The Product Cyber Security Engineer is a hands-on, execution-focused role responsible for strengthening and scaling Product Security capabilities across software-enabled and connected products.
This role partners closely with R&D, Software Engineering, DevOps, Quality, Systems Engineering, and Regulatory teams to ensure cybersecurity risks are proactively identified, documented, mitigated, and tracked throughout the product lifecycle.
The engineer owns and delivers core Product Security artifacts required by Product Security procedures, including threat models, cybersecurity risk assessments, vulnerability management evidence, SBOMs, and patch verification documentation.
The role plays a critical part in sustaining regulatory compliance, enabling secure product releases, and maintaining customer trust by integrating cybersecurity into design controls, risk management, and release readiness processes.
Requirements
Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or related technical field, or equivalent practical experience.
3+ years of experience in software engineering, product security, cybersecurity engineering, or a closely related role.
Hands-on experience with product or application security, including vulnerability assessment, threat modeling, and secure development practices.
Demonstrated ability to execute efficiently in complex, documentation-heavy environments.
Bias toward working smarter, leveraging existing tools, automation, and modern engineering practices to reduce manual effort and cycle time.
Comfortable identifying opportunities to streamline, standardize, and scale repeatable security activities without sacrificing quality or compliance.
Working knowledge of software vulnerability management, including CVSS scoring, remediation workflows, and risk acceptance.