Product Cybersecurity Engineer

$62,400 - $72,800/Yr

The Judge Group - Wyoming, MN

posted 8 days ago

Full-time
Wyoming, MN
Administrative and Support Services

About the position

The Product Cybersecurity Engineer will support the Chief Cybersecurity Engineer in developing and implementing the enterprise-wide product cybersecurity strategy. This role involves conducting threat analysis and risk assessments, providing guidance on security concerns, and ensuring compliance with cybersecurity regulations. The engineer will also be responsible for defining cybersecurity architectures and controls, managing key management systems, and promoting a cybersecurity culture within the organization.

Responsibilities

  • Support the Chief Cybersecurity Engineer in developing, communicating, and implementing the enterprise-wide product cybersecurity strategy & roadmap.
  • Provide guidance to stakeholders on security concerns and recommended controls.
  • Execute threat analysis and risk assessment (TARA) on various levels and mitigate identified risks by defining appropriate cybersecurity controls.
  • Develop, refine, and review cybersecurity requirements and gain approval from the Chief Cybersecurity Engineer.
  • Perform design reviews over internal and external cybersecurity solutions and mitigate weaknesses throughout the product life cycle.
  • Define in-vehicle cybersecurity architectures and develop cybersecurity controls such as secure boot and secure reprogramming.
  • Manage and provide guidance on key management systems and support supplier usage of the client PKI system.
  • Collaborate with the Ride Command team to ensure robust overall connected ecosystem cybersecurity.
  • Support triage and prioritization of vulnerabilities identified during verification and validation phases.
  • Support institutionalization of ISO/SAE 21434 processes and produce compliant work products.
  • Support regulatory compliance initiatives and supply chain integrity and security initiatives.
  • Promote cybersecurity culture by providing training to team members regularly.

Requirements

  • Bachelor's degree in computer science, computer engineering, software engineering, electrical engineering, IT security or other relevant domains.
  • 3+ years of experience in automotive cybersecurity, embedded system security, IoT security, or cyber-physical system security.
  • Experience with securing wireless communication protocols such as cellular, Wi-Fi, Bluetooth, and RF.
  • Experience with setting up and managing KMS, PKI, CA, and certificate/key management.
  • Experience with conducting threat analysis and risk assessment.
  • Experience with developing cybersecurity goals and requirement specifications.
  • Experience with designing cybersecurity controls such as secure boot and security access.
  • Experience with SELinux, App Armor, Hypervisor, TEE, HSM, etc.
  • Excellent written and verbal communication skills.

Nice-to-haves

  • Advanced degree in cybersecurity.
  • 10+ years of experience in automotive product cybersecurity.
  • Experience with symmetric and asymmetric cryptography and digital signatures.
  • Experience with developing telematics, infotainment, or connected ECUs.
  • Experience with implementing ISO/SAE 21434 processes.
  • Understanding of cybersecurity regulations and standards such as UNR 155 and NIST best practices.
  • Experience with CAN, CAN-FD, J1939, Ethernet, USB, etc.
  • Understanding of embedded RTOS and Linux based operating systems.
  • Experience with reporting and managing security issues in tools such as Jira.
  • Experience with modern programming languages like C, C++, Python, etc.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service