Lead Engineer, Product Cyber Security
Otis Worldwide
- Location
- Unit 2A & 2B (Octave Block), 6th floor, Parcel - 4, Salarpuria Sattva - Knowledge City, Madhapur, Hyderabad, Telangana, India, Zip/Postal Code: 500081
- Work model
- On-Site
- Level
- Senior
- Posted
- Aug 14, 2026
Skills
About this role
Location: Unit 2A & 2B (Octave Block), 6th floor, Parcel - 4, Salarpuria Sattva - Knowledge City, Madhapur, Hyderabad, Telangana, India, Zip/Postal Code: 500081 The Product Cyber Security Engineer works closely with product development teams across all global regions executing cyber security strategy of minimizing flaws and improving product resiliency to cyber-attacks by ensuring adherence to the integrated secure development lifecycle process, which embodies a secure-by-design defense in depth philosophy. You are a strong technical expert in matters related to threat modeling and cyber controls and will report to a team manager responsible for product architecture review and testing. This role is part of the Product Cyber team (under the Global DT Cyber team) which focuses on continuously improving the cyber posture of products that are often installed in customer's environments and products related to mobile and cloud components. On a typical day you will: Work with product development teams to conduct functional cybersecurity risk assessments and identify applicable cybersecurity requirements throughout the full development lifecycle. Develop standard work documents for cybersecurity controls that meet technical requirements for systems and components, including requirements arising from standards such as IEC 62443. Coordinate with quality and product development teams to periodically update cybersecurity design policies and ensure those policies are incorporated into product design, including requirements for traceability, system validation, and verification. Lead or support standard work associated with product cybersecurity incident response management. Work closely with the product testing teams to validate recommended security controls Continually enhance the capabilities of the cybersecurity team by identifying technology and methodology gaps, participating in and leading technical and industry committees, and creating a discipline health scorecard. Identification of technology and methodology gaps Participating in and leading technical and industry committees Work in an environment focused on continuous improvement, lean processes, and product development. Stay updated on latest cyber security hacking news, technologies and methodologies including: The latest attack methodologies, including penetration testing and red-team methodologies Latest forensic and incident response methodologies. Attend security and hacker conferences to stay on the cutting edge of cybersecurity practices. What You Will Need to be successfull: Ability to learn, adopt, and proficiently apply cybersecurity fundamentals, skills, and methods to design secure products and services. 5+ years of experience with product cybersecurity principles and hands-on implementation of security mitigation controls for products such as embedded, IoT, cloud, or mobile systems. Knowledge of IEC 62443 or similar recognized cybersecurity standards and frameworks. Knowledge of state-of-the-art cybersecurity controls and mitigation methods Working knowledge of cybersecurity threat modeling and systematic threat discovery throughout the product lifecycle. Experience of risk assessment and risk treatment strategies utilizing recognized risk management frameworks. Excellent written, verbal, and presentation skills, with the ability to communicate effectively with globally dispersed, cross-functional teams. Working knowledge of creating and using AI agents to automate workflows. Bachelor of Science or Engineering degree in cybersecurity, computer science, or a related engineering discipline. What is Nice to Have: Strong knowledge of cryptographic systems and requirements for authentication, authorization, and encryption across different types of systems. Knowledge and experience with incident response management and risk assessment Collaboration and contributions to global standards or related published papers. Experience with