Robert Boschposted 15 days ago
Full-time • Mid Level
Watertown, MA
Machinery Manufacturing

About the position

As a product security engineer you will play a key role in the evaluation, support, management, and implementation of cybersecurity measures pertaining to HVAC control and communicating systems for Bosch Home Comfort North America. The selected individual will possess some experience in the design and validation of security services executing on different hardware platforms. He or she will assume the role of Security Manager for current and future projects, and be responsible for security feature implementation according to the product life cycle for various HVAC connected systems.

Responsibilities

  • Security reviews for new features, products, technologies, and services.
  • Secure design, architecture, implementation, and penetration testing of HVAC connectivity systems (i.e. IoT devices, AWS cloud, Mobile App).
  • Secure development life-cycle (SDLC) practices including threat modeling and security testing.
  • Influence decision-makers and stakeholders throughout the organization across project teams to achieve a consistently high security bar.
  • Assist in security review engagements and lead remediation efforts.
  • Create security guidance and documentation (e.g. Security Concept) for development.
  • Develop and deliver security training and outreach to internal development teams.
  • Develop and improve metrics that drive desired behavior and security outcomes.
  • Identify pressing security problems that are amenable to automatic detection. Work to implement new detection techniques and tools.
  • Ensure that detected security issues are treated with a level of urgency that reflects their true risk.
  • Investigate security issues and identify opportunities for detecting or preventing similar issues with automation.
  • Provide guidance to the Regional Business Unit Engineering and third-party development teams on secure coding and development practices.

Requirements

  • Bachelor of Science in Computer Engineering, Computer Science or a related technical discipline.
  • 5+ years of experience with any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration and network security.
  • 5+ years knowledge and understanding of security engineering, system and network security, authentication and security protocols, cryptography, or application security.

Nice-to-haves

  • Desired experience working in the HVAC/Refrigeration industry, with a familiarity of existing HVAC residential and commercial equipment, systems and suppliers.
  • An advanced degree is preferred.
  • Demonstrated experience collaborating with other security engineers and developers to deliver complex projects.
  • Knowledge and experience with cryptography and computer security.
  • Knowledge of full life-cycle software engineering practices including coding standards, testing, source control management, and operations.
  • Strong demonstrated knowledge of web protocols, common attacks, and an in-depth knowledge of operating systems (OS) tools and architecture.
  • Experience with virtualization technologies, especially with AWS services.
  • Relevant industry certifications (e.g. AWS Certified Security) a plus.
  • Familiarity with Bosch Security Engineering Process (SEP), or similar process, a huge plus.

Benefits

  • Health, dental, and vision plans
  • Health savings accounts (HSA)
  • Flexible spending accounts
  • 401(K) retirement plans with an employer match
  • Wellness programs
  • Life insurance
  • Short- and long-term disability insurance
  • Paid time off
  • Parental leave
  • Adoption assistance
  • Reimbursement of education expenses
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service