Product Security Engineer

Phoenix Contact — Poland · Posted ~4 hours ago

Senior Full-time

Skills

Cybersecurity Secure software development lifecycle Threat modeling Risk assessment IEC 62443 Security testing CI/CD

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Join a security-focused engineering team responsible for protecting connected industrial solutions. The role covers security strategy, threat analysis, secure development processes, compliance, and mentoring security specialists.

Highlights

Lead security initiatives for industrial solutions with responsibility for secure development practices, compliance, and security governance.

Description

Your responsibilities: Ownership of the end-to-end security strategy for all Industrial Cabinet Solutions (ICS) software and firmware developmentDrive implementation and continuous improvement of secure-by-design principles aligned with ISA/IEC 62443 standardsEnsure compliance with applicable legislation – in particular the EU Cyber Resilience Act (CRA) – including conformity assessments, vulnerability reporting requirements, and CE marking preparationReview and approve security test plans, penetration testing schedules, and red team activitiesGovern ongoing threat modeling and risk assessments for ICS' SaaS products and connected devicesDevelop and maintain security guidelines, procedures, and governance frameworksReport security posture, risks, and initiatives to business unit leadershipOversee secure software development lifecycle (SSDLC) integration into CI/CD pipelines and define and observe security related KPIsMentoring ethical hackers and security testersContributing to the wider PSSE community at the Phoenix Contact group Success Metrics: Reduction in security vulnerabilities identified post-releaseTime-to-remediation for critical and high-severity vulnerabilitiesSuccessful completion of penetration tests and security auditsTeam security competency growth (certifications, training completion)Compliance readiness for EU CRA by enforcement date (December 2027)Guardrail improvements and security KPIs Requirements: Bachelor’s degree in cyber security or equivalent professional experienceFundamental knowledge of all aspects of cyber security including security management, system security and administration, network protocols, programming languages, threat and risk analysis, and security testingExtensive skills in at least one of the areas listed aboveFamiliarity with ISA/IEC 62443 (industrial automation cybersecurity) standardsUnderstanding of EU Cyber Resilience Act requirements and implementation timelinesKnowledge of relevant frameworks (NIST CSF, ISO 27001, OWASP)Excellent written and spoken English (at least CEFR level C1) Nice to have: Bachelor’s and master’s degrees in cyber securityIndustry certifications, in particular Offensive Security Certified Professional (OSCP), Certified Penetration Testing Specialist (CPTS), Certified Secure Software Lifecycle Professional (CSSLP), or Global Industrial Cyber Security Professional (GICSP)Working proficiency in German (CEFR level B2)