Product Security Engineer
Saur Energy International · Location, WV · Yesterday
Full-time
Responsibilities
- Support product security regulatory compliance activities, including the European Cyber Resilience Act (EU CRA).
- Act as a product security representative to support secure development lifecycle implementation efforts.
- Participate in new product development process audits and security assessments.
- Perform product security risk assessments and threat modeling activities.
- Identify, assess, prioritize, and help mitigate vulnerabilities and security threats impacting products and solutions.
- Collaborate with business units to inventory products and support risk prioritization initiatives.
- Coordinate security scans and penetration testing activities, analyze results, and ensure remediation of identified vulnerabilities.
- Support vulnerability management programs and Product Security Incident Response Team activities.
- Aid in product security training and awareness initiatives.
- Maintain knowledge of applicable industry standards, including IEC 62443, IEC 29147, IEC 30111, ISO/IEC 27001, and NIST SP 800-218.
- Participate in embedded software development projects based on business requirements.
- Translate product specifications into software requirements.
- Design, develop, test, and maintain embedded software modules.
Requirements
- Bachelor’s degree in Engineering, Computer Science, Information Security, or a related discipline, or equivalent relevant experience.
- Experience in product security, secure product development, cybersecurity governance, or related domains.
- Understanding of Secure Development Lifecycle (SDL), Secure-by-Design, and Defense-in-Depth principles.
- Knowledge of IEC 62443 and cybersecurity governance practices.
- Familiarity with European Cyber Resilience Act (CRA) requirements.
- Experience with cybersecurity standards and frameworks such as IEC 62443, ISO/IEC 27001, NIST SP 800-218, COBIT, or NIST Cybersecurity Framework.
- Knowledge of Software Bill of Materials (SBOM) concepts and implementation.
- Hands-on experience with static code analysis tools such as Coverity.
- Experience designing embedded systems using multitasking real-time operating systems (RTOS) such as VxWorks, UCOS, ThreadX, FreeRTOS, or MQX.
- Strong programming skills in C and C++.
- Familiarity with RTOS environments such as VxWorks, UCOS, ThreadX, FreeRTOS, or MQX.
- Knowledge of communication protocols such as RS232, SPI, and I2C.
- Experience with Linux environments, including U-Boot, Linux Kernel, GDB, and CMake.
- Understanding of embedded security best practices.
Qualifications
- Strong problem-solving, organizational, communication, and collaboration skills.
Preferred Qualifications
- Experience supporting cybersecurity regulatory compliance initiatives within industrial or embedded product environments.
- Knowledge of vulnerability management and product security incident response processes.
- Experience conducting threat modeling, penetration testing coordination, and security risk assessments.
- Exposure to industrial automation, embedded product development, or operational technology (OT) security.
- Ability to work effectively in global, cross-functional teams and manage multiple priorities.