Job Title: Senior Product Security Engineer
Location: Pewaukee, WI ,53072
Duration: 06 Months Contract
Description:
Role Level
- Mid-level to Senior
- Must be able to hit the ground running
- 5+ years of hands-on experience
- No time for training
Core Requirements
Must-Have Technical Skills
- Security lifecycle process
- Manufacturing background/ certifications
- Product Lifecycle management and architecture background
Day-to-Day Responsibilities
- Start out being involved with product team and if they have questions then sit on calls with them.
- POC for the products team.
- IOT need due to products being developed in manufacturing space and they have robotics and understanding product security side and OT protections and manufacturing facilities wise and what they manufacturing standards are and lifecycles for security.
- Facility is meeting requirements as well.
- Working with product team and other product team engineers.
- Work with development team as well for the product side.
- Little light in the beginning and then building it out further - still enough work but slower in the start.
- Lifecycle management.
Overview
We are seeking a Senior Product Security Engineer to lead the security design and governance of our Industrial Internet of Things (IIoT) and Grid connected product portfolio. Reporting to the Cybersecurity Manager, this role is the primary technical authority for IIoT product security across the entire device lifecycle - from early design through field deployment and ongoing operation.
This is a deeply technical role focused on hardware and embedded systems security, OT/IT convergence, and the application of industrial security standards. Day-to-day development and DevSecOps execution (code scanning, firmware management, CI/CD pipeline tooling) is owned by the Product Security Engineer II; the Senior Engineer operates at the architectural, standards, and cross-functional leadership level.
Core Responsibilities
IIoT Security Architecture and Standards
- Security Architecture: Define and own the security architecture for connected IIoT products, including device identity frameworks (PKI/certificate management), secure boot chains, cryptographic key management, and hardware root of trust.
- Industrial Standards Leadership: Establish and enforce security design requirements based on applicable standards and frameworks (e.g., IEC 62443, UL 2900, NERC CIP, NIST SP 800-82, NIST CSF) across product lines.
- OT/IT Convergence: Design security boundaries and communication controls for environments where operational technology (OT) interfaces with enterprise IT systems, ensuring defense-in-depth across both layers.
- Protocol and Interface Security: Evaluate and provide security guidance on industrial communication protocols used in energy and grid applications (e.g., IEC 61850, DNP3, Modbus, CAN bus, GOOSE/Sampled Values).
Threat Modeling and Risk Management
- Lead Threat Modeling: Conduct and lead structured threat modeling exercises (e.g., STRIDE, PASTA) for new IIoT product initiatives and significant feature changes, translating identified risks into actionable design controls.
- Risk Prioritization: Assess and prioritize security risks across fielded and in-development device portfolios based on exploitability, potential impact to grid operations or physical safety, and business criticality.
- Vulnerability Coordination: Serve as the technical lead for coordinating responses to security vulnerabilities identified in fielded IIoT products, including working with Product, Engineering, and customers on disclosure and remediation timelines.
- Supply Chain Security: Evaluate hardware component and third-party software supply chain risks, providing security requirements for procurement and vendor selection of embedded components.
Governance, Consultation, and Leadership
- Security SME: Act as the primary subject matter expert for IIoT and OT product security, providing high-context technical consultation to product architects, engineering leads, and executive leadership.
- Security Standards Ownership: Own the product security standards, policies, and design review processes applicable to IIoT devices, ensuring teams have clear, actionable requirements before development begins.
- Cross-Functional Collaboration: Partner with Hardware, Firmware, Systems Engineering, and Product Management teams to embed security requirements early in the product development process without creating unnecessary friction.
- Incident Leadership: Serve as the senior technical contributor during high-severity security incidents involving fielded IIoT products, leading root cause analysis and driving architectural improvements to prevent recurrence.
- Public Disclosure and Advisory: Coordinate with Threat Intelligence and engineering teams to document identified vulnerabilities and assist in drafting CVEs and public security advisories following successful remediation.
Required Technical Qualifications
- IIoT and Embedded Security: Demonstrated expertise in securing embedded and IIoT devices, including secure boot, hardware security modules (HSMs), trusted execution environments (TEEs), and firmware security architecture.
- Industrial Protocols: Working knowledge of industrial communication protocols common in energy and grid applications (IEC 61850, DNP3, Modbus, CAN bus) and their associated security considerations.
- OT/ICS Security: Strong understanding of OT and ICS security principles, network segmentation strategies (e.g., Purdue Model, IEC 62443 zones and conduits), and the unique threat landscape of connected energy infrastructure.
- PKI and Cryptography: Solid understanding of public key infrastructure, certificate lifecycle management for device identity, and applied cryptography as it relates to constrained embedded environments.
- Security Standards: Deep familiarity with IEC 62443, UL 2900, NERC CIP, and NIST SP 800-82; ability to translate standards requirements into concrete, enforceable product security controls.
- Threat Modeling: Proven experience leading structured threat modeling sessions for hardware/firmware products in OT or energy environments.
Leadership and Soft Skills
- Influence without authority: Demonstrated ability to drive security decisions across hardware, firmware, and systems engineering teams through technical credibility and clear communication of risk.
- Communication: Ability to articulate complex IIoT security risks and architectural trade-offs to both executive leadership and technical engineering teams.
- Analytical Decision Making: Capable of assessing risk across a diverse device portfolio, balancing security requirements against product constraints (cost, connectivity, compute limits) and operational realities of energy infrastructure.
Preferred Qualifications
- Bachelor's degree or equivalent experience in Information Security, Electrical Engineering, Computer Engineering, or a related technical field.
- Industry-recognized security certifications preferred but not required (e.g., GICSP, CISSP, ISA/IEC 62443 Cybersecurity Certificate Program, CSSA).
- 5+ years of dedicated experience in product security, embedded/IIoT security, or OT/ICS security, with at least 2 years in a senior or lead capacity.
- Experience with energy sector products or grid-connected devices (switchgear, UPS, inverters, DERs) is strongly preferred
Contact:
Jaya Balaji: jayabalaji.s@sunrisesys.com | (732) 515-5373 | URL:
www.sunrisesys.com