
Cybersecurity Engineer, Product Cybersecurity
Westinghouse Air Brake Technologies Corporation12 days ago
Cedar Rapids, IA, USASenior / Staff+
Base Salary
$91k - $130k/yr
Responsibilities
- Conduct cybersecurity reviews and assessments of Wabtec products throughout the software development lifecycle.
- Perform threat modeling, threat and risk assessments, security analyses, attack-surface analysis, vulnerability assessments, and security testing.
- Advise engineering teams, product managers, leadership, and other stakeholders on cybersecurity principles, technical controls, risk management, and secure design.
- Support cybersecurity consulting across connected products, web services, industrial systems, and embedded product portfolios.
- Recommend secure design principles, software security controls, hardening strategies, and risk mitigation measures.
- Investigate cybersecurity defects, perform root cause analyses, and support corrective and preventive actions.
- Develop and deliver cybersecurity training and awareness programs.
- Create and improve cybersecurity standards, procedures, technical controls, and best practices.
- Integrate cybersecurity requirements into product architectures, designs, and development processes.
- Support vulnerability disclosure, remediation planning, and product security incident response activities.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
- 8–10 years of experience in the design, development, and testing of web-based, embedded, and/or connected systems.
- At least 4 years of hands-on experience in product or application cybersecurity engineering, architecture, risk assessment, or risk management.
- Hands-on experience with threat modeling, attack-surface analysis, vulnerability assessments, security testing, and security risk assessment methodologies and tools.
- Experience applying cybersecurity frameworks, regulations, and standards such as IEC 62443, NIST 800-53, NIST Cybersecurity Framework, or ISO/IEC 27001.
- Experience with secure product development processes and DevSecOps practices.
- Experience with security architecture and cryptographic technologies, including PKI, secure boot, key management, certificate lifecycle management, and secure communications.
- Current knowledge of cybersecurity threats, technologies, and industry trends.
- Ability to influence technical decisions, manage multiple priorities, and collaborate with global engineering, product, customer, supplier, and leadership stakeholders.
- Strong analytical, organizational, problem-solving, communication, presentation, and stakeholder management skills.
- Industrial-sector experience in rail, transportation, mining, automotive, manufacturing, or critical infrastructure is preferred.
Benefits
- Health, welfare, and retirement benefits are available.
- Annual bonus may be offered if eligible.
- The role is part of a global, international, matrixed organization; no specific work arrangement is stated.