ForgeApply
Try it free

ForgeApply · Job listing

Senior Product Security Engineer

FTI

WI - Menasha, UShybrid

Tailor your resume for this FTI job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for FTI's site. Free trial, no card required.

About this role

You’ve discovered something special. A company that cares. Cares about leading the way in construction, engineering, manufacturing and renewable energy. Cares about redefining how energy is designed, applied and consumed. Cares about thoughtfully growing to meet market demands. And ─ as “one of the Healthiest 100 Workplaces in America” ─ is focused on the mind/body/soul of team members through our Culture of Care .

The Senior Product Security Engineer leads the security   design   and governance of our Industrial Internet of Things ( IIoT )   and Grid connected   product portfolio. Reporting to the   Cybersecurity Manager , this role is the primary technical authority for   IIoT   product security across the entire device lifecycle - from early design through field deployment and ongoing operation.  

This is a deeply technical role focused on hardware and embedded systems security, OT/IT convergence, and the application of industrial security standards. Day-to-day development and   DevSecOps   execution (code scanning, firmware management, CI/CD pipeline tooling) is owned by the Product Security Engineer II; the Senior Engineer   operates   at the architectural, standards, and cross-functional leadership level.

MINIMUM REQUIREMENTS Education: Bachelor's degree or equivalent experience in Information Security, Electrical Engineering, Computer Engineering, or   a related   technical field. Experience: 5+ years of dedicated experience in product security, embedded/ IIoT   security, or Education: I ndustry-recognized security certifications preferred but not   required   (e.g., GICSP, CISSP, ISA/IEC 62443 Cybersecurity Certificate Program, CSSA).   Experience: OT/ICS security, with at least 2 years in   a senior   or lead capacity and

Travel: 5-10% Work Schedule: Typical work hours are between 7:00 a.m. and 5:00 p.m. Monday – Friday. However, work may be performed at any time on any day of the week to meet business needs.    KEY RESPONSIBILITIES IIoT   Security Architecture and Standards  

• Security Architecture: Define and own the security architecture for connected   IIoT   products, including device identity frameworks (PKI/certificate management), secure boot chains, cryptographic key management, and hardware root of trust.   • Industrial Standards Leadership:   Establish   and enforce security design requirements based on applicable standards and frameworks (e.g., IEC 62443, UL 2900, NERC CIP, NIST SP 800-82, NIST CSF) across product lines.   • OT/IT Convergence: Design security boundaries and communication controls for environments where operational technology (OT) interfaces with enterprise IT systems, ensuring defense-in-depth across both layers.   • Protocol and Interface Security: Evaluate and   provide   security guidance on industrial communication protocols used in energy and grid applications (e.g., IEC 61850, DNP3, Modbus, CAN bus, GOOSE/Sampled Values).  

Threat Modeling and Risk Management  

• Lead Threat Modeling: Conduct and lead structured threat modeling exercises (e.g., STRIDE, PASTA) for new   IIoT   product initiatives and significant feature changes, translating identified risks into actionable design controls.   • Risk Prioritization: Assess and prioritize security risks across fielded and in-development device portfolios based on exploitability, potential impact to grid operations or physical safety, and business criticality.   • Vulnerability Coordination: Serve as the technical lead for coordinating responses to security vulnerabilities   identified   in fielded   IIoT   products, including working with Product, Engineering, and customers on disclosure and remediation timelines.   • Supply Chain Security: Evaluate hardware   component   and third-party software supply chain risks, providing security requirements for procurement and vendor selection of embedded components.  

Governance, Consultation, and Leadership  

• Security SME: Act as the primary subject matter expert for   IIoT   and OT product security, providing high-context technical consultation to product architects, engineering leads, and executive leadership.   • Security Standards Ownership: Own the product security standards, policies, and design review processes applicable to   IIoT   devices, ensuring teams have clear, actionable requirements before development begins.   • Cross-Functional Collaboration: Partner with Hardware, Firmware, Systems Engineering, and Product Management teams to embed security requirements early in the product development process without creating unnecessary friction.   • Incident Leadership: Serve as the senior technical contributor during high-severity security incidents involving fielded   IIoT   products, leading root cause analysis and driving architectural improvements to prevent recurrence.   • Public Disclosure and Advisory: Coordinate with Threat Intelligence and engineering teams to document   identified   vulnerabilities and   assist   in drafting CVEs and public security advisories following successful remediation.  

Technical  Components

• IIoT   and Embedded Security:   Demonstrated   expertise   in securing embedded and   IIoT   devices, including secure boot, hardware security modules (HSMs), trusted execution environments (TEEs), and firmware security architecture.   • Industrial Protocols: Working knowledge of industrial communication protocols common in energy and grid applications (IEC 61850, DNP3, Modbus, CAN bus) and their associated security considerations.   • OT/ICS Security: Strong understanding of OT and ICS security principles, network segmentation strategies (e.g., Purdue Model, IEC 62443   zones   and conduits), and the unique threat landscape of connected energy infrastructure.   • PKI and Cryptography: Solid understanding of public key infrastructure, certificate lifecycle management for device identity, and applied cryptography as it relates to constrained embedded environments.   • Security Standards: Deep familiarit

Tailor your resume for this FTI role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Security & Cybersecurity Jobs · More jobs at FTI · Browse all jobs

Free ATS checker · No Salary on the Job Posting? How to Find the Number Before You Interview