Cybersecurity Engineer - Product Cybersecurity
Wabtec CorporationMatch Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessMetro location plus senior, visible cybersecurity role increases applicant density despite specialized skills.
Requires embedded product security and industrial standards expertise, making cross-industry transferability low.
Explicit 8-10 years and mandatory hands-on product cybersecurity experience make screening highly strict.
Job Description
Structured overview of role & requirementsAbout This Role
Conduct cybersecurity assessments and reviews of Wabtec products through the Software Development Lifecycle ensuring compliance with company cybersecurity standards and controls.
Provide expert guidance and support to engineering teams on threat modeling, risk assessments, secure design principles, and mitigation strategies for web and embedded systems.
Develop and deliver cybersecurity training and awareness programs, and contribute to improving product security maturity and incident response activities.
Minimum Requirements
Bachelor's degree in Computer Science, Cybersecurity, or related field.
8-10 years experience designing, developing, and testing web-based, embedded, or connected systems.
4+ years hands-on experience in product/application cybersecurity engineering, architecture, risk assessment, or risk management.
Experience with threat modeling, vulnerability assessments, security testing, and relevant cybersecurity frameworks such as IEC 62443, NIST 800-53, or ISO/IEC 27001.
Ideal Candidate Profile
Experienced with secure product development processes and DevSecOps practices in industrial or critical infrastructure sectors (rail, transportation, mining, automotive, manufacturing).
Ability to independently manage priorities and influence cybersecurity improvements in a global, matrixed organization working with diverse technical and non-technical stakeholders.
Strong knowledge of security architecture, cryptographic technologies (e.g., PKI, secure boot), and evolving cybersecurity threats and industry trends.
