Lead Product Cybersecurity Engineer
Eaton Corporation
- Location
- Shenzhen, Guangdong, CHN, 518101
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 25 approvals (FY2023)
- Posted
- 2h ago
Skills
About this role
Eaton is an intelligent power management company dedicated to protecting the environment and improving the quality of life for people everywhere. We make products for the data center, utility, industrial, commercial, machine building, residential, aerospace and mobility markets. What you’ll do: As a Lead Product Cybersecurity Engineer, you will provide technical leadership for product cybersecurity, shape security architecture and risk decisions, and drive the integration of cybersecurity across the entire product lifecycle for Eaton products and solutions. • Lead threat modeling and risk assessment activities during early design phases, ensuring cybersecurity requirements are identified and integrated in alignment with relevant standards. • Lead the planning and execution of vulnerability assessments and penetration testing across Eaton products and solutions, while directly performing complex or high-risk testing of IoT devices, embedded systems, web/mobile applications, and industrial systems to identify, validate, and communicate security risks. • Define and review security architectures for complex products and solutions, including trust boundaries, attack surfaces, privilege models, data flows, defense-in-depth controls, and documented risk-based technical trade-offs. • Serve as a technical escalation point for complex product cybersecurity issues; lead design reviews, and drive alignment on risk-based decisions across global, cross-functional stakeholders. • Continuously monitor the evolving threat landscape, emerging technologies, and industry standards, driving improvements in internal cybersecurity frameworks and processes. • Lead the cybersecurity technical readiness for product certification activities, including interpretation of applicable requirements, review of supporting evidence, and engagement on technical issues related to standards such as UL 2900 and IEC 62443. Qualifications: Bachelor’s or master’s degree in Cybersecurity, Computer Science, Electronics Engineering, Electrical Engineering, or a related field. Minimum 10 years of relevant experience in product cybersecurity, embedded security, IoT security, or application security, including demonstrated technical leadership across complex product security programs. Proven experience across multiple phases of the Secure Product Development Lifecycle including threat modeling, security testing, and implementation validation. Strong experience in IoT / embedded / connected product cybersecurity. Hands-on experience in penetration testing and security assessment using tools such as Burp Suite, Kali Linux, Nessus, Coverity, Black Duck, and Defensics. Solid understanding of common attack vectors and effective mitigations across web, IoT, operating system, and cloud environments. Strong knowledge of communication and protocol security, including HTTPS, MQTT, SSH, Wi-Fi, Bluetooth, Zigbee, and ICS protocols. Strong knowledge and practical experience in embedded product security, including hardware roots of trust, secure boot and chain of trust, firmware signing and anti-rollback, secure update mechanisms, device identity, key provisioning and storage, debug interface protection, operating system hardening, and privilege separation. Proven ability to conduct threat modeling and risk assessments and translate findings into actionable security requirements. Programming or scripting experience in one or more languages. Familiarity with AI-assisted cybersecurity workflows and security considerations for AI-enabled products is a plus. Strong collaboration skills and ability to work effectively with global, cross-functional teams. Strong communication and presentation skills across engineering and business stakeholders. Fluent in English, able to collaborate and communicate effectively with global teams. At Eaton, we don’t just want to offer you a job, but a journey and experience. Our goal is to give you the space to find that