SonicJobs Logo
Left arrow iconBack to search

Senior Product Security Engineer

Faith Technologies
Posted 2 months ago, valid for 12 days
Location

Menasha, WI, US

Salary

Competitive

Contract type

Full Time

By applying, a Faith Technologies account will be created for you. Faith Technologies's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Senior Product Security Engineer at Faith Technologies, Inc. leads security design and governance for their Industrial Internet of Things (IIoT) product portfolio.
  • Candidates should have a Bachelor's degree in a relevant field and a minimum of 5 years of dedicated experience in product security or embedded/IIoT security.
  • The role requires expertise in hardware and embedded systems security, OT/IT convergence, and the application of industrial security standards.
  • Salary information is not provided in the job description, but the company emphasizes competitive, merit-based compensation and industry-leading benefits.
  • The position also involves collaboration across teams and may require travel of 5-10% to meet business needs.

You’ve discovered something special. A company that cares. Cares about leading the way in construction, engineering, manufacturing and renewable energy. Cares about redefining how energy is designed, applied and consumed. Cares about thoughtfully growing to meet market demands. And ─ as ā€œone of the Healthiest 100 Workplaces in Americaā€ ─ is focused on the mind/body/soul of team members through our Culture of Care.

The Senior Product Security Engineer leads the securityĀ designĀ and governance of our Industrial Internet of Things (IIoT)Ā and Grid connectedĀ product portfolio. Reporting to theĀ Cybersecurity Manager, this role is the primary technical authority forĀ IIoTĀ product security across the entire device lifecycle - from early design through field deployment and ongoing operation.Ā 

Ā 

This is a deeply technical role focused on hardware and embedded systems security, OT/IT convergence, and the application of industrial security standards. Day-to-day development andĀ DevSecOpsĀ execution (code scanning, firmware management, CI/CD pipeline tooling) is owned by the Product Security Engineer II; the Senior EngineerĀ operatesĀ at the architectural, standards, and cross-functional leadership level.

MINIMUM REQUIREMENTS

Education: Bachelor's degree or equivalent experience in Information Security, Electrical Engineering, Computer Engineering, orĀ a relatedĀ technical field.

Experience: 5+ years of dedicated experience in product security, embedded/IIoTĀ security,

or

Education: Industry-recognized security certifications preferred but notĀ requiredĀ (e.g., GICSP, CISSP, ISA/IEC 62443 Cybersecurity Certificate Program, CSSA).Ā 

Experience: OT/ICS security, with at least 2 years inĀ a seniorĀ or lead capacity and

Travel: 5-10%

Work Schedule: Typical work hours are between 7:00 a.m. and 5:00 p.m. Monday – Friday. However, work may be performed at any time on any day of the week to meet business needs.

Ā Ā 

KEY RESPONSIBILITIES

IIoTĀ Security Architecture and StandardsĀ 

  • Security Architecture: Define and own the security architecture for connectedĀ IIoTĀ products, including device identity frameworks (PKI/certificate management), secure boot chains, cryptographic key management, and hardware root of trust.Ā 
  • Industrial Standards Leadership:Ā EstablishĀ and enforce security design requirements based on applicable standards and frameworks (e.g., IEC 62443, UL 2900, NERC CIP, NIST SP 800-82, NIST CSF) across product lines.Ā 
  • OT/IT Convergence: Design security boundaries and communication controls for environments where operational technology (OT) interfaces with enterprise IT systems, ensuring defense-in-depth across both layers.Ā 
  • Protocol and Interface Security: Evaluate andĀ provideĀ security guidance on industrial communication protocols used in energy and grid applications (e.g., IEC 61850, DNP3, Modbus, CAN bus, GOOSE/Sampled Values).Ā 

Ā 

Threat Modeling and Risk ManagementĀ 

  • Lead Threat Modeling: Conduct and lead structured threat modeling exercises (e.g., STRIDE, PASTA) for newĀ IIoTĀ product initiatives and significant feature changes, translating identified risks into actionable design controls.Ā 
  • Risk Prioritization: Assess and prioritize security risks across fielded and in-development device portfolios based on exploitability, potential impact to grid operations or physical safety, and business criticality.Ā 
  • Vulnerability Coordination: Serve as the technical lead for coordinating responses to security vulnerabilitiesĀ identifiedĀ in fieldedĀ IIoTĀ products, including working with Product, Engineering, and customers on disclosure and remediation timelines.Ā 
  • Supply Chain Security: Evaluate hardwareĀ componentĀ and third-party software supply chain risks, providing security requirements for procurement and vendor selection of embedded components.Ā 

Ā 

Governance, Consultation, and LeadershipĀ 

  • Security SME: Act as the primary subject matter expert forĀ IIoTĀ and OT product security, providing high-context technical consultation to product architects, engineering leads, and executive leadership.Ā 
  • Security Standards Ownership: Own the product security standards, policies, and design review processes applicable toĀ IIoTĀ devices, ensuring teams have clear, actionable requirements before development begins.Ā 
  • Cross-Functional Collaboration: Partner with Hardware, Firmware, Systems Engineering, and Product Management teams to embed security requirements early in the product development process without creating unnecessary friction.Ā 
  • Incident Leadership: Serve as the senior technical contributor during high-severity security incidents involving fieldedĀ IIoTĀ products, leading root cause analysis and driving architectural improvements to prevent recurrence.Ā 
  • Public Disclosure and Advisory: Coordinate with Threat Intelligence and engineering teams to documentĀ identifiedĀ vulnerabilities andĀ assistĀ in drafting CVEs and public security advisories following successful remediation.Ā 

TechnicalĀ Components

  • IIoTĀ and Embedded Security:Ā DemonstratedĀ expertiseĀ in securing embedded andĀ IIoTĀ devices, including secure boot, hardware security modules (HSMs), trusted execution environments (TEEs), and firmware security architecture.Ā 
  • Industrial Protocols: Working knowledge of industrial communication protocols common in energy and grid applications (IEC 61850, DNP3, Modbus, CAN bus) and their associated security considerations.Ā 
  • OT/ICS Security: Strong understanding of OT and ICS security principles, network segmentation strategies (e.g., Purdue Model, IEC 62443Ā zonesĀ and conduits), and the unique threat landscape of connected energy infrastructure.Ā 
  • PKI and Cryptography: Solid understanding of public key infrastructure, certificate lifecycle management for device identity, and applied cryptography as it relates to constrained embedded environments.Ā 
  • Security Standards: Deep familiarity with IEC 62443, UL 2900, NERC CIP, and NIST SP 800-82; ability to translate standards requirements into concrete, enforceable product security controls.Ā 
  • Threat Modeling: Proven experience leading structured threat modeling sessions for hardware/firmware products in OT or energy environments.
  • Performs other related duties as required and assigned.

The job description and responsibilities described are intended to provide guidelines for job expectations and the employee's ability to perform the position described. It is not intended to be construed as an exhaustive list of all functions, responsibilities, skills, and abilities. Additional functions and requirements may be assigned by supervisors as deemed appropriate.

How Does FTI Give YOU the Chance to Thrive?

If you’re energized by new challenges, FTI provides you with many opportunities. Joining FTI opens doors to redefine what’s possible for your future.

Once you’re a team member, you’re supported and provided with the knowledge and resources to achieve your career goals with FTI. You’re officially in the driver’s seat of your career, and FTI’s career development and continued education programs give you opportunities to position yourself for success.

FTI is a ā€œmerit to the coreā€ organization. We recognize and reward top performers, offering competitive, merit-based compensation, career path development and a flexible and robust benefits package.

Ā 

Benefits are the Game-Changer

We provide industry-leading benefits as an investment in the lives of team members and their families.Ā You’re invited to review the full list of FTI benefits available to regular/full-time team members. Start here. Grow here. Succeed here. If you’re ready to learn more about your career with FTI, apply today!

Faith Technologies, Inc. is an Equal Opportunity Employer – veterans/disabled.

Employment is contingent upon successfully passing a background and drug test




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Faith Technologies account will be created for you. Faith Technologies's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.