Senior Product Security Engineer IRC263202

Description

In Grid Integration Services we are at the forefront of the digital revolution: through digital services, we enable our customers to increase the reliability of their assets and systems while optimizing costs. For our growing R&D team, we are looking for a hands-on product security engineer who ensures that our SW solutions fulfill the highest standards of cybersecurity, integrate with the software ecosystem of our company, and can be taken over by the software operations team. Are you a result-oriented team player who fosters a positive work culture? Are you ready to drive digitalization and innovation for rapidly changing power grids? Are you willing to continuously drive improvement and occasionally get your hands dirty? Then do not hesitate and submit your application today!

Requirements

  • Bachelor’s degree in computer science, information technology, or similar
  • At least 2 years of experience in software development
  • Experience in agile software development processes and security development lifecycle processes
  • Knowledge of system administration, networks, infrastructure (switches, routers, firewalls), configuration, troubleshooting, and root cause analysis
  • Strong understanding of cybersecurity standards, guidelines, and best practices for building highly resilient hardened software systems (e.g., NIST, CIS, and OWASP)
  • Experience in system security, product / application security architecture, network security, and web services
  • Experience in implementation, configuration, operation, maintenance, and troubleshooting of security controls such as L3 and L7 firewalls
  • Experience with static code analysis, dynamic code analysis, open-source software scanning, software composition analysis
  • Experience with industrial data transfer protocols such as OPC, IEC 61850, OCPP, MQTT, and similar is an advantage
  • Preferably experience in
     Linux, Windows, and mobile environments
     Docker and Kubernetes
     C#, .Net Framework, .Net (Core)
     Microservices and containerized applications
     Azure cloud environment
  • Need to be ready for a business trip
  • Fluency in written and spoken as well as technical writing English
  • Ability to work independently with a sense of ownership and responsibility
  • Communication and interpersonal skills and intercultural sensitivity
     

Job responsibilities

  • Act as an individual contributor in RD team and lead the product security efforts
  • Own, enforce, and continuously improve the security development lifecycle process according to IEC 62443-4-1 standard
  • Prepare security requirements documents as part of product requirements engineering and customer solution development phases
  • Prepare security architecture and design documents in response to requirements specifications, develop associated user stories, and drive them through the product development lifecycle
  • Conduct and document threat modeling and attack surface analysis for product releases
  • Conduct code reviews to ensure compliance to the security development lifecycle as well as security architecture and design
  • Ensure products are meeting Hitachi Energy’s minimum cybersecurity requirements or if customer-specific or respective standards such as IEC 62443-3-3 or IEC 62443-4-2
  • Develop, implement, and configure security controls and solutions (e.g., L3 and L7 firewalls) concluded with respective quality assurance and user acceptance testing activities
  • Conduct security risk assessments and drive the product releases through Hitachi Energy cyber security clearance process and respective tests in close collaboration with Hitachi Energy product security officers and security assurance teams
  • Analyze the developed code, prepare bug reports, conduct root cause analysis, suggest fixes, implement and / or ensure implementation of the identified solution, subsequent verification and validation steps
  • Deploy and operate security solutions for internal / external customer projects in on-premise and/or off-
    premise models
  • Act as L3/L4 support team member for security incident (e.g. vulnerabilities) management process
    Engage with internal / external software development vendors
40 views
·
2 applications
100% read
·
100% responded
Last responded more than a month ago
22 views
·
0 applications
To apply for this and other jobs on Djinni login or signup.
Loading...