Salary
💰 $152,400 - $190,000 per year
Tech Stack
CloudCyber SecurityLinuxPythonRTOSSDLC
About the role
- Act as the cybersecurity design authority for T&D products, defining end-to-end architectures across hardware, firmware, and cloud-connected systems
- Translate and implement global regulatory standards (IEC 62443, IEC 61850, IEC 62351, NERC CIP) into product requirements and lead security certification efforts
- Guide engineering teams through threat modeling, secure coding, SDLC best practices, and Cyber-Informed Engineering adoption
- Define and support embedded and software-based security features using C/C++, Python, and modern toolchains
- Collaborate on penetration testing, fuzz testing, code reviews, and security simulations
- Lead cross-functional initiatives with PSL, product management, compliance, field operations, and R&D to align cybersecurity objectives
- Monitor cybersecurity trends, ICS/OT threat landscapes, and recommend tools and methods to enhance product security posture
- Partner with PSL, incident response and product security teams to support vulnerability remediation and post-incident analysis
- Create security documentation including architecture specs, procedures, and training materials
- Represent the company in industry forums, standards bodies, and technical panels; contribute to white papers, patents, and publications
Requirements
- Bachelor’s degree in engineering, Computer Science, Cybersecurity, or a related field
- Minimum of 8 years of engineering experience
- Minimum of 5 years focused on cybersecurity for embedded or software-defined systems
- Professional certifications such as CISSP, GIAC (GPEN/GXPN), CEH, or ISA/IEC 62443 preferred
- Proven ability to secure OT/ICS environments, preferably within the energy or utilities sector
- Deep familiarity with industrial protocols (e.g., IEC 61850, DNP3, Modbus, IEEE 2030.5)
- Familiarity with cybersecurity standards (IEC 62443, IEC 61850, IEC 62351, NERC CIP)
- Experience in embedded system development (C/C++, RTOS)
- Experience with Linux and Windows platforms
- Proficiency in C/C++ and Python and modern toolchains
- Hands-on background in PKI, identity management, network security appliances, and security monitoring
- Experience with penetration testing, fuzz testing, code reviews, and security simulations
- Proficient in threat modeling, risk/vulnerability assessment, and using forensic/security analysis tools
- Excellent communication and stakeholder engagement skills
- Willingness to travel for customer engagements, conferences, and global collaboration
- Exposure to quality improvement methodologies (e.g., Lean, Six Sigma) is a plus
- Recognized as a thought leader through publications, patents, or industry involvement