обновлено 9 дней назад
Cybersecurity Governance & Assurance Specialist (Automotive)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Cybersecurity Governance & Assurance Specialist (Automotive): Managing product cybersecurity governance and compliance frameworks for off-highway machinery with an accent on ISO/SAE 21434, ISO 24882, and Cyber Resilience Act (CRA) standards. Focus on executing compliance assessments, coordinating testing activities, and establishing post-production vulnerability management workflows.
Location: London, United Kingdom
Company
is an independent technology consulting firm providing engineering, digital, telecom, and life sciences solutions to business clients worldwide.
What you will do
- Own and maintain the product cybersecurity governance and assurance framework for off-highway machinery programmes.
- Develop standards, templates, checklists, guidance, and training for consistent cybersecurity execution.
- Plan and conduct compliance assessments of product programmes and suppliers, reporting risks and evidence gaps.
- Review TARA outputs, cybersecurity requirements, architecture evidence, testing strategies, and residual risk statements.
- Define cybersecurity testing expectations and coordinate Red Team activities, remediation, and assurance evidence.
- Establish post-production vulnerability governance, support Cyber Resilience Act Article 14 reporting, and feed lessons learned into standards and training.
Requirements
- At least 3 years of cybersecurity experience in a Tier 1 or OEM environment, preferably in on-highway or off-highway sectors.
- Experience in product cybersecurity assurance, governance, compliance assessment, or cybersecurity audit for embedded or cyber-physical products.
- Strong working knowledge of ISO/SAE 21434 and ISO 24882, plus working knowledge of IEC 62443 and supplier assurance.
- Familiarity with Cyber Resilience Act compliance, including Article 14 reporting workflows.
- Excellent technical writing, communication, stakeholder management, analytical, and pragmatic problem-solving skills.
- Professional English is required for the role.
Nice to have
- Experience with TARA, threat modelling, attack trees, vulnerability management, and post-production monitoring.
- Experience in cybersecurity requirements engineering and cybersecurity testing evidence.
- Knowledge of functional safety interfaces, ECUs, CAN, J1939, UDS diagnostics, and SBOM concepts.
Culture & Benefits
- International community representing more than 110 nationalities.
- Internal Academy with more than 250 training modules.
- Trust-focused environment with opportunities for internal career progression.
- Regular internal events, including afterworks and team-building activities.
Hiring process
- Brief virtual or phone call.
- Approximately three interviews, depending on seniority.
- Possible case study, technical assessment, role play, or problem-solving exercise.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
OT Assurance Consultant (Cybersecurity)
4 дня назад
Cyber Security Analyst (Cybersecurity)
4 дня назад
Senior Systems Engineer (Cybersecurity)
8 дней назад
Business Information Security Officer (Cybersecurity)
3 дня назад
Security Assurance Manager
5 дней назад