ironquill.tech/board

$ cat jobs/cybersecurity-engineer-product-cybersecurity-wabtec-fc654397628a.json

Cybersecurity Engineer - Product Cybersecurity

Wabtec·Worldwide·Bengaluru, IN·mid
Apply on smartrecruiters → Get AI match score →
Summary: The Cybersecurity Engineer is responsible for ongoing cybersecurity assessments of Wabtec products to determine whether they comply with applicable Wabtec cybersecurity standards and technical controls. They will advise product managers and engineering teams, create awareness of cybersecurity standards and technical controls, and recommend best practices for satisfying these standards and controls for all Wabtec products offered or made available for customers. They will work closely with others to define and maintain technical controls to address external standards, Wabtec standards, and product requirements. Duties and Responsibilities: This position requires strong technical expertise in cybersecurity controls for mainly web and embedded systems. Key responsibilities include: Conduct cybersecurity reviews and assessments of Wabtec products throughout the Software Development Lifecycle (SDLC), evaluating compliance with Wabtec policies, standards, and technical controls. Partner with engineering teams to perform threat modeling, threat and risk assessments, and security analyses to identify vulnerabilities, attack vectors, and product threat surface Provide expert guidance on cybersecurity principles, technologies, and risk management, clearly communicating technical concepts to engineering teams, leadership, and non-technical stakeholders. Support cybersecurity consulting activities across Wabtec's connected products, web service, industrial systems and embedded product portfolios. Recommend secure design principles, software security controls, hardening strategies, and risk mitigation measures that reduce attack-surface while ensuring maintainability and operational efficiency. Support engineering teams in investigating cybersecurity defects, performing root cause analyses, and implementing corrective and preventive actions. Develop and deliver cybersecurity training and awareness programs for engineers, technical leaders, product managers, and business