Position Summary:The Rockwell Automation
Safety, Sensing & Industrial Components Business is looking for a
Supervisor, Product Security Test. You will lead a team responsible for the security verification and validation of industrial control system (ICS) products, embedded devices, industrial software, and communication technologies. You will combine people leadership with technical oversight of security testing activities that include penetration testing, vulnerability assessment, fuzz testing, security automation, and product security research.
As a leader within our engineering organization, you will develop a team of security test engineers. You will partner with product development, architecture, and cybersecurity teams to improve the security posture of Rockwell Automation products throughout the product lifecycle.
You will report to the Senior Manager of Development Test Engineering.
Your Responsibilities:- Lead and develop a team of Product Security Test Engineers.
- Guide planning, prioritization, and execution of security testing activities across multiple product development programs.
- Oversee penetration testing, vulnerability assessments, fuzz testing, security feature validation, and security research activities.
- Ensure security test plans, test cases, and results are traceable to product security requirements and applicable standards.
- Partner with product development, architecture, quality, and cybersecurity teams to integrate security throughout the product lifecycle.
- Lead recruitment, onboarding, performance management, and professional development of team members.
- Guide the development of security test tools, automation frameworks, test environments, and testing methodologies.
- Review and communicate security findings, risks, and recommendations to engineering and business leaders.
- Foster a culture of technical excellence, collaboration, continuous improvement, and innovation.
- Stay informed on emerging cybersecurity threats, vulnerabilities, tools, and industry best practices.
The Essentials - You Will Have:- Bachelor's Degree or equivalent years of relevant work experience.
- Legal authorization to work in the US is required. We will not sponsor individuals for employment visas, now or in the future, for this job opening.
- Ability to travel, including internationally, up to 10% of time.
The Preferred - You Might Also Have:- Typically requires 2+ years of relevant experience in people leadership, supervisory, or engineering management.
- Relevant experience in product security, security testing, embedded-system testing, embedded firmware/software engineering, test engineering, or a related technical field.
- Degree in Computer Science, Computer Engineering, Cybersecurity, Electrical Engineering, or a related technical field.
- Practical experience with penetration testing, vulnerability assessment, security verification and validation, or related product-security activities.
- Experience planning and coordinating complex engineering work, including developing estimates, schedules, resource plans, and project commitments.
- Demonstrated ability to develop engineers with varying levels of experience and technical specialization.
- Working knowledge of security-testing methods applicable to embedded products, software applications, communication protocols, networks, or industrial automation systems.
- Understanding of networking fundamentals, including OSI and TCP/IP concepts.
- Experience with scripting or software development languages such as Python.
- Strong leadership, communication, project planning, and problem-solving skills.
- Ability to collaborate across global teams.
- Experience leading cybersecurity, penetration testing, or product security teams.
- Experience performing or leading security assessments of industrial control system products, embedded devices, firmware, industrial software, or communication protocols.
- Familiarity with hardware-debugging and embedded-system interfaces such as UART, SPI, I2C, JTAG, or SWD.
- Knowledge of cryptographic principles and experience validating cryptographic implementations.
- Experience with industrial automation products, embedded systems, or industrial communication protocols such as EtherNet/IP, CIP, IO-Link, Modbus, or PROFINET.
- Familiarity with security tools such as Burp Suite, Nmap, Wireshark, and fuzzing frameworks.
- Experience with CI/CD, test automation, DevOps, or security automation practices.
- Industry certifications such as OSCP, GPEN, CEH, or similar.
- Experience with vulnerability research, reverse engineering, or published security findings.
What We Offer:- Health Insurance including Medical, Dental and Vision
- 401k
- Paid Time off
- Parental and Caregiver Leave
- Flexible Work Schedule where you will work with your manager to enjoy a work schedule that can be flexible with your personal life.
- To learn more about our benefits package, please visit at www.raquickfind.com.
Rockwell Automation's hybrid policy aligns that employees are expected to work at a Rockwell location at least Mondays, Tuesdays, and Thursdays unless they have a business obligation out of the office.