Johnson Controls

Principal Product Security Engineer

Pune, Maharashtra, India
Python Perl Java C++ Linux Kali Nessus Netsparker OpenVAS BurpSuite Metasploit ARM RTOS C OWASP NIST 800-53 ISO 27001 GDPR SOC 2 CSSLP CISSP CCSP OSCP CEH Git Jira Docker Kubernetes AWS Azure GCP API Microservices
Description

Principal Product Security Engineer

Location: Pune-Maharashtra-India

Time Type: Full time

Job Description

What we look for

· Technical and operational excellence, thought leadership, and integrative thinking.

· Expert knowledge and practical product and software security experience, including secure SDLC practices, security and privacy by design architectures, and secure by default configurations.
 

Strong problem-solving skills to analyze cybersecurity issues and requirements (legal/regulatory, policy, customer, industry standards) and relate them to appropriate security controls.

· Demonstrated ability to lead change initiatives that intelligently manage software cyber risks.

· Proven ability to deliver results using agile methodologies and tools (e.g. Scrum/Kanban, Jira).

· Understanding of agile software development and continuous integration/deployment.

· Practical experience with Linux OS, programming and scripting languages (e.g. Java, Python, Perl), and security tools (e.g. Kali, Nessus, Netsparker, openVAS, BurpSuite, Metaspolit).

· Understanding of embedded systems architectures (e.g. ARM, Cortex), embedded systems tools/emulators, RTOS/Linux, network protocols and programming languages (such as C/C++).

· Understanding of penetration testing, reverse engineering, software attack vectors, fault injection, device fingerprinting, and tamper resistance.

· Understanding TPM, Secure Boot, OTP, PKI, SPI/I2C bus analyzers, JTAG probing.

· Knowledge of current security threats and techniques for exploiting software vulnerabilities.

· Understanding of web and mobile application secure design principles such as OWASP.

· Understanding of data protection, secure cloud, and network infrastructure design principles.

· Familiarity with technology risk management related frameworks such as RMF, NIST 800-53, ISA/IEC 62443, UL CAP, ISO 27001, GDPR, CSL, CSA, SOC 2 and other comparable.

· Experience with Operational Technologies (e.g. Controls Systems, Building Management) a plus.

· Superior interpersonal, organizational, written/verbal communication, and presentation skills.

· Ability to build trust with stakeholders and explain complex security topics to all audiences.

· Active participation in hackathons, cybersecurity competitions, and exercises are a plus.

· CSSLP, CISSP, CCSP, OSCP, CEH or related cybersecurity certifications.

· Bachelors degree in Cybersecurity, Computer Science, Engineering, Information Systems, or related technical degree.

· Minimum of 7 years of experience with at least 5 years in software or product cybersecurity.

· Travel is occasional at approximately 10%, including international.

Johnson Controls
Johnson Controls

0 applies

0 views

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got over 200,000 jobs from 15,000+ vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 15,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say