QNX Cybersecurity Analyst (Embedded)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Cybersecurity Analyst (Embedded/RTOS): Analyzing open-source vulnerabilities and assessing their impact on embedded and RTOS-based products with an accent on vulnerability triage and risk assessment. Focus on managing product security catalogs, performing SCA scan reviews, and collaborating with engineering teams to remediate security incidents.
Location: Ottawa, Ontario
Salary: $80,000 - $112,500
Company
provides a trusted foundation for software-defined businesses, specializing in critical embedded systems for automotive, medical, and industrial sectors.
What you will do
- Perform technical analysis of open-source vulnerabilities (CVEs) and assess their impact on embedded and RTOS-based products.
- Triage external vulnerability reports, analyze risk, and communicate findings to engineering and business stakeholders.
- Maintain the product security catalog and assess CVEs flagged by automated monitoring systems.
- Review, analyze, and report on Software Composition Analysis (SCA) scan results.
- Act as a product security point-of-contact for internal teams and external customers.
- Collaborate with development teams and project managers to drive security incidents through investigation and remediation.
Requirements
- Hands-on experience working with product security teams and performing vulnerability assessments.
- Solid working knowledge of CVE, CWE, and CPE ecosystems in real-world security contexts.
- Experience with embedded or systems software using C, C++, and/or Python.
- Familiarity with secure software development in regulated or safety-critical environments.
- Basic understanding of industry standards such as ASPICE, ISO 26262, ISO 21434, and UNECE WP.29 R155.
- Strong written and verbal communication skills for explaining technical topics to varied audiences.
Culture & Benefits
- Competitive base salary with the Variable Incentive Pay (VIP) bonus program.
- Comprehensive health benefits including medical, dental, and vision coverage.
- Financial well-being support through life, disability insurance, and retirement plans.
- Employee share purchase program and paid-time-off.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →