Source description
About the role
Emerson is hiring for the role of Product Security Engineer! Responsibilities of the candidate: Support product security regulatory compliance activities, including the European Cyber Resilience Act (EU CRA). Act as a product security representative to support secure development lifecycle implementation efforts. Participate in new product development process audits and security assessments. Perform product security risk assessments and threat modeling activities. Identify, assess, prioritize, and help mitigate vulnerabilities and security threats impacting products and solutions Coordinate security scans and penetration testing activities, analyze results, and ensure remediation of identified vulnerabilities. Collaborate with business units to inventory products and support risk prioritization initiatives. Support vulnerability management programs and Product Security Incident Response Team activities. Assist in product security training and awareness initiatives. Maintain knowledge of applicable industry standards, including IEC 62443, IEC 29147, IEC 30111, ISO/IEC 27001, and NIST SP 800-218. Participate in embedded software development projects based on business requirements. Translate product specifications into software requirements. Design, develop, test, and maintain embedded software modules Build collaborative relationships with product teams, organizational functions, and business partners to support product security objectives. Requirements: Bachelor’s degree in Engineering, Computer Science, Information Security, or a related discipline, or equivalent relevant experience. Experience in product security, secure product development, cybersecurity governance, or related domains. Understanding of Secure Development Lifecycle (SDL), Secure-by-Design, and Defense-in-Depth principles. Knowledge of IEC 62443 and cybersecurity governance practices. Familiarity with European Cyber Resilience Act (CRA) requirements. Experience with cybersecurity standards and frameworks such as IEC 62443, ISO/IEC 27001, NIST SP 800-218, COBIT, or NIST Cybersecurity Framework. Knowledge of Software Bill of Materials (SBOM) concepts and implementation. Hands-on experience with static code analysis tools such as Coverity. Experience designing embedded systems using multitasking real-time operating systems (RTOS) Strong programming skills in C and C++. Familiarity with RTOS environments such as VxWorks, UCOS, ThreadX, FreeRTOS, or MQX. Knowledge of communication protocols such as RS232, SPI, and I2C. Experience with Linux environments, including U-Boot, Linux Kernel, GDB, and CMake. Understanding of embedded security best practices. Strong problem-solving, organizational, communication, and collaboration skills.