Bachelor’s or master’s degree in Cybersecurity, Computer Science, Electronics Engineering, Electrical Engineering, or a related field.
Minimum 10 years of relevant experience in product cybersecurity, embedded security, IoT security, or application security, including demonstrated technical leadership across complex product security programs.
Proven experience across multiple phases of the Secure Product Development Lifecycle including threat modeling, security testing, and implementation validation.
Strong experience in IoT / embedded / connected product cybersecurity.
Hands-on experience in penetration testing and security assessment using tools such as Burp Suite, Kali Linux, Nessus, Coverity, Black Duck, and Defensics.
Solid understanding of common attack vectors and effective mitigations across web, IoT, operating system, and cloud environments.
Strong knowledge of communication and protocol security, including HTTPS, MQTT, SSH, Wi-Fi, Bluetooth, Zigbee, and ICS protocols.
Strong knowledge and practical experience in embedded product security, including hardware roots of trust, secure boot and chain of trust, firmware signing and anti-rollback, secure update mechanisms, device identity, key provisioning and storage, debug interface protection, operating system hardening, and privilege separation.
Proven ability to conduct threat modeling and risk assessments and translate findings into actionable security requirements.
Programming or scripting experience in one or more languages.
Familiarity with AI-assisted cybersecurity workflows and security considerations for AI-enabled products is a plus.
Strong collaboration skills and ability to work effectively with global, cross-functional teams.
Strong communication and presentation skills across engineering and business stakeholders.
Fluent in English, able to collaborate and communicate effectively with global teams.