
Embedded Cybersecurity Engineer(Platform Security)
Caterpillar2 days ago
Wuxi, China or Shanghai, ChinaSenior
Responsibilities
- Design, develop, integrate, and validate cybersecurity architectures and product-level security solutions for DCU platforms using Orin and Thor.
- Develop secure boot, boot-chain, image-signature verification, measured boot, and trusted-computing mechanisms.
- Build PKI, certificate authority, device identity, certificate lifecycle, and key-management systems.
- Implement mutual authentication, trusted device access, ASP, access control, identity authentication, and authorization mechanisms.
- Develop, integrate, and optimize MACsec, TLS, DTLS, and IPsec security communications.
- Harden embedded Linux systems through permissions management, SELinux/AppArmor, security baselines, and attack-surface reduction.
- Design and implement OTA security, including image signing, integrity verification, key protection, and anti-rollback mechanisms.
- Configure, develop, integrate, and optimize ROS2 DDS Security for in-vehicle network data protection.
- Develop security logging, audit trails, intrusion detection, and security-event monitoring capabilities.
- Maintain SBOMs, perform license compliance and CVE analysis, and integrate security patches.
- Support ISO 21434, IEC 62443, and ISO 27001 compliance activities, including security requirements, design, validation, and audits.
Requirements
- Bachelor's degree or higher in computer science, software engineering, cybersecurity, information security, electronic engineering, or a related field.
- At least 8 years of embedded Linux platform development experience and at least 3 years of cybersecurity project development experience.
- Knowledge of Linux architecture, including process management, thread synchronization, memory management, network protocol stacks, and system-service development.
- Experience with embedded Linux security mechanisms, secure boot processes, and system security architecture.
- Knowledge of OpenSSL, PKI, certificate authorities, X.509 certificates, and modern cryptography.
- Experience managing device certificate lifecycles, including issuance, deployment, renewal, rotation, and revocation.
- Knowledge of secure boot, chain of trust, measured boot, and trusted-platform technologies.
- Knowledge of key management, secure storage, TPM, HSM, and TEE technologies.
- Knowledge of TLS, DTLS, IPsec, MACsec, and network-security protocol implementation.
- Experience with Linux permissions management, access-control models, SELinux/AppArmor, and system hardening.
- Knowledge of software supply-chain security, SBOM, and open-source software security governance.
- Knowledge of ROS2 DDS Security and industrial Ethernet security is preferred.
- Understanding of ISO 21434, IEC 62443, NIST Cybersecurity Framework, and related security best practices is preferred.
- Experience developing secure-boot platform security features, building CA/PKI platforms, managing device certificates, or developing, integrating, or debugging MACsec is preferred.
Benefits
- Equal opportunity employer.
- Posting window is September 28, 2026 through October 15, 2026.
About Caterpillar
Caterpillar Inc. designs, manufactures, and services construction and mining equipment, diesel and natural gas engines, industrial gas turbines, and diesel-electric locomotives for infrastructure, resource, and energy customers. The public company, founded in 1925 and headquartered in Irving, Texas, sells primarily through an independent worldwide dealer network and provides equipment financing. It operates through Construction Industries, Resource Industries, and Energy & Transportation segments, with shares traded on the NYSE and Euronext Paris.