3 months ago
Westerville, OH, USAMid Level
Responsibilities
- Investigate reported and internally discovered vulnerabilities across embedded firmware and gateway platforms.
- Analyze embedded firmware packages, update mechanisms, and exposed network, diagnostic, and field-service interfaces.
- Support secure boot, firmware signing, and update validation implementations with firmware engineering teams.
- Conduct threat modeling and risk assessments for embedded platforms and interface exposure.
- Drive vulnerability response workflows, including root-cause analysis, remediation tracking, and verification.
- Support alignment with IEC 62443, ISO 27001, NIS2, and CRA-related cybersecurity obligations.
- Review and maintain SBOMs and supplier security documentation for compliance and supply-chain security.
- Partner with QA and firmware teams on security testing, validation, and release readiness.
- Contribute to security requirements, checklists, and conformance matrices for embedded platforms.
Requirements
- Bachelor’s degree in Computer Engineering, Computer Science, Electrical Engineering, or a related technical field.
- At least 3 years of experience resolving security issues in embedded firmware.
- At least 3 years of experience with Linux-based secure firmware development and testing.
- At least 3 years of experience using C/C++.
- Working knowledge of embedded security concepts including secure boot, firmware signing, cryptography, and secure update mechanisms.
- Familiarity with networked embedded systems and protocols such as TCP/IP, TLS, and diagnostic interfaces.
- Ability to collaborate with engineering, quality, and compliance teams.
- Preferred experience with IEC 62443, ISO/SAE 21434, or similar industrial and operational technology security frameworks.
- Preferred familiarity with SBOM formats and tooling such as CycloneDX and SPDX.
- Preferred experience supporting embedded-product security compliance or regulatory readiness.
- Preferred background in firmware development or reviewing embedded firmware code for security.
- Preferred understanding of secure device lifecycle concepts including manufacturing security, provisioning, and field updates.
