Responsibilities
- Partner with firmware, hardware, and product teams to strengthen cybersecurity considerations across product lifecycles.
- Provide technical guidance on implementation of security requirements and security controls for hardware and firmware-based products.
- Evaluate product security posture and implementation effectiveness with a security lens, identifying potential attack paths, control gaps, and risk areas.
- Help product teams prioritize practical mitigations based on product risk, exploitability, and business objectives.
- Support product teams in balancing cybersecurity rigor with product delivery objectives and business priorities.
- Facilitate product security risk assessments and support threat modeling activities across firmware-driven products.
- Assess product security risks across: authentication and authorization mechanisms, firmware update protections, secure boot and trust anchors, cryptographic protections, debug and manufacturing access controls, provisioning and lifecycle security mechanisms.
- Participate in technical reviews to evaluate security implementation effectiveness and identify opportunities for risk reduction.
- Support product security readiness activities by evaluating implementation effectiveness, security evidence, and residual product risk from an assurance perspective.
- Assess security posture and implementation effectiveness related to: authentication and authorization mechanisms, firmware update protections, secure boot and trust anchors, cryptographic protections, debug and manufacturing access controls, provisioning and lifecycle security mechanisms.
- Evaluate security artifacts and technical evidence including: threat modeling outputs, SAST and static analysis findings, SBOM and dependency risk visibility, fuzzing and penetration testing outcomes, vulnerability remediation activities, security validation evidence.
- Support customer, regulatory, and internal security assurance activities through technical assessment, documentation, and security evidence review.
- Provide technically grounded recommendations to strengthen product security posture, reduce risk, and improve confidence in product readiness.
- Identify recurring security gaps, lessons learned, and opportunities for scalable product security improvement across programs.
- Support Product Security Incident Response Team (PSIRT) activities, including vulnerability triage, technical assessment, remediation coordination, and product security risk evaluation.
- Conduct technical vulnerability assessments and support CVSS scoring activities based on exploitability, deployment context, product exposure, and customer impact.
- Partner with firmware and product teams to assess reported vulnerabilities, identify root causes, and recommend practical remediation strategies.
- Help translate vulnerability learnings into durable product security improvements and security best practices.
- Support coordination and technical analysis for external vulnerability disclosures, customer-reported issues, and security research findings.
- Author technical security white papers, technical guidance, and customer-facing security content related to product security posture, secure design practices, and emerging cybersecurity topics.
- Support customer security inquiries, product assurance requests, and technical cybersecurity discussions.
- Contribute to internal security guidance, reusable security patterns, and best practices to improve consistency across product teams.
- Collaborate closely with: Platform Security Architects, Firmware Engineering, Hardware/ASIC teams, Product Engineering, Validation teams, PSIRT, Product Security Assurance, External security assessment partners.
- Provide clear technical direction and risk-informed guidance to engineering and business stakeholders.
Requirements
- Strong technical depth in embedded systems and firmware
- Practical product security experience
- Ability to influence engineering teams toward scalable, risk-informed security outcomes
- Strong technical judgment
- Hands-on engagement
- Ability to communicate complex cybersecurity topics to engineering, business, and customer stakeholders