Engineer

Engineer

Shenzhen Office, CN

Key Area:  Product Testing & Laboratory Services
Level of Experience:  Entry Level
Employment Type:  Fixed-Term
Full Time / Part Time:  Full Time
Weekly Hours:  40
Remote Working:  Onsite
Requisition ID:  6106
Posting Date:  Jul 21, 2026

Do you want to boost the future towards a safe, secure and sustainable world?

At DEKRA we deal with future topics in every field of work: from vehicle inspection to cyber security, from product testing to clean energies or from automated driving to artificial intelligence. We anticipate technical developments early on and drive industry transformation as thought leaders. For the exciting tasks that lie ahead we are looking for skilled and passionate people who want to grow and achieve their best in a global team. Enthusiasts wanting to do meaningful work and to make a contribution as a trusted partner for our clients and for society. People like you. 
 

A Day in the Life and the Impact You’ll Make:

We are looking for an experienced Cybersecurity Engineer to perform product security testing and penetration testing based on Common Criteria frameworks, support ICT product and cryptographic module certification projects, and provide technical consulting on Common Criteria, FIPS 140-3, and ISO/IEC 19790 standards.

What You’ll Do:

  • Perform security testing and penetration testing based on Common Criteria frameworks.
  • Collaborate with other cybersecurity engineers to complete security testing and certification projects.
  • Provide clients with security testing and penetration testing plans based on threat modeling and security frameworks.
  • Offer consulting and technical support to clients based on Common Criteria, FIPS 140-3, and ISO/IEC 19790 standards.
  • Analyze identified security risks and propose mitigation or remediation solutions.
  • Conduct vulnerability assessments, exploit testing, and reporting for targets of evaluation.
  • Assist in security certification and compliance projects for ICT products and cryptographic modules.
  • Audit product cryptographic algorithm implementations (AES, RSA, ECC, HMAC, etc.) and key management policies in accordance with FIPS 140-3 requirements.
  • Verify the quality of entropy sources for deterministic random bit generators (DRBGs) to ensure compliance with statistical randomness requirements.
  • Maintain accurate documentation and provide reports for internal and external stakeholders.
  • Stay updated on emerging technologies and security threats to continuously improve testing methods.

What You’ll Bring:

  • Bachelor’s degree or above in Information Technology, Cybersecurity, Software Engineering, or a related field.
  • At least 5 years of experience in information technology, cybersecurity, software engineering, or a related field, including at least 2 years in security or penetration testing.
  • Proficiency in security and penetration testing for Web, App, IoT, or Android systems, with knowledge of common vulnerability principles, detection, exploitation, and mitigation methods.
  • Skill in using common penetration testing tools and conducting threat modeling.
  • Knowledge of Common Criteria, FIPS 140-3, ISO/IEC 19790, and cybersecurity best practices.
  • Strong English communication, documentation, and teamwork skills.

Nice to Have

  • Experience in ICT product Common Criteria projects or cryptographic module certification.
  • Certifications such as CISSP, OSEP, or OSCE.

What You’ll Receive for the Value You Bring:

  • A culture of trust, collaboration, and continuous learning
  • A secure, future-oriented employer committed to your personal and professional growth


At DEKRA we value your unique experiences, 
perspectives, and backgrounds. We are committed to an inclusive workplace for all team members.