
Product Cybersecurity Engineer
Posted 1 hour ago

Posted 1 hour ago
This is a fully remote position, open to applicants in United States.
• Incorporate security practices such as threat modeling and architecture reviews into product development processes from the requirements stage to release.
• Offer early security insights on hardware, firmware, and software design choices, taking into account third-party and supply chain risk factors.
• Draft, assess, and verify security requirements across both hardware and software domains; enforce secure coding practices and conduct security analyses on primary computing systems.
• Help maintain the Software Bill of Materials (SBOM) and Hardware Bill of Materials (HBOM) using specialized SBOM tools to ensure component visibility, vulnerability tracking, and supply chain transparency across products.
• Apply security perspectives during safety and functional evaluations in partnership with safety, systems, and software teams.
• Support proactive vulnerability patching and secure update strategies using product security tools for threat modeling and risk profiling.
• Execute hazard and threat analyses (TARA/HARA) early in the architecture and development life cycle.
• Examine and strengthen the security architecture of vehicle subsystems and autonomous frameworks; define security requirements at both the system and product levels and ensure adequate validation coverage.
• Collaborate with senior engineers on Ethernet, in-vehicle networking, and cloud interface configurations, including port security and network segmentation.
• Maintain up-to-date knowledge of R155/156, ISO 21434, and UL 4600; assist with internal audits, risk assessments, and compliance documentation.
• Engage with Auto-ISAC to monitor emerging threats, attack vectors, and industry standards.
• Work across disciplines like cybersecurity, hardware, and product engineering to provide architectural security design feedback.
• Help cultivate a security-first culture within the organization through integrated best practices and awareness initiatives.
• Undertake additional responsibilities as assigned by your manager.
• Bachelor’s Degree in Computer Science, Computer Engineering, or a closely related field.
• At least [1-3] years of experience in a product cybersecurity or similar role.
• Proficient in performing threat modeling and attack surface analysis.
• Experience in generating and managing Software Bills of Materials (SBOMs) using industry-standard tools and familiarity with SBOM formats like SPDX and CycloneDX.
• Knowledge of vehicle communication networks and protocols at both physical and application layers (CAN, LIN, Ethernet, DBCs), embedded systems interaction, and module security technologies.
• Understanding of security-relevant services outlined in ISO 14229-1 (UDS).
• Experience with TARA and HARA methodologies and familiarity with UNECE WP.29, ISO/SAE 21434, and security standards.
• Ability to effectively communicate findings and collaborate with engineering teams to facilitate timely mitigation and remediation efforts.
• Comprehensive healthcare package that includes medical, dental, vision, life, and disability insurance. Domestic partners who have lived together for at least one year are also eligible for participation.
• Availability of Health Savings and Flexible Spending Accounts for healthcare and dependent care.
• Attractive retirement benefits, including an employer safe harbor match that is immediately vested.
• Generous paid parental leave and a phased return-to-work program.
• Flexible vacation policy in addition to paid company holidays.
• Total Wellness Program offering a variety of resources for overall wellbeing.
actago GmbH
Zscaler
Thomson Reuters
DSV - Global Transport and Logistics
Get handpicked remote jobs straight to your inbox weekly.