Назад
Company hidden
обновлено 9 дней назад

Cybersecurity Governance & Assurance Specialist (Automotive)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle/senior
Английский
b2
Страна
UK
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Cybersecurity Governance & Assurance Specialist (Automotive): Managing product cybersecurity governance and compliance frameworks for off-highway machinery with an accent on ISO/SAE 21434, ISO 24882, and Cyber Resilience Act (CRA) standards. Focus on executing compliance assessments, coordinating testing activities, and establishing post-production vulnerability management workflows.

Location: London, United Kingdom

Company

hirify.global is an independent technology consulting firm providing engineering, digital, telecom, and life sciences solutions to business clients worldwide.

What you will do

  • Own and maintain the product cybersecurity governance and assurance framework for off-highway machinery programmes.
  • Develop standards, templates, checklists, guidance, and training for consistent cybersecurity execution.
  • Plan and conduct compliance assessments of product programmes and suppliers, reporting risks and evidence gaps.
  • Review TARA outputs, cybersecurity requirements, architecture evidence, testing strategies, and residual risk statements.
  • Define cybersecurity testing expectations and coordinate Red Team activities, remediation, and assurance evidence.
  • Establish post-production vulnerability governance, support Cyber Resilience Act Article 14 reporting, and feed lessons learned into standards and training.

Requirements

  • At least 3 years of cybersecurity experience in a Tier 1 or OEM environment, preferably in on-highway or off-highway sectors.
  • Experience in product cybersecurity assurance, governance, compliance assessment, or cybersecurity audit for embedded or cyber-physical products.
  • Strong working knowledge of ISO/SAE 21434 and ISO 24882, plus working knowledge of IEC 62443 and supplier assurance.
  • Familiarity with Cyber Resilience Act compliance, including Article 14 reporting workflows.
  • Excellent technical writing, communication, stakeholder management, analytical, and pragmatic problem-solving skills.
  • Professional English is required for the role.

Nice to have

  • Experience with TARA, threat modelling, attack trees, vulnerability management, and post-production monitoring.
  • Experience in cybersecurity requirements engineering and cybersecurity testing evidence.
  • Knowledge of functional safety interfaces, ECUs, CAN, J1939, UDS diagnostics, and SBOM concepts.

Culture & Benefits

  • International community representing more than 110 nationalities.
  • Internal Academy with more than 250 training modules.
  • Trust-focused environment with opportunities for internal career progression.
  • Regular internal events, including afterworks and team-building activities.

Hiring process

  • Brief virtual or phone call.
  • Approximately three interviews, depending on seniority.
  • Possible case study, technical assessment, role play, or problem-solving exercise.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →