Key Responsibilities
ā¢Ā Ā Ā Conduct vulnerability assessments, coordinate penetration testing activities, and perform risk analysis.
ā¢Ā Ā Ā Support secure system architecture reviews and threat modeling initiatives.
ā¢Ā Ā Ā Enforce organizational security policies, standards, and procedures.
ā¢Ā Ā Ā Investigate security incidents and lead root cause analysis along with remediation actions.
ā¢Ā Ā Ā Ensure alignment with relevant standards such as IEC 62443, EN18031, and ISO 27001.
ā¢Ā Ā Ā Support cybersecurity compliance initiatives including IEC 62443, EU CRA, ISO 27001, and NIST frameworks.
ā¢Ā Ā Ā Maintain security documentation, playbooks, and incident response plans.
ā¢Ā Ā Ā Ensure secure design principles are applied, including least privilege, defense in depth, and secure defaults.
ā¢Ā Ā Ā Validate secure implementation of requirements and mitigation strategies.
ā¢Ā Ā Ā Perform security testing on firmware releases from development teams.
ā¢Ā Ā Ā Apply Static Code Analysis techniques to identify security vulnerabilities in code.
ā¢Ā Ā Ā Conduct Software Composition Analysis to support software supply chain security.
ā¢Ā Ā Ā Participate in unit testing and secure code reviews.
ā¢Ā Ā Ā Continuously improve security practices by staying informed on emerging threats, tools, and industry practices.
ā¢Ā Ā Ā Collaborate with DevOps and engineering teams to integrate security practices within CI/CD pipelines.
Required Qualifications
ā¢Ā Ā Ā Minimum 5 years of experience in industrial cybersecurity or IT/OT security environments.
ā¢Ā Ā Ā Engineering degree or equivalent experience in Software Engineering, Computer Science, or Cybersecurity.
ā¢Ā Ā Ā Strong programming skills in C and C++.
ā¢Ā Ā Ā Solid understanding of encryption algorithms, key management, and secure protocols such as TLS and SSH.
ā¢Ā Ā Ā Knowledge of common software vulnerabilities including OWASP Top 10 and CWE/SANS Top 25.
ā¢Ā Ā Ā Familiarity with Linux, Windows, RTOS environments, and network protocols such as TCP/IP, DNS, and HTTPS.
ā¢Ā Ā Ā Understanding of industrial communication protocols including Serial, Modbus, and HART.
ā¢Ā Ā Ā Familiarity with cybersecurity frameworks and standards such as IEC 62443, ISO 27001, NIST, and OWASP.
ā¢Ā Ā Ā Self-motivated with the ability to work effectively in a collaborative team environment.
ā¢Ā Ā Ā Experience working with Software Bill of Materials (SBOM).
Preferred Qualifications
ā¢Ā Ā Ā Experience implementing DevSecOps practices within software development lifecycles.
ā¢Ā Ā Ā Hands-on experience with Azure DevOps or similar CI/CD platforms.
Ā
arrow