We are on a digital transformation journey. We continue to grow the organization drive and develop this transformation and make sure we are ready for the digital future together with our customers and stakeholders.
The Product Software Security Specialist plays a critical role in ensuring the security of products throughout their lifecycle. This role involves identifying and mitigating security risks collaborating with crossfunctional teams and implementing security best practices to protect products from vulnerabilities and threats.
Key Responsibilities:
- Compliance with Industrial Security Standards: Ensure that industrial software systems comply with security standards and regulations by performing essments against IECIECCRA and RED. In addition support the R&D teams in security compliance against relevant standards and legislation.
- Threat Modeling & Risk essment for Industrial Software: Perform threat modeling and risk essments specific to the software used in industrial environments focusing on potential attack vectors such as remote access thirdparty software and network protocols. Also develop and improve processes and templates for threat modeling and risk essment when needed.
- Customer Security Questionnaires: Answer customer security questionnaires about our industrial products. Translate customer needs into product security requirements.
- Secure Software Development Lifecycle (SDLC) for Industrial Systems: Integrate security best practices into the development lifecycle of industrial software systems. Ensure that security is considered at every stage from design to deployment and in ongoing maintenance.
- Support the integration of security testing tools with test & development environments (e.g. CI/CD pipelines).
Requirements
Experience
- 3 years of experience in software or product security preferably in industrial or OT environments.
- Handson experience essing and securing software used in industrial control systems (ICS) SCADA systems and embedded software.
Key Competencies
- Deep understanding of both software/product security principles and industrial software systems allowing to secure industrial software effectively.
- Proficiency in threat modeling risk essment and implementing security controls for industrial products.
- Familiarity with cybersecurity standards like IEC 62443
- Proficiency in programming languages relevant to industrial systems (e.g. C/C Python Java) and secure coding practices.
- Excellent communication ss to work effectively with crossfunctional teams including product managers marketing and product developers.
- Certifications (Optional but Preferred):
ISA/IEC 62443 Cybersecurity Certification
Certified Secure Software Lifecycle Professional (CSSLP)