Job Description
Engineer III - Cybersecurity R&D
This role has been designed as 'Hybrid' with a requirement that you will work on average 2 days per week from an HPE office.
Job Description:
This is an opportunity to join a dynamic team that will operate at the frontier of cybersecurity, as part of the Junos Cybersecurity R&D organization in the HPE Networking business unit.
The mission of Cybersecurity R&D is to collaborate across functions to build and sustain secure routers, switches, and firewalls running Junos OS and Junos OS Evolved. The organization spans cybersecurity domains with major responsibilities in the development of system security features, applied cryptography, supporting security certifications, and Secure Development Lifecycle (SDL) practices, including harnessing frontier AI models for vulnerability discovery and remediation.
Responsibilities:
• Support security certifications including NIST FIPS 140, Common Criteria, and the European Union Cybersecurity Resilience Act (EUCRA)
• Develops and enhances product security capabilities including certification gap analysis, risk-based threat modelling, static analysis of code, dynamic analysis of running network devices, penetration testing, hardware security assessments, and AI-enhanced vulnerability management
• Adopts new cybersecurity technologies and innovations that benefit product security posture and processes; participate in development of the cybersecurity roadmap, and then executes the roadmap
• Leverages domain experience to provide consulting to key stakeholders including engineering managers, platform teams, and product line managers
• Pursues excellence in cybersecurity design and development
Education and Experience Required:
• Bachelor's or Master's degree in Computer Science, Cybersecurity, or adjacent technical field of study
• Typically 4-6 years experience
Knowledge and Skills:
• Deep knowledge of the art and science of cybersecurity
• Ability to improvise, adapt, and overcome in the face of quickly evolving cybersecurity challenges and strategies
• Strong knowledge of networking, networking security protocols (TLS, SSH, IPsec), and cryptography as built into networking products
• Significant experience working in one or more programming languages: C preferred, Python; bonus points for Rust
• Working experience driving product security certifications -- FIPS 140 and Common Criteria - from gap analysis, to product preparation, to pre-testing, to submission to third-party labs, to certificate award; ability to quickly ramp on on EU CRA
• Working experience in harnessing AI systems for defensive security purposes including vulnerability discovery and management; understands the importance of AI governances and keeping the human-in-the-loop
• Strong technical communication skills both verbal and written; ability to explain, persuade, and evangelize
Relocation will be provided for eligible candidates