Product Security Engineer
Technology, Data & Digital · Software & Web Development · Software Engineering · Cybersecurity
In short
The Product Security Engineer will execute product security controls, participate in requirement analysis and threat modeling, and perform various security tests including fuzzing and vulnerability scanning. This role requires a Bachelor's or Master's degree with 4-6 years of experience in embedded systems or product security, and proficiency in Python scripting and industrial protocol security.
Responsibilities
- Execute product security controls such as secure boot, firmware integrity checks, authentication, and vulnerability mitigation.
- Participate in firmware/software requirement analysis, documentation, and threat modeling activities.
- Perform integration, system, and regression testing for embedded products.
- Execute security test cases including fuzzing, protocol security validation, and cryptographic checks.
- Conduct vulnerability scanning and document findings as per CVE/CWE standards.
- Validate security controls against IEC 62443-4-2 component requirements.
- Support development of automated test scripts using Python/scripting.
- Analyze and validate industrial communication protocol security (HART, Modbus, Ethernet/IP, ProfiNet).
- Collaborate with cross-functional engineering teams to support security deliverables.
Requirements
- Bachelor's or Master's degree in computer science / Electronics/ Instrumentation or related field
- Overall 4-6 yrs of experience in embedded systems or product Verification and Validation and Product Security
- Experience with firmware/hardware integration and security testing.
- Strong understanding of penetration testing methodologies and tools.
- Threat modeling and vulnerability analysis expertise.
- Experience with vulnerability scanning tools such as Nessus, OpenVAS, or Qualys.
- Familiarity with fuzzing tools (AFL, libFuzzer).
- Knowledge of industrial protocol security (HART, Modbus).
- Python scripting for test automation.
- Familiarity with OWASP Embedded Top 10 and CWE/CVE databases.
Desired Qualifications
- Demonstrate strong energy, ownership, and a bias for action.
- Show learning agility by quickly acquiring new skills, applying feedback, and strengthening core engineering fundamentals.
- Approach problems with structured thinking and sound engineering judgment to deliver practical solutions.
- Collaborate effectively across teams, leverage expertise when needed, and operate independently with accountability to deliver results.
Benefits
- Competitive benefits plans
- Variety of medical insurance plans
- Employee Assistance Program
- Employee resource groups
- Recognition programs
- Flexible time off plans
- Paid parental leave (maternal and paternal)
- Vacation and holiday leave
#Product Security#Embedded Systems#Firmware#Vulnerability Mitigation#Security Testing#Threat Modeling#Python Scripting#Industrial Communication Protocols