Motivepower, Inc

Cybersecurity Engineer, Product Cybersecurity

Motivepower, Inc$91K — $129K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, or related field.
  • 8-10 years of experience in design, development, and testing of web-based, embedded, or connected systems.
  • 4+ years of hands-on experience in product/application cybersecurity engineering.
  • Experience with cybersecurity frameworks such as IEC 62443, NIST 800-53, or ISO/IEC 27001.
  • Knowledge of secure product development processes and DevSecOps practices.

Responsibilities

  • Conduct ongoing cybersecurity assessments of Wabtec products across the Software Development Lifecycle (SDLC).
  • Partner with engineering teams for threat modeling, and security analyses to identify vulnerabilities.
  • Provide expert guidance on cybersecurity principles, effectively communicating with technical and non-technical stakeholders.
  • Support cybersecurity consulting activities across Wabtec's product portfolios.
  • Recommend secure design principles and risk mitigation measures for product improvements.
  • Investigate cybersecurity defects, perform root cause analyses, and recommend corrective actions.
  • Develop and deliver cybersecurity training and awareness programs for stakeholders.

Benefits

  • Health, welfare, and retirement benefits available at mywabtecbenefits.com.
  • Potential for an annual bonus if eligible.
Full Job Description
Summary: The Cybersecurity Engineer is responsible for ongoing cybersecurity assessments of Wabtec products to determine whether they comply with applicable Wabtec cybersecurity standards and technical controls. They will advise product managers and engineering teams, create awareness of cybersecurity standards and technical controls, and recommend best practices for satisfying these standards and controls for all Wabtec products offered or made available for customer. They will work closely with others to define and maintain technical controls to address external standards, Wabtec standards, and product requirements. Duties and Responsibilities: This position requires strong technical expertise in cybersecurity controls for mainly web and embedded systems. Key responsibilities include: Conduct cybersecurity reviews and assessments of Wabtec products throughout the Software Development Lifecycle (SDLC), evaluating compliance with Wabtec policies, standards, and technical controls. Partner with engineering teams to perform threat modeling, threat and risk assessments, and security analyses to identify vulnerabilities, attack vectors, and product threat surface Provide expert guidance on cybersecurity principles, technologies, and risk management, clearly communicating technical concepts to engineering teams, leadership, and non-technical stakeholders. Support cybersecurity consulting activities across Wabtec's connected products, web service, industrial systems and embedded product portfolios. Recommend secure design principles, software security controls, hardening strategies, and risk mitigation measures that reduce attack-surface while ensuring maintainability and operational efficiency. Support engineering teams in investigating cybersecurity defects, performing root cause analyses, and implementing corrective and preventive actions. Develop and deliver cybersecurity training and awareness programs for engineers, technical leaders, product managers, and business stakeholders. Contribute to the development, documentation, and continuous improvement of cybersecurity standards, procedures, technical controls, and best practices. Promote and share cybersecurity best practices across the organization to improve product security maturity and consistency. Collaborate with product development teams to integrate cybersecurity requirements into product architectures, designs, and development processes. Support vulnerability disclosure, remediation planning, and security incident response activities related to product cybersecurity. Perform other duties and special projects as assigned. Minimum Qualifications: Bachelor's degree in Computer Science, Cybersecurity, or a related field. 8 - 10 years of experience in the design, development, and testing of web-based, embedded, and/or connected systems. 4+ years of hands-on experience in product/application cybersecurity engineering, architecture, risk assessment, or risk management. Hands-on experience with security risk assessment methodologies, techniques, and tools, including threat modeling, attack surface analysis, vulnerability assessments, and security testing. Experience applying cybersecurity frameworks, regulations, and standards such as IEC 62443, NIST 800-53, NIST Cybersecurity Framework (CSF), ISO/IEC 27001, or equivalent. Experience in industrial sectors such as rail, transportation, mining, automotive, manufacturing, or critical infrastructure is preferred. Experience with secure product development processes and DevSecOps practices. Experience in security architecture and implementing cryptographic technologies, including PKI, secure boot, key management, certificate lifecycle management, and secure communications. Ability to work independently and effectively manage multiple priorities in a global, matrixed organization. Strong analytical, organizational, and problem-solving skills. Excellent verbal, written, presentation, and stakeholder management skills. Ability to manage multiple tasks while collaborating with diverse stakeholders in an international environment. Proven ability to influence technical decisions and drive cybersecurity improvements across global teams and external partners. Strong collaboration skills with engineering, product management, customers, suppliers, and leadership teams. Demonstrated commitment to continuous improvement, operational excellence, and cybersecurity maturity. Current knowledge of evolving cybersecurity threats, technologies, and industry trends This role is focused on Product Cybersecurity Engineering, including threat modeling, security architecture reviews, embedded/IoT security, secure product design, and cybersecurity compliance. Candidates whose experience is primarily in IT Security, SOC, Information Security, Network Security, Data Security, Governance/Risk/Compliance (GRC), or Penetration Testing may not be a suitable match for this position. Qualifications Additional Information Our job titles may span more than one career level. The salary rate for this role is currently $[redacted]00 The actual salary offered to a candidate may be influenced by a variety of factors, such as: training, transferable skills, work experience, education, business needs, market demands and work location. The base pay range is subject to change and may be modified in the future. More information on offered benefits, which include health, welfare, and retirement, are available at mywabtecbenefits.com. Other benefit offerings for this role may include annual bonus, if eligible.

About Motivepower, Inc

MotivePower, Inc. is an American manufacturer of diesel-electric locomotives. The company is a wholly-owned subsidiary of Wabtec, and traces its history back to the MK Rail division of Morrison-Knudsen.
Learn more about Motivepower, Inc
Industry
Founded
1999

Similar Jobs

More Jobs at Motivepower, Inc

More Information Technology Jobs

Find similar Cybersecurity Engineer, Product Cybersecurity jobs: