Jobs · Information Technology · Wisconsin

Senior Product Security Engineer

FTI · Menasha, WI · 2 wk ago
Information TechnologyFull-time

About the role

The Senior Product Security Engineer leads the security design and governance of our Industrial Internet of Things (IIoT) and Grid connected product portfolio. Reporting to the Cybersecurity Manager, this role is the primary technical authority for IIoT product security across the entire device lifecycle - from early design through field deployment and ongoing operation.

Responsibilities

  • Define and own the security architecture for connected IIoT products, including device identity frameworks (PKI/certificate management), secure boot chains, cryptographic key management, and hardware root of trust.

  • Establish and enforce security design requirements based on applicable standards and frameworks (e.g., IEC 62443, UL 2900, NERC CIP, NIST SP 800-82, NIST CSF) across product lines.

  • Design security boundaries and communication controls for environments where operational technology (OT) interfaces with enterprise IT systems, ensuring defense-in-depth across both layers.

  • Evaluate and provide security guidance on industrial communication protocols used in energy and grid applications (e.g., IEC 61850, DNP3, Modbus, CAN bus, GOOSE/Sampled Values).

  • Lead structured threat modeling exercises (e.g., STRIDE, PASTA) for new IIoT product initiatives and significant feature changes, translating identified risks into actionable design controls.

  • Assess and prioritize security risks across fielded and in-development device portfolios based on exploitability, potential impact to grid operations or physical safety, and business criticality.

  • Serve as the technical lead for coordinating responses to security vulnerabilities identified in fielded IIoT products, including working with Product, Engineering, and customers on disclosure and remediation timelines.

  • Evaluate hardware component and third-party software supply chain risks, providing security requirements for procurement and vendor selection of embedded components.

  • Act as the primary subject matter expert for IIoT and OT product security, providing high-context technical consultation to product architects, engineering leads, and executive leadership.

  • Own the product security standards, policies, and design review processes applicable to IIoT devices, ensuring teams have clear, actionable requirements before development begins.

  • Partner with Hardware, Firmware, Systems Engineering, and Product Management teams to embed security requirements early in the product development process without creating unnecessary friction.

  • Serve as the senior technical contributor during high-severity security incidents involving fielded IIoT products, leading root cause analysis and driving architectural improvements to prevent recurrence.

  • Coordinate with Threat Intelligence and engineering teams to document identified vulnerabilities and assist in drafting CVEs and public security advisories following successful remediation.

Requirements

  • Education: Bachelor's degree or equivalent experience in Information Security, Electrical Engineering, Computer Engineering, or a related technical field.

  • Experience: 5+ years of dedicated experience in product security, embedded/IIoT security, or OT/ICS security, with at least 2 years in a senior or lead capacity.

Qualifications

  • Industry-recognized security certifications preferred but not required (e.g., GICSP, CISSP, ISA/IEC 62443 Cybersecurity Certificate Program, CSSA).

Skills

  • Demonstrated expertise in securing embedded and IIoT devices, including secure boot, hardware security modules (HSMs), trusted execution environments (TEEs), and firmware security architecture.

  • Working knowledge of industrial communication protocols common in energy and grid applications (IEC 61850, DNP3, Modbus, CAN bus) and their associated security considerations.

  • Strong understanding of OT and ICS security principles, network segmentation strategies (e.g., Purdue Model, IEC 62443 zones and conduits), and the unique threat landscape of connected energy infrastructure.

  • Solid understanding of public key infrastructure, certificate lifecycle management for device identity, and applied cryptography as it relates to constrained embedded environments.

  • Deep familiarity with IEC 62443, UL 2900, NERC CIP, and NIST SP 800-82; ability to translate standards requirements into concrete, enforceable product security controls.

  • Proven experience leading structured threat modeling sessions for hardware/firmware products in OT or energy environments.

Benefits

  • Industry-leading benefits as an investment in the lives of team members and their families.

Pay

TBD

Schedule

Typical work hours are between 7:00 a.m. and 5:00 p.m. Monday – Friday. However, work may be performed at any time on any day of the week to meet business needs.

Company Overview

Cares about leading the way in construction, engineering, manufacturing and renewable energy. Cares about redefining how energy is designed, applied and consumed. Cares about thoughtfully growing to meet market demands. And ─ as “one of the Healthiest 100 Workplaces in America” ─ is focused on the mind/body/soul of team members through our Culture of Care.

Equal Opportunity Employer

At FTI, we are committed to providing equal employment opportunities to all individuals regardless of race, color, religion, sex, national origin, age, disability, veteran status, genetic information, sexual orientation, gender identity, or any other characteristic protected by law. We are proud to be an equal opportunity employer.

Similar jobs