Eaton Corporation - Moon, PA

posted 3 months ago

Full-time - Mid Level
Moon, PA
Electrical Equipment, Appliance, and Component Manufacturing

About the position

As a Senior Hardware Cybersecurity Engineer at Eaton's Electrical Sector, you will be an integral part of a global team dedicated to enhancing cybersecurity initiatives within Eaton's product solutions. This role is pivotal in supporting the Product Cybersecurity Center of Excellence's mission, which involves conducting extensive research and development, evaluating products and solutions, and performing design reviews. You will engage in coding, scripting, and developing procedures for new cyber tools and automation, as well as conducting scanning and associated analysis. Additionally, you will manage lab environments and oversee small projects, contributing to idea and concept generation while participating in product assessment planning and reviews. In this position, your responsibilities will include performing threat modeling for hardware and embedded products, identifying security requirements, and conducting penetration testing and risk assessments. You will review the security features and datasheets of various chipsets used in residential and industrial embedded devices, recommending appropriate chipsets for our products. Your role will also involve participating in architectural reviews of hardware designs that impact critical security components such as hardware root of trust, bootloaders, secure boot processes, and certificate/key storage across various platforms. You will set up various tools to perform hardware security testing and propose mitigation techniques to the product development team. Automating the hardware testing process, including secure boot and secure firmware upgrade functionalities, will be a key aspect of your work. Furthermore, you will build tools, scripts, and automation frameworks around security to achieve a significant impact at Eaton's scale.

Responsibilities

  • Perform Hardware and Embedded product threat modeling, identify hardware security requirements and perform pen testing & risk rating.
  • Review the security features and datasheet of various chipsets used in the residential and industrial embedded devices and recommend right chipsets for our products.
  • Take part in architectural reviews of the hardware designs that impact hardware root of trust, bootloader, secure boot, certificate/key storage etc. on various platforms.
  • Setup various tools and perform Hardware security testing and propose the mitigation techniques to product development team.
  • Automate the hardware testing process including secure boot and secure firmware upgrade functionalities.
  • Build tools, scripts, and automation frameworks around security to achieve Eaton-scale impact.

Requirements

  • Bachelor's degree in Computer Security, Computer Science, Electrical Engineering, or similar fields with emphasis in Cybersecurity and at least 2 years of experience in threat modeling and working with hardware security testing tools, OR a Master's degree in the same fields.
  • Knowledge of hardware security features such as TrustZone, HSM, TPM, secure elements, etc.
  • Experience in writing scripts for tools such as Open OCD with focus on programming languages such as Python and Java.
  • Working knowledge of networking fundamentals, network protocols, and Access Control (i.e., User Authentication and Identity Management).
  • Must be able to relocate to Pittsburgh, PA (Moon Township).
  • Must be able to work in the United States of America without sponsorship now or in the future.

Nice-to-haves

  • Understanding of hardware supplier risk rating methodologies; knowledge of hardware attacks such as Side channel attacks and Fault injection attacks.
  • Knowledge of Computer system security technologies, Embedded systems security, Symmetric and Asymmetric cryptography, PKI, X509 certificate generation, PKCS standards, etc.
  • Knowledge of cybersecurity standards and protocols such as IEC 62443, UL2900, IEC15118, SAE21434, PKCS, Matter, and EV Charger security such as OCPP.

Benefits

  • Health and Welfare benefits
  • Retirement benefits
  • Programs that provide for paid and unpaid time away from work
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service