This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Cybersecurity Engineer (CSE) works within the systems engineering function and is directly engaged with the development of secure, robust and resilient vehicle solutions for powertrain electrification (BEV, HEV, EV, etc) projects. Those solutions range across hardware and software, including but not limited to immobilizers/anti-theft devices, manipulation detection system, secure boot methods, key storage and management, secure on-board communication and secure diagnostics, hardware trust anchors (microcontroller hardware security modules). The CSE supports the development team in ensuring all aspects of the stakeholder requirements are implemented and tested according to the latest automotive cybersecurity standards and best practices.
Job Responsibility:
Conduct the cybersecurity activities for a given project
Interface with customer on technical cybersecurity requirements and issues
Create a cybersecurity assurance case per project and the related documentation
Perform cybersecurity risk assessments and threat modelling within a product scope
Analyse and determine safety, financial, operational and privacy issues identified in a risk analysis
Where there are safety impacts, work with the Functional Safety (ISO 26262) team to find solutions
Suggest countermeasures appropriate to the project given the technical constraints or operational limitations
Create and maintain a knowledge database of typical assets, threats and attack paths for our product portfolio
Create and maintain solutions to manage cybersecurity risks
Drive cybersecurity solution development and provide technical support for hardware and software teams
Engage with suppliers to evaluate cybersecurity capabilities and track reported vulnerabilities
Evaluate new tools (Threat Analysis tool, Software Bill of Material tool, etc.)
Be part of vulnerability monitoring and incident response teams
Follow and contribute to the secure development lifecycle at BorgWarner
Network and maintain a high-level of industry knowledge
Help promoting a safety and security culture
Support the roll-out of processes and procedures compliant with latest cybersecurity standards and regulations
Assist in training and raising awareness, organizing events
Requirements:
Bachelor’s degree in Electrical Engineering, Mechatronics Engineering or similar
2+ years of experience in an embedded cybersecurity position or 4+ years in an embedded systems development, preferably for ASPICE compliant projects
Understanding of multi-core embedded microcontrollers that use HTAs (hardware trust anchors) or HSMs (hardware security modules)
Understanding of cybersecurity specific testing such as penetration and fuzz testing
Good understanding of formal risk assessment and management, knowledge of NIST SP-800-30 and ISO IEC 31010
Experience in the automotive or transportation domain
Experience with requirements engineering, ability to navigate through multiple customer specifications as well as published standards and policies (UNECE WP.29 R155 CSMS, R156 SUMS, ISO/SAE 21434)
Familiarity with cryptography and cybersecurity concepts such as defense in depth, access control models, memory protection, secure boot, Secure Coding, public key infrastructure (PKI)
Ability to work easily with Office software suite and engineering software (prior experience with simulation or analysis tools like Ansys Medini Analyze for instance)
Strong communication and analytical skills
Ability to work independently, take ownership of project deliverables, go above and beyond the task at hand
Fluency in English is required
Willingness to travel occasionally, both domestically and internationally
Nice to have:
German and/or French would be an advantage
What we offer:
Private Medicover medical care for the employee and their family
Co-financing for the sport card Multisport
Possibility to join the PZU insurance
Flexible working hours
Salary adequate to skills and experience
Co-financing for holidays
Hard and soft training, language courses
Hybrid working model (2 days per week remote work)