
Cybersecurity Engineer - Product Cybersecurity
Westinghouse Air Brake Technologies Corporation13 days ago
Bengaluru, IndiaSenior / Staff+
Responsibilities
- Conduct cybersecurity reviews and assessments of Wabtec products across the software development lifecycle.
- Perform threat modeling, threat and risk assessments, attack-surface analysis, vulnerability assessments, and security analyses.
- Advise engineering and product teams on cybersecurity principles, secure design, software security controls, hardening, and risk mitigation.
- Support cybersecurity consulting for connected products, web services, industrial systems, and embedded product portfolios.
- Investigate cybersecurity defects, perform root-cause analyses, and support corrective and preventive actions.
- Develop and deliver cybersecurity training and awareness programs for technical and business stakeholders.
- Develop, document, and continuously improve cybersecurity standards, procedures, technical controls, and best practices.
- Integrate cybersecurity requirements into product architectures, designs, and development processes.
- Support vulnerability disclosure, remediation planning, and product security incident response activities.
- Influence cybersecurity improvements and technical decisions across global teams and external partners.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
- 8–10 years of experience designing, developing, and testing web-based, embedded, and/or connected systems.
- At least 4 years of hands-on experience in product or application cybersecurity engineering, architecture, risk assessment, or risk management.
- Hands-on experience with threat modeling, attack-surface analysis, vulnerability assessments, security testing, and related risk assessment methodologies and tools.
- Experience applying IEC 62443, NIST 800-53, the NIST Cybersecurity Framework, ISO/IEC 27001, or equivalent frameworks, regulations, and standards.
- Experience with secure product development processes and DevSecOps practices.
- Experience with security architecture and cryptographic technologies including PKI, secure boot, key management, certificate lifecycle management, and secure communications.
- Industrial-sector experience in rail, transportation, mining, automotive, manufacturing, or critical infrastructure is preferred.
- Strong analytical, organizational, problem-solving, communication, presentation, stakeholder management, and collaboration skills.
- Ability to work independently, manage multiple priorities, and collaborate in a global, matrixed organization.
- Ability to influence technical decisions and drive cybersecurity improvements across global teams and external partners.
- Current knowledge of evolving cybersecurity threats, technologies, and industry trends.