Job DescriptionUL is seeking a Cybersecurity Expert who will be involved with the cybersecurity work product development for various complex software-intensive systems such as systems for self-driving vehicles, industrial automation, battery and energy storage in both mobile and stationary applications etc. The Expert will lead the development, and review of work products for clients seeking compliance to standards in cybersecurity and related fields, including ISO 21434, ISO 24089, and other similar standards relevant to product, system, hardware, and software engineering safety lifecycle. The ideal candidate will bring hands-on software development expertise to strengthen secure design, implementation, and verification of software-intensive systems.
ResponsibilitiesHere is what the Cybersecurity Expert is required to perform:- Lead the development of ISO/SAE 21434:2021 processes and templates.
- Lead the development of ISO/SAE 21434:2021 work products such as TARA, Cybersecurity goal and claims, Cybersecurity concept, Cybersecurity specification, Cybersecurity verification specification, Cybersecurity assessment report, Cybersecurity validation report, Cybersecurity case.
- Lead the development of ISO 24089:2023 processes and templates.
- Lead the development of ISO 24089:2023 work-products such as Software Update Infrastructure Management Report, Software Update Cybersecurity Risk Analysis Report, Software Update Safety and Cybersecurity Risk Analysis Report, Software Update Vehicle Function Management Report.
- Lead the creation of processes for UN Regulations No. 155 and 156.
- Apply secure software development practices and coding expertise to guide clients in designing, implementing, and verifying software-intensive cybersecurity work products.
Additional responsibilities may include:- Lead business development activities defining Statements of Work (SOWs), providing budgetary estimates, and submitting full proposals for client-funded projects. Leverage industry experience and network to win projects and build the business.
- Lead client programs, including major/large-scale client programs, by interacting regularly with clients in technical program meetings and project reviews. Address client concerns and to resolve client issues. Provide expert technical leadership and guidance to clients in reference to functional safety and related technical fields. Projects may include regular travel to client sites and to other UL locations.
- Contribute to the strategic direction of the business by providing technical and market expertise to management planning and report-out activities.
- Contribute to the development of UL technical standards and other relevant technical standards (from ISO, IEC, IEEE, SAE, etc.) by direct participation as member of standards committees.
- Integrate continuous improvement and safety culture in all aspects of the job.
QualificationsQualifications for the role:- Required: Bachelor degree in Electrical, Electronics, Computer Science, Mechanical, Automotive, Robotics, Software or Mechatronics Engineering. Masters Preferred.
- Required: 5+ years' Experience with ISO 21434, Cybersecurity Management Systems (CSMS), Automotive Cybersecurity Risk Management, Continuous Cybersecurity Activities (Incident Response, Cybersecurity Monitoring)
- Required: Software development experience, including hands-on coding, secure software design, and familiarity with software development lifecycle practices for embedded or safety-relevant systems.
- Preferred: Additional 5+ years' experience with security controls at the vehicle level, secure onboard communication, secure boot, network segmentation, secure coding practices, and secure architecture practices.
- Preferred: Knowledge of functional safety standards such as ISO 26262 and SOTIF (ISO 21448), and their intersection with cybersecurity engineering.
- Preferred: Knowledge of Cybersecurity Resilience Act (CRA)
- Experience with secure automotive topics such as:
- Secure vehicle architecture and frameworks
- Secure development processes (ASPICE for Cybersecurity, NIST Cybersecurity Framework, ISO 27001, OWASP)
- Security testing for automotive: Penetration testing, vulnerability scanning, fuzz testing, dynamic/static application security testing, design review
- Software supply chain security: Distributed development, vendor security assessments, secure software supply chain risk management
- Experience with ISO 24089, Software Update Management Systems (SUMS), including experience with vehicle software update campaigns and securing vehicle infrastructure related to software updates.
Total Rewards: We understand compensation is an important factor as you consider the next step in your career. The estimated salary range for this position is $110,000 to $150,000 USD and is based on multiple factors, including job-related knowledge/skills, experience, geographical location, as well as other factors. This position is eligible for annual bonus compensation with a target payout of 10% of the base salary. This position also provides health benefits such as medical, dental and vision; wellness benefits such as mental and financial health; and retirement savings (401K) commensurate with the standard rewards offered in each individual location or country. We also provide full-time employees with paid time off including vacation (15 days), holiday and personal days (totaling 12 days) and sick time off (72 hours).
#LI-SG2
#LI-Remote
Applications must be received by 2/23/27