Security and safety evaluation lab for embedded systems and critical infrastructure
SERMA Safety and Security operates a multi-site security evaluation and consulting practice across France, with a technical stack weighted heavily toward threat detection, identity and access management, and compliance frameworks (Palo Alto Networks, Splunk, CyberArk, ISO 27001/27005). The hiring mix—security roles outnumber engineering by 5:1—reflects a service-delivery model rather than product-focused scaling. Active projects center on embedded device security, mobile security tools, and SOC integration, while pain points around audit capacity expansion and vulnerability remediation suggest they are scaling assessment throughput faster than internal tooling can support.
SERMA Safety and Security is a French security and safety consultancy founded in 2015, operating across nine regional sites with a focus on systems where security and safety cannot be decoupled. They serve clients in IoT, embedded systems, industrial control, and information security, offering three core service lines: cybersecurity assessments and hardening for software and IoT products; security evaluation and certification (holding credentials including CESTI, PASSI RGS, SESIP, and FIPS); and functional safety consulting for critical systems using formal methods. The firm works across the product lifecycle—from design review through operational oversight—and delivers training alongside advisory services. Clients span banking, telecoms (GSMA audit programs), and industrial verticals.
Security and safety evaluation, certification, and consulting for embedded systems, IoT products, and critical infrastructure. They run a security evaluation laboratory and provide compliance assessments against standards including ISO 27001, CESTI, and FIPS.
Headquartered in Pessac, Nouvelle-Aquitaine, France, with nine operational sites across the country. All hiring is conducted in France.
Stack includes Palo Alto Networks, Checkpoint, Fortinet, Tenable, Splunk, CyberArk, Checkmarx, Wallis, Proofpoint, and Qualys for threat detection, vulnerability management, identity governance, and SIEM operations.
Other companies in the same industry, closest in size