... for penetration testing of embedded devices, mobile applications, and cloud services; review ... IoT cybersecurity and provide recommendations to improve architectures, controls, and processes.
... for penetration testing of embedded devices, mobile applications, and cloud services; review ... IoT cybersecurity and provide recommendations to improve architectures, controls, and processes.
IoT Technology Experience with the applicable, recognized certification in the following areas is recommended but not necessary: * Penetration Testing * Social Engineering * Phishing Email Campaigns
IoT Technology Experience with the applicable, recognized certification in the following areas is recommended but not necessary: * Penetration Testing * Social Engineering * Phishing Email Campaigns
IoT Technology Experience with the applicable, recognized certification in the following areas is recommended but not necessary : * Penetration Testing * Social Engineering * Phishing Email Campaigns
Quick apply
IoT Technology Experience with the applicable, recognized certification in the following areas is recommended but not necessary : * Penetration Testing * Social Engineering * Phishing Email Campaigns
Cyber Security Engineer
Indianapolis, IN · On-site
IoT Technology Experience with the applicable, recognized certification in the following areas is recommended but not necessary : * Penetration Testing * Social Engineering * Phishing Email Campaigns
Cyber Security Engineer
Indianapolis, IN · On-site
IoT Technology Experience with the applicable, recognized certification in the following areas is recommended but not necessary : * Penetration Testing * Social Engineering * Phishing Email Campaigns
... Penetration Testing, Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), Data Loss Prevention, IPS/IDS, Cloud Services, IoT / OT Security, Data ...
... Penetration Testing, Security Information and Event Management (SIEM), Security Orchestration, Automation, and Response (SOAR), Data Loss Prevention, IPS/IDS, Cloud Services, IoT / OT Security, Data ...
Iot Penetration Testing information
What is the difference between Iot Penetration Testing vs Iot Security Analyst?
| Aspect | Iot Penetration Testing | Iot Security Analyst |
|---|---|---|
| Certifications | CEH, OSCP, CISSP | CISSP, GIAC, CompTIA Security+ |
| Work Environment | Hands-on testing, vulnerability assessment | Monitoring, policy development, incident response |
| Employer & Industry Usage | Cybersecurity firms, tech companies, government agencies | Organizations with IoT infrastructure, manufacturing, healthcare |
While both roles focus on IoT security, Iot Penetration Testing involves actively probing IoT devices for vulnerabilities, whereas Iot Security Analysts monitor and develop strategies to protect IoT systems. The roles complement each other in securing IoT environments.
- Internship Web Penetration Tester
- Cyber Security Penetration Tester
- Senior Security Researcher
- Senior Penetration Tester
- Remote Penetration Tester
- Junior Penetration Tester
- Freelance Penetration Testing Ethical Hacking
- Internship Vulnerability Assessment Penetration Testing
- Mid Penetration Tester
- Penetration Tester
- Pnpt Certification
- Salaried Oscp Remote
- Red Teaming
- Temporary Cybersecurity Penetration Tester
- Oscp Salary
- Freelance Penetration Tester Ethical Hacker
- Remote Cybersecurity Penetration Tester
- Evening Penetration Tester Red Team
- Overnight International Penetration Tester
- Freelance Cybersecurity Penetration Tester
Full-time
Re-posted 18 days ago
Job description
LHP Engineering Solutions is a global Functional Safety leader committed to creating safe transportation with developing technologies such as Electric Vehicles and Advanced Driver Assistance Systems. They are seeking a Senior Embedded Cybersecurity Engineer to act as the cybersecurity lead for connected, firmware-based products, working closely with various teams to ensure secure solutions throughout the product lifecycle.
Responsibilities:
• Serve as the cybersecurity subject-matter expert in new product development (NPD) firmware activities and cross-functional project meetings.
• Provide cybersecurity and IT operational guidance to firmware, platform, and IT teams on secure design, coding, configuration management, and deployment practices.
• Manage cybersecurity aspects of Azure build/CI/CD pipelines, including Azure DevOps (ADO), Azure Key Vaults, and key/certificate lifecycle management.
• Lead and document cybersecurity risk assessments for critical assets (embedded devices, cloud services, mobile applications, manufacturing systems, and supporting IT infrastructure).
• Perform cybersecurity assessments (Ex: RED EN-18031 and CRA assessments) on targeted products and coordinate remediation with engineering teams.
• Develop, implement, and maintain cybersecurity policies and processes for IoT products across development, production, manufacturing, operations, and post-deployment support.
• Create and maintain cybersecurity work products and evidence to support ISO 27001 certification and other relevant standards.
• Review, triage, and drive closure of Azure ADO tickets related to cybersecurity implementation and vulnerabilities.
• Coordinate and provide technical guidance for penetration testing of embedded devices, mobile applications, and cloud services; review findings and drive remediation plans.
• Monitor industry trends, standards, and regulations related to embedded/IoT cybersecurity and provide recommendations to improve architectures, controls, and processes.
Qualifications:
Required:
• B.S. or M.S. in Electrical Engineering, Computer Engineering, Computer Science, Cybersecurity, or a related field.
• 5+ years of experience in embedded, IoT, or OT cybersecurity, including hands-on work with firmware-based products.
• Demonstrated experience with Azure DevOps (ADO) pipelines and Azure Key Vault (or similar CI/CD and secret-management platforms), including key and certificate lifecycle management.
• Strong background in cybersecurity risk assessment and management (e.g., threat modeling, risk analysis methods) and familiarity with ISO 27001 and at least one of ISO 21434 or IEC 62443.
• Solid understanding of embedded hardware/software interactions, secure boot concepts, and common attack vectors against embedded and IoT devices.
• Experience with communication protocols used in automotive, material handling, or industrial systems (Ex: CAN, LIN, Ethernet/TCP/IP, industrial fieldbuses).
• Proven ability to collaborate with multi-disciplinary teams (firmware, IT, DevOps, manufacturing, suppliers, and leadership) and communicate complex cybersecurity topics clearly to non-experts.
• Strong documentation, ticketing, and organizational skills.
Preferred:
• Experience performing or leading assessments against RED EN-18031 and/or EU Cyber Resilience Act requirements.
• Prior experience supporting ISO 27001 certification efforts, including creation of policies, procedures, and audit evidence.
• Experience coordinating third-party penetration tests and managing remediation programs.
• Knowledge of hardware security modules (HSMs), secure elements, and secure boot implementations for embedded devices.
• Familiarity with automotive/industrial safety and quality standards (Ex: ISO 26262, ASPICE) and their relationship to cybersecurity.
• Professional certifications such as CISSP, CSSLP, CEH, or comparable credentials.
Company:
LHP has provided engineering consulting, training, and technology solutions within the automotive/transportation industry for over 20 years. Founded in 2001, the company is headquartered in Columbus, USA, with a team of 501-1000 employees. The company is currently Late Stage.
About LHP Engineering Solutions
Sourced by ZipRecruiter
Industry
Industrial machinery manufacturing
Company size
201 - 500 Employees
Headquarters location
Columbus, IN, US
Year founded
2001