Compliance and Risk Management Specialist

V2Soft

$95K — $115K *
Manufacturing & Automotive
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in a related field
  • 5-7 years of experience in cybersecurity engineering or related roles
  • Strong understanding of cryptographic key management and PKI
  • Experience conducting audits and ensuring compliance with cybersecurity standards
  • Familiarity with automotive cybersecurity standards is a plus
  • Hands-on experience with PKI/KMS platforms

Responsibilities

  • Define and document cryptographic key requirements for vehicle ECUs
  • Coordinate across program teams to ensure comprehensive cybersecurity integration
  • Conduct technical audits of Tier-1 suppliers for adherence to security standards
  • Establish metrics to monitor supplier compliance and escalate issues as needed
  • Drive the technical implementation of cryptographic requirements in backend systems
  • Create and maintain technical documentation for key provisioning processes
  • Enforce compliance through audits and maintain version control of specifications

Benefits

  • Hybrid work environment with 4 days onsite
  • Cross-functional collaboration with various engineering teams
  • Opportunity to influence automotive cybersecurity strategies
  • Extension of professional development in cybersecurity best practices
  • Engagement with leading-edge cryptographic technologies
Full Job Description
Position Description:
We are seeking a Cybersecurity Key Provisioning Process Engineer to join our Vehicle Cybersecurity organization. This role sits at the intersection of automotive engineering, cryptographic security architecture, and manufacturing operations - owning the end-to-end process by which cryptographic key material is defined, provisioned, and secured across every Electronic Control Unit (ECU) and vehicle program. The ideal candidate is a systems thinker who can translate cryptographic and security requirements into concrete engineering specifications, drive supplier accountability through audit and integration, and operate our backend Public Key Infrastructure (PKI) and Key Management System (KMS) to deliver secure keys at scale. This is a highly cross-functional role requiring fluency in cybersecurity engineering, supplier quality/manufacturing processes, and product key management systems. This role involves the development and governance of security policies and procedures, review of security controls and their efficiency, and monitoring processes for compliance risk and vulnerabilities. They also specialize in managing third party security risk programs
Skills Required:
Embedded Systems, Auditing, Cyber Security, Compliance Professional
Skills Preferred:
ISO 27001, Supply Chain Operations
Experience Required:
Own and facilitate the process for defining, documenting, and approving cryptographic key requirements (algorithms, key lengths, key hierarchies, usage policies, rotation/expiry rules) for each ECU type and vehicle program. Serve as the central point of coordination between vehicle program teams, ECU feature owners, and cybersecurity architecture to ensure requirements are complete, consistent, and traceable across program timelines. Conduct technical audits of Tier-1 supplier manufacturing sites and processes to validate conformance to our cybersecurity requirements. Assess supplier readiness against Client cryptographic and secure manufacturing requirements; identify gaps and drive corrective action plans. Establish and monitor supplier compliance metrics, escalating non-conformances through appropriate governance channels. Partner with cybersecurity architects, ECU/software engineering teams, vehicle program management, procurement, and manufacturing to define cryptographic key requirements tailored to each ECU's function, threat model, and program constraints. Orchestrate the technical implementation of approved key requirements within Client backend PKI and KMS infrastructure, coordinating with platform/IT teams responsible for these systems. Define and manage key lifecycle workflows within the KMS in alignment with program and supplier timelines. Troubleshoot and resolve issues in the key delivery pipeline between backend systems and supplier manufacturing lines. Author clear, precise technical documentation, specifications, and work instructions covering cryptographic key requirements, provisioning processes, and PKI/KMS interfaces. Cascade approved requirements to relevant internal teams and external suppliers, ensuring proper acknowledgment and implementation. Enforce compliance with documented requirements through audits, design reviews, and program gate reviews; maintain version control and change management for all specifications.
Experience Preferred:
• Familiarity with automotive cybersecurity standards (ISO/SAE 21434, UNECE R155/R156). • Hands-on experience with commercial or in-house PKI/KMS platforms (e.g., Thales, Entrust, HashiCorp Vault, AWS KMS, or automotive-specific secure provisioning platforms). • Experience with ECU/embedded systems development lifecycle and vehicle program timing • Knowledge of secure manufacturing/provisioning protocols (e.g., SHE, HSM-based key injection, secure flashing). • Project or process management experience (e.g., Agile, Six Sigma, or similar). • Experience with relevant control frameworks (e.g., NIST 800-53/800-57, ISO 27001, PCI-HSM, or automotive-specific key management security standards) is a plus.
Education Required:
Bachelor's Degree
Additional Information:
Hybrid Position 4days a week onsite

Similar Jobs

More Jobs at V2Soft

More Manufacturing & Automotive Jobs

Find similar Compliance and Risk Management Specialist jobs: