Junior Cybersecurity Engineer - Cryptography and Hardware Security Testing (m/f/d)

Junior Cybersecurity Engineer - Cryptography and Hardware Security Testing (m/f/d)

Campanillas, MA, ES, 29590

Key Area:  Product Testing & Laboratory Services
Level of Experience:  Entry Level
Employment Type:  Permanent
Full Time / Part Time:  Full Time
Weekly Hours:  40.00
Remote Working:  Hybrid
Requisition ID:  6845
Posting Date:  Sep 29, 2026

Do you want to boost the future towards a safe, secure and sustainable world?


 

Do you want to boost the future towards a safe, secure and sustainable world? Build your career in applied cryptography and product security by learning how the security-critical components are tested and evaluated in real products.

 

At DEKRA Digital Trust Services, we help technology companies demonstrate that their products meet demanding security requirements. In our Cybersecurity Laboratory, you will work with experienced specialists on the evaluation of cryptographic modules, embedded systems and secure hardware, covering software, firmware and hardware implementations.

 

As a member of our Crypto Team in Cybersecurity, you will contribute to the evaluation of cryptographic algorithms, protocols and security-critical implementations across a wide range of projects. Our team works with topics including cryptographic module testing, implementation security, random number generation, entropy evaluation, hardware security, side-channel analysis, fault injection and post-quantum cryptography. Besides, you will support projects involving FIPS 140-3 and ISO/IEC 19790, which define security requirements for cryptographic modules, the components responsible for functions such as encryption, digital signatures and cryptographic key management.

 

As part of project activities, you will evaluate and verify the security of products and systems ranging from software-based cryptographic modules to embedded and hardware-based security components. Working alongside experienced specialists, you will progressively gain exposure to different technical areas and testing methodologies. Depending on project needs and development opportunities, you may contribute across multiple domains and gradually build expertise spanning the full scope of the team's activities.

 

What will your work involve?

Working in a team under the guidance of experienced evaluators, you will:

  • Analyze the implementations of cryptographic algorithms and protocols from a security perspective.
  • Review technical documentation, product architecture and relevant source code to understand how a cryptographic module is designed and operates.
  • Translate security requirements into test activities using the laboratory’s procedures and tools.
  • Set up test environments, execute tests and investigate unexpected results. Depending on the project, this may include checking authentication, cryptographic key handling, self-tests and error conditions.
  • Support cryptographic algorithm testing and develop or adapt scripts to automate tasks and analyze results.
  • Contribute to the review of random number generators and entropy sources, including design evidence, data sets and statistical results. 
  • Contribute to implementation-security testing, including side-channel analysis and fault injection testing, according to your background and development path.
  • Identify gaps or inconsistencies between the implementation, its documentation and the applicable requirements.
  • Work with senior colleagues and client engineering teams to clarify findings, obtain supporting evidence and verify corrections.
  • Prepare clear, traceable test records and technical reports, and support the preparation of validation submissions and responses to review comments.

 

What do you need to bring?

  • A degree in Computer Science, Mathematics, Telecommunications, Cybersecurity, Physics, Electrical/Electronic Engineering or a related discipline.
  • A basic understanding of cryptography, including symmetric and asymmetric encryption, hashing and digital signatures.
  • Practical programming or scripting experience. Academic projects, internships and personal projects count; Python and/or C/C++ are particularly relevant.
  • The ability to approach problems systematically, investigate technical details and explain your reasoning.
  • English skills sufficient to read technical standards, write clear reports and participate in technical discussions.
  • Attention to detail, a collaborative attitude and a willingness to learn from feedback.

 

The following would be useful, but are not essential:

  • Familiarity with Linux, command-line tools, debugging or software testing.
  • Experience with cryptographic libraries, embedded systems, PKI or secure communication protocols such as TLS, SSH or IPsec.
  • Exposure to FIPS 140-3, ISO/IEC 19790, cryptographic algorithm testing, random number generation or entropy assessment.
  • Knowledge of statistics, electronics, signal processing, side-channel analysis or fault injection.
  • Academic or personal projects involving applied cryptography, embedded security or security evaluation.

 

How will you develop?

This is primarily a junior role. Previous experience with FIPS 140-3, entropy evaluation or advanced hardware attacks is not required. We welcome recent graduates and early-career professionals with solid technical foundations, curiosity and a methodical approach. Candidates who already have deeper knowledge in one or more of these areas are also encouraged to apply, as responsibilities can be adapted to experience.

 

You will learn the relevant standards, testing methods, laboratory practices and reporting expectations through training, mentoring and guided project work. You will begin with supervised tasks and progressively take responsibility for defined parts of an evaluation as your knowledge and experience grow. 

 

Depending on your interests, existing knowledge and project needs, you can develop expertise in areas such as cryptographic module evaluation, algorithm testing, entropy assessment, secure hardware, side-channel analysis, fault injection, embedded security or post-quantum cryptography. 

 

What do we offer?

  • A permanent contract with hybrid working options based around our Málaga (Parque Tecnológico) office.
  • Flexible working arrangements, with early finishes on Fridays and during the summer.
  • Health insurance fully paid by the company.
  • Access to meal, childcare, transport and Wellhub benefit options.
  • Professional development through internal and external training, certification programs and opportunities to participate in cybersecurity events.
  • English lessons to support your continued development.
  • Projects with leading technology companies and collaboration with experienced cybersecurity specialists.
  • Employee referral incentives, the KUDOS recognition program and discounts across major brands.
  • Healthy snacks and free coffee in the office.

If you enjoy understanding how technology works, investigating details and turning technical findings into clear conclusions, we would like to hear from you. Tell us about a project, course or practical experience that sparked your interest in cybersecurity or cryptography.

At DEKRA we value your unique experiences, perspectives, and backgrounds. We are committed to an inclusive workplace for all team members.