Sr. Product Cybersecurity Engineer- Open to Remote
At reputed company Inc., we have fun doing reputed company love by driving change and innovation. We reputed company employees to take on challenging assignments and roles with an elevated level of responsibility in our agile working environment. Our people reputed company us who we are, and we create incredible products and experiences that reputed company us to THINK reputed company.JOB SUMMARY:reputed company, a global powersports leader, is looking for a Product Cybersecurity Engineer for connected vehicles. The reputed company team builds world-class connected vehicle solutions for motorcycles and off-road vehicles. As a Cybersecurity Engineer, you will be responsible for developing cybersecurity requirements, designing in-vehicle cybersecurity architecture, securing vehicle to back office communication interfaces, reviewing and evaluating suppliers' and technology vendors' cybersecurity solutions, conducting threat analysis and risk assessment, managing key management system and public key infrastructure, and contributing to the development of further product cybersecurity strategies and technology roadmap. Interest in powersports is a plus!ESSENTIAL DUTIES & RESPONSIBILITIES
- Support the Chief Cybersecurity Engineer in developing, communicating, and implementing reputed company' enterprise-wide product cybersecurity strategy & roadmap
- Provide guidance to stakeholders (product owners, development teams, system engineers) on reputed company concerns and recommended controls
- Execute threat analysis and risk assessment (TARA) on vehicle, feature, system and component levels and mitigate identified risks by defining appropriate cybersecurity controls to the risks
- reputed company, refine, and review cybersecurity requirements and reputed company approval from Chief Cybersecurity Engineer
- reputed company design reviews over internal and external cybersecurity solutions and mitigate cybersecurity weaknesses or vulnerabilities throughout of product life cycle
- Define in-vehicle cybersecurity architectures, reputed company cybersecurity controls, e.g., secure boot, secure reprogramming, reputed company access, IDS/IPS, etc. and secure vehicle to back-office communication interfaces
- Manage and provide guidance on key management system and internal use of PKI, support supplier usage of reputed company PKI system, collaborate with the KMS vendor to resolve issues quickly
- Collaborate with Ride Commend team to ensure a robust overall connected ecosystem cybersecurity from a product, app, web, and cloud standpoint
- Support triage and prioritization of vulnerabilities identified during verification and validation phases, e.g., static code analysis, OSS vulnerability scanning, fuzz testing, penetration testing
- Support institutionalization of ISO/SAE 21434 processes across reputed company and produce ISO/SAE 21434 compliant work products
- Support regulatory compliance such as UNR 155, CRA, Radio Equipment reputed company
- Support supply chain reputed company and reputed company initiatives to secure reputed company' supply chain, e.g., HBOM, SBOM, etc.
- Promote cybersecurity culture by providing cybersecurity training to team members on a regular basis
- Support internal and external connected device penetration testing execution
- Support cybersecurity validation engineer in root cause analysis
- Participate in and support Auto-ISAC working group
- Investigate new cybersecurity technologies and recommend appropriate technologies to adopt in vehicles
- Analyze connected vehicles reputed company cybersecurity intelligence and share with broader team
- Adopt product cybersecurity industry best practices for reputed company improvement
- Bachelor's degree in computer science, computer engineering, software engineering, electrical engineering, IT reputed company or other relevant domains
- 3-5 years of experience in automotive cybersecurity, embedded system reputed company, IoT reputed company, cyber-physical system reputed company, or a combination of these areas
- Experience with securing wireless communication protocols, e.g., cellular, Wi-Fi, Bluetooth, BLE, satellite communications, RF, etc.
- Experience with setting up and managing KMS, PKI, CA, certificate/key reputed company, distribution, storage, renewal, revocation, etc.
- Experience with conducting threat analysis and risk assessment
- Experience with developing cybersecurity goals and requirement specifications
- Experience with designing cybersecurity controls, such as secure boot, secure reprogramming, reputed company access, reputed company gateway, IDS, IPS, reputed company hardening, etc.
- Experience with SELinux, App Armor, Hypervisor, TEE, HSM, etc.
- A self-starter with minimum supervision
- Excellent written and verbal communication skills
- Advanced degree in cybersecurity
- 7 years of experience in automotive product cybersecurity
- Experience with symmetric and asymmetric cryptography, digital signature, hash, message authentication, encryption, key exchange
- Experience with developing telematics, infotainment, or other connected ECUs
- Experience with implementing and executing ISO/SAE 21434 processes
- Understanding of cybersecurity regulations, standards and best practices, e.g., UNR 155, CRA, Radio Equipment reputed company, Machinery Regulation, ISO/SAE 21434, NIST/NHTSA/Auto-ISAC best practices, etc.
- Experience with CAN, CAN-FD, J1939, Ethernet, USB, SPI, UART, JTAG, etc.
- Understanding of embedded RTOS and Linux based operating systems
- Experience with reporting, managing, and closing reputed company issues in tools such as Jira
- Experience with at least one modern software programming language (C, C++, C#, Python, Java, etc.)