Source description
About the role
Vulnerability Management Product Cyber Specialist
Pune, Maharashtra, India
Trending
Job Description
Job Summary
Forensic Analysis & Offensive Security for Product Cybersecurity This role supports shift left forensic and offensive security evaluations for embedded and connected products across on highway and off highway platforms. The role is focused on hands on technical execution, including early vulnerability discovery, exploit feasibility analysis, architecture reviews, reverse engineering, and pre certification penetration testing, to provide actionable technical findings ahead of external certification testing. This role does not own security capability strategy, tooling ownership, or organizational maturity and does not replace external penetration testing or certification mandated evaluations.
KEY Responsibilities
- Vulnerability Scanning & Analysis
- Perform firmware, binary, and configuration vulnerability scanning, side channel attacks on embedded products.
- Identify known weaknesses such as insecure configurations, outdated components, and cryptographic issues.
- Assess vulnerabilities based on practical exploitability and product context, in addition to standard severity scoring.
- Document findings clearly with technical evidence and reproducible observations. B. Product & ECU Penetration Testing
- Execute pre certification penetration testing activities early in the product lifecycle.
- Perform attacker perspective testing to identify realistic product weaknesses prior to engagement with external labs.
- Conduct hands on testing using defined test setups for: o ECU level penetration testing o System level penetration testing o CAN / UDS / J1939 / Ethernet / MODBUS and related protocol fuzzing
- Provide test results, observations, and technical inputs that complement external penetration testing efforts.
- Architecture & Threat Assessments
- Perform shift left architecture reviews focused on identifying implementation weaknesses related to, Trust boundaries o Cryptographic usage and key handling o Secure boot and firmware integrity o OTA mechanisms o Secure communication paths
- Correlate architectural weaknesses with observed attack paths and test results from internal assessments.
- Provide specific, actionable technical recommendations to improve product robustness prior to external testing.
- Reverse Engineering & Firmware Analysis
- Extract firmware using available interfaces such as JTAG/SWD, memory access techniques, and OTA packages.
- Perform static and dynamic binary analysis using reverse engineering tools.
- Support protocol analysis, secure boot evaluation, and proof of concept exploit development where required to validate findings.
- Capture technical artefacts, evidence, and analysis results in a structured and traceable manner.
- Forensic Analysis & Post Incident Support
- Support collection and analysis of logs, traces, firmware artefacts, and memory dumps following security events.
- Assist in reconstructing attack sequences using forensic evidence and technical analysis.
- Correlate forensic findings with observed product behavior and known attack techniques. • Provide technical inputs to strengthen product design and implementation before subsequent test cycles.
External Qualifications and Competencies
TECHNICAL COMPETENCIES
• Embedded and product cybersecurity fundamentals • Firmware extraction and binary analysis
• Reverse engineering tools (e.g., Ghidra, IDA, Binary Ninja) • Structured problem solving
• CAN / UDS / J1939 / Ethernet security concepts
• Fuzzing frameworks and protocol testing tools
• Debug interfaces (JTAG/SWD), logic analyzers, and bus sniffers
• Strong analytical skills with attention to technical detail
• Clear documentation and cross functional technical communication .
EXPERIENCE •
6–7 years of experience in product or embedded cybersecurity or related technical domains
• Hands on exposure to penetration testing or security assessment of automotive or industrial devices
• Experience working with embedded architectures (e.g., ARM, PowerPC, microcontrollers, IoT)
• Practical experience with reverse engineering and protocol analysis
5. EDUCATION
• Bachelor’s or Master’s degree in Cybersecurity, Electronics, Computer Engineering, or related fields
• Exposure to ISO/SAE 21434, embedded security, or offensive security practices preferred
• Demonstrated hands on technical assessment experience
Additional Responsibilities Unique to this Position
Technical Skills
- Embedded cybersecurity and secure product development.
- Firmware extraction and analysis techniques.
- Static and dynamic binary analysis.
- Reverse engineering tools such as Ghidra, IDA Pro, Binary Ninja, or equivalent.
- ECU and embedded device penetration testing.
- Protocol analysis and security testing.
- CAN, UDS, J1939, Ethernet, MODBUS, and related communication protocols.
- Fuzzing frameworks and protocol testing tools.
- Secure boot, cryptographic implementation, and OTA security assessment.
- Debug interfaces including JTAG, SWD, logic analyzers, and bus sniffers.
- Security vulnerability analysis and exploit validation.
- Technical documentation and reporting.
Professional Skills
- Strong analytical and investigative skills.
- Excellent problem-solving capability.
- Effective stakeholder communication and technical presentation skills.
- Ability to work independently while collaborating across global teams.
- Attention to detail and evidence-based decision making.
- Project coordination and technical leadership capabilities.
About Us
Cummins is an equal opportunity employer. Our policy is to provide equal employment opportunities to all qualified persons without regard to race, sex, color, disability, national origin, age, religion, union affiliation, sexual orientation, veteran status, citizenship, gender identity, or other status protected by law.
Apply Now
Job Info
- Job Identification2431040
- Job CategoryEngineering
- Posting Date07/02/2026, 12:36 PM
- Job ScheduleFull time
- Role CategoryOn-site with Flexibility
- LocationsDahanukar Colony, Pune, Maharashtra, 411038, IN
- Affiliated to Bargaining Unit/Trade UnionNo
- Relocation Eligible?No
- Does the role require work to be done 100% onsite due to its operational nature?No
Similar Jobs
American English
-
Čeština
-
Deutsch
-
American English
-
Español
-
Français
-
Italiano
-
日本語
-
한국어
-
Nederlands
-
Polski
-
Português do Brasil
-
Română
-
Türkçe
-
简体中文
We use cookies on this site to enhance your experience. By clicking any link on this page, you give consent for us to set cookies. For more information, click on Learn more
AcceptDecline
Are You Still With Us?
It seems you've been gone for a while. For security reasons we will end your session automatically in 03:00 unless you would like to continue working.
End SessionContinue Working
Work Summary
This summary is generated by AI Assist. Click inside the summary text box to make changes as necessary.
DiscardAdd Summary
Page Vulnerability Management Product Cyber Specialist - Cummins Talent Acquisition Careers loaded
More at Cummins
Related open roles
Solution Engineer Senior - First Fit Supply Planning IT
Mumbai · Onsite
Instrumentation Engineering Technician - OCU - Technical - 4x10 PM Shift
United States · Onsite
Product Engineering Specialist
India · Onsite
IAM Solution Architect
United States · Onsite
IAM Product Owner – Customer Identity Access Management
United States · Onsite
Principal Technical Engineer – Identity Access Management
United States · Onsite
