • Equity • Remote • Internship • Bachelor's Degree
Python
DevOps
Amazon EKS
AWS
Azure
CI/CD
GCP
Helm
Kubernetes
Terraform
Cybersecurity
FedRAMP
Orca Security
Apply
QA Engineer 7 days ago
In office • Full-Time • 3+ years exp • Bachelor's Degree • Athens
C#
JavaScript
Python
TypeScript
Mobile
JUnit
DevOps
CI/CD
Docker
Git
GitHub Actions
GitLab CI
Jenkins
GitHub
GitLab
Cybersecurity
Burp Suite
OWASP ZAP
QA
Cypress
Jest
JMeter
k6
Locust
Playwright
Pytest
Selenium
TestNG
Vitest
Apply
In office • Full-Time • 4+ years exp • Bachelor's Degree
C#
Go
JavaScript
Kotlin
Lua
PHP
Python
Ruby
Rust
Swift
DevOps
AWS
Azure
GCP
IAM
Apply
In office • Full-Time • 4+ years exp • Bachelor's Degree • Abu Dhabi
C++
Rust
Apply
Remote/Hybrid • Internship • PhD • Thessaloniki
Python
Cybersecurity
Ghidra
IDA Pro
Apply
Remote/Hybrid • Full-Time • PhD • Thessaloniki
Assembly
Assembly
WinDbg
Cybersecurity
Ghidra
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.