drjobs Product Cybersecurity Engineer

Product Cybersecurity Engineer

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Belfast - UK

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

What you will do

  • Liaising with the Hardware/Firmware and Software engineering teams to schedule code reviews/scans as per guidelines outlined by JCI cyber Security Board.

  • Working with Senior Cyber architect to run and discuss results of scans assess where the risks lie how best to mitigate

  • Working with the development team to address cyber risks

  • Being the gatekeeper and working with the development team and our customers ensuring that all products and solutions released to the market adhere to the latest security standards.

How you will do it

You will work across multiple parallel project releases and work items and will have a strong desire to actively champion product cybersecurity best practices. The ideal candidate will take ownership of issues and work on own initiative driving work items to successful completion. You will have good timemanagement and organizational skills and be a continual learner aware of the everchanging nature of cybersecurity and keen to stay on top of the latest developments.

What we look for

  • Ability to work in the Belfast office three days per week

  • Authorisation to work in Ireland

  • Basic familiarity with and keen interest in formal cybersecurity controls and best practices. E.g. OWASP Top 10 NIST 80053.

  • Ability to liaise and negotiate amongst multiple product stakeholders including:

    • Engineering management architects and lead engineers

    • Product Security Incident Response Team (PSIRT)

    • Global Cybersecurity architects

    • Product Management

    • Supplier Assessment Team

    • Site Reliability Engineering (SRE)

    • Legal (Software Copyright / Licensing Compliance Trade Compliance)

    • Individual software and hardware engineers

  • Previous development experience including familiarity with authentication authorization and SDKs and local and remote APIs.

  • Basic networking experience and understanding

  • Understanding of including ability to reason about and explain common cybersecurity vulnerabilities. E.g. can (to some extent) compare and contrast SOME of:

    • Authentication vs. authorization

    • Vulnerability vs. weakness

    • Hashes vs. ciphers

    • SQL injection vs. OS injection

    • RNG vs. PRNG vs. cryptographic RNG

    • High entropy passwords vs. low entropy

    • HSM vs. TEE

    • TLS v3 vs. SSL v3

    • Stack overflow buffer overflow and integer overflow / wraparound.

    • Certificate vs. key

    • Signature vs. hash

Desirable:

  • Basic understanding of software release pipelines: e.g. VCS branching/tagging GitOps software signing versioning CI/CD.

  • Cybersecurity qualifications such as Security CCSP CISSP CEH etc.

  • Familiarity with Common Vulnerability Enumerations (CVEs) Common Weakness Enumerations (CWEs).

  • Familiarity with multiple operating systems including Windows and Linux

  • Degree (or equivalent experience) in a STEM subject particularly cybersecurity computer science software engineering or electronic engineering.

  • Basic understanding of software architecture diagrams attack vectors and threat modelling including an ability to create threat models and reason about attack vectors involving multiple vulnerabilities.

  • Basic understanding of asymmetric vs. symmetric cryptography

  • A skilled communicator able to liaise with multiple levels of engineering and management staff

  • A reasonable degree of previous project / ticket management experience. E.g. SCRUM management sprint reviews etc.

#LIHybrid

#GOSIA

Employment Type

Full-Time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.