MENU

$name

Penetration Tester & Product Security Specialist

: 2026-09-14

IT, Finance & Compliance
Nils Foss Allé 1
3400  Hillerød



Denmark

At FOSS, we are driven by a strong sense of purpose, and we hope you are too. By 2030, the world population will exceed 9 billion and the middle class will have doubled. This means we will need to be outstandingly smart about our global food production. FOSS is on a mission to enable the sustainable use of the planet’s food resources, and thus to the nutrition of the people of the world. As a global market leader, we contribute through innovative food analysis, which is used to secure food quality, reduce waste, and optimize food production. If that sounds like something you’d like to be a part of, read on!

What you will be doing

FOSS products are increasingly connected to customer networks and must meet growing cybersecurity requirements. Under the EU Cyber Resilience Act, we must report actively exploited vulnerabilities within 24 hours from September 2026 and demonstrate compliance for products sold in the EU from December 2027. Around 60 instrument and cloud platforms are in scope, and R&D has already started threat modelling.

We now need a new colleague who can validate our products' security through penetration testing and establish a vulnerability management approach that customers, auditors, and regulators can trust.

As our new Penetration Tester & Product Security Specialist, you will build this capability from the ground up. Reporting to the Head of Information Security, you will work closely with R&D to embed security into products, supported by a clear mandate, strong management focus, and a security team that has already identified the key gaps.

Key responsibilities include:

  • Plan and carry out hands-on penetration testing of FOSS instruments, instrument platforms, embedded components and cloud solutions, across Windows, Linux, embedded targets, web interfaces, APIs and Azure. You report findings so they can be acted on: reproducible, realistically rated, and written for the engineer who will fix them
  • Own our penetration testing program and decide what gets tested and how often, what we do in-house, and where specialist external testing is the right answer
  • Build and run vulnerability management for the portfolio: establish screening based on Software Bills of Materials, keep it current as products change, and triage what it produces by assessing exploitability in the real product context and driving what matters to closure with the responsible teams
  • Operate the vulnerability handling process the Cyber Resilience Act requires, including readiness to support 24-hour early warning and 72-hour full notification, and how we receive reports from researchers, customers and service engineers
  • Support R&D on product risk assessments and STRIDE threat modelling, bringing the attacker’s perspective that makes an assessment credible rather than procedural, and helping the teams get better at it themselves
  • Advise on secure design and secure development with IEC 62443-4-1 and 62443-4-2 as the working frame, since our products are components in industrial automation environments
  • Contribute the technical substance behind Cyber Resilience Act conformity: security requirements, test evidence, and technical documentation that must stand up to a notified body

What we hope to see you bring

We are looking for a specialist, and we know this combination is not common. If you are strong on most of the essentials and genuinely interested in the rest, apply and tell us which is which.

We hope to see you bring:

  • Demonstrable hands-on penetration testing experience against real systems, covering scoping, execution and reporting rather than scanning alone. Embedded or industrial targets, or a clear appetite to move into them
  • Strong software engineering skills in C, C++, C#, Python or comparable. You can read and reason about production code, follow a build and release pipeline, and discuss a finding with a developer as a peer
  • Working knowledge of IEC 62443, in particular 4-1 and 4-2, and how it applies to a product manufacturer rather than to a plant operator
  • Practical vulnerability management: SBOM and software composition analysis, CVE and CVSS, VEX, and the judgement to tell an exploitable finding from a theoretical one
  • Professional-level English, written and spoken, as this is our working language. Danish is an advantage in our Danish organization, but not a requirement
  • Credibility with engineers and the ability to influence without authority. You will not manage the teams that have to act on your findings, so the role works through persuasion and earned trust
  • Structure and follow-through. A finding that is reported and forgotten has cost us money and bought us nothing
  • Sound judgement under time pressure and discretion with sensitive information. Some of this work runs against a 24-hour reporting clock, and you will know about unfixed vulnerabilities in products our customers depend on

Why choose FOSS?

You get end-to-end ownership of product security testing and vulnerability management across a full portfolio, from embedded instruments to cloud services, in a company where those products are the business rather than a side activity. The role exists because of a deadline with board-level attention, and it reports to the Head of Information Security rather than sitting several levels down in a delivery team. That is a real mandate, and it comes with technical variety that is hard to find in one place: analytical instrumentation, embedded platforms, industrial connectivity and cloud.

You join a small, close-knit security team where your work is visible and your scope grows with your ability, in a global, family-owned company with strong engineering traditions and colleagues who take quality seriously. We support relevant certification and further training, including the offensive security certifications that are expensive to fund yourself.

The position is full-time and based at the FOSS Innovation Centre in Hillerød. Onsite presence matters in this role, because it depends on being close to the R&D colleagues you will be working with, and occasional travel can occur.

We would love to hear from you!

If you’re ready to take the next step in your career and contribute to a purpose-driven organization, we would love to hear from you.

Submit your application through the link below. Please note that only applications sent through the link will be considered. We review applications on an ongoing basis and encourage you to apply early. If you have any questions about the role, please contact Christian Ryge, Head of Information Security, at +45 2091 6692.

We look forward to receiving your application!

FOSS is committed to maintaining an inclusive and diverse culture. You can help us sustain an unbiased recruitment process by not including photo and age in your application.

About FOSS  

Today, more than 8 billion people around the world are dependent on nutritional food. Tons of food being produced in a million different ways and under varying conditions, creating challenges all the way from field to fork. One of them, obviously, is the effect it has on climate change. 

FOSS helps the world’s 100 biggest food companies, and more than 40,000 others around the world navigate exactly that with intelligent, data-driven and innovative analytical solutions. We are making sustainability a better business, and we’re doing so as the global market leader in our field – improving food quality, minimizing food waste, ensuring food safety, and securing fair payment.

Join a pioneering and innovative company in the food and agriculture industry. A company on a mission, with offices all around the world and 1,750 talented colleagues across 34 different countries.


back to top icon
The content is hosted on YouTube.com (Third Party). By showing the content you accept the use of Marketing Cookies on Fossanalytics.com. You can change the settings anytime. To learn more, visit our Cookie Policy.