More jobs:
Product Cybersecurity Manager
Job in
Dearborn, Wayne County, Michigan, 48120, USA
Listed on 2026-06-26
Listing for:
Ford Energy
Full Time
position Listed on 2026-06-26
Job specializations:
-
Engineering
Cybersecurity
Job Description & How to Apply Below
We are seeking a Product Cybersecurity Manager with deep technical expertise in firmware, hardware, and penetration testing. In this role, you will implement, validate, and optimize security controls across the entire lifecycle of our BESS portfolio. You will support immediate product security initiatives—ensuring robust defense‑in‑depth from early‑stage hardware development through deployment—and serve as the senior technical security lead for our BESS product portfolio.
Responsibilities- End‑to‑End Security Architecture & Engineering
- Lifecycle Integration
:
Lead and integrate cybersecurity engineering across the entire battery storage system lifecycle, including design, manufacturing, deployment, operations, and decommissioning. - Hardware & Firmware Hardening
:
Define, implement, and audit security controls at the silicon, microcontroller, and firmware levels, including secure boot, cryptographic key management, secure storage, and Hardware Security Modules (HSMs). - Technical Innovation
:
Develop solutions to unusually complex cyber‑physical security problems that require a high degree of ingenuity and creativity. Establish engineering precedents and design patterns that will serve as the template for future product lines and support the long‑term reputation of the organization. - Threat Modeling & Offensive Security Validation
- Cyber‑Physical Threat Modeling
:
Lead threat modeling (e.g., STRIDE) and risk assessments to resolve highly ambiguous, large‑scale technical challenges across battery management systems (BMS), power conversion systems (PCS), and overall BESS architectures. Develop novel, high‑performance, and resilient security frameworks under extreme hardware and operational constraints. - Active Penetration Testing
:
Plan, coordinate, and execute hands‑on penetration testing and vulnerability assessments on embedded hardware, firmware, and communication protocols (e.g., Modbus, CAN, DNP3, and TCP/IP). - Governance, Compliance & Incident Management
- Standards & Framework Alignment
:
Align product engineering processes and security controls with relevant industry standards and frameworks (e.g., IEC 62443, ISO 21434, UL 2900, and NIST SP 800‑82). - Project Risk Governance
:
Establish and manage cybersecurity work packages, compile risk registers, and represent cybersecurity requirements in stage‑gate reviews and engineering boards. - Incident Response Operations
:
Develop and support security incident response playbooks for fielded BESS assets, and manage coordinated vulnerability disclosure for discovered firmware/hardware bugs. - Cross‑Functional Collaboration & Technical Leadership
- Consensus Building
:
Drive technical security direction and best practices across multiple engineering teams (hardware, firmware, cloud, and systems), building architectural consensus for end‑to‑end product security. - Talent Mentorship
:
Actively mentor and guide peers to elevate the collective technical cybersecurity capabilities of the organization.
- Experience
: A minimum of 5–7 years of experience in Embedded Systems Security, Product Cybersecurity, or Security Engineering, with a proven track record in a product lead or senior technical capacity. - Education
:
Bachelor’s or Master’s degree in Computer Engineering, Electrical Engineering, Computer Science, Cybersecurity, or a related technical field. - Hardware & Firmware Security
:
Expert‑level proficiency in secure coding practices (C/C++ or Rust), hardware architectures, secure boot, JTAG debugging protection, and cryptographic implementations. - Penetration Testing
:
Strong hands‑on experience performing penetration testing on physical hardware interfaces (e.g., UART, JTAG, SPI, and I2C) and industrial/automotive network protocols (e.g., CAN, Modbus, and DNP3). - Threat Modeling & Risk Assessment
:
Demonstrated experience conducting threat modeling and risk assessments for complex cyber‑physical or industrial control systems (ICS). - Standards & Regulations
:
Deep familiarity with cybersecurity frameworks and standards relevant to embedded systems and critical infrastructure (e.g., IEC 62443, ISO 21434, or UL 2900).
- Experience in Renewable Energy, Automotive (EV/BMS), or…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×