Principal Product Cybersecurity Assurance Engineer
Job Description
Humanoid builds highly regulated electromechanical and AI-enabled robotic systems, and this role helps ensure the product cybersecurity assurance story holds from concept through post-market deployment. In this onsite Principal Product Cybersecurity Assurance Engineer position in Cambridge, MA, you will lead security engineering delivery across the HMND 01 platform family (Alpha Wheeled and Alpha Bipedal), shape the assurance strategy, and support documentation, incident response readiness, compliance, and certification evidence.
What you’ll do
- Lead and develop a cross-functional team of security engineers, staying accountable for delivery of product security services across product teams throughout the HMND 01 lifecycle.
- Define product cybersecurity requirements and advise development teams on appropriate standards, techniques, and toolchains for embedded and AI-enabled robotic systems.
- Partner with cross-functional stakeholders to establish security protocols, tools, and processes to stay ahead of emerging threats, including attack surfaces tied to the KinetIQ AI inference pipeline and the cloud-to-robot communication architecture.
- Own and maintain audit-ready security artefacts, including Security Management Plans, TARA reports, Risk Assessments, and Remediation Action Plans across both HMND 01 platforms.
- Drive security assurance through the full product lifecycle so HMND 01 designs are robust, compliant, and resilient.
- Improve organisational security engineering capability through continual enhancement of processes and engineering practices.
- Ensure compliance with cybersecurity obligations under EU Machinery Regulation 2023/1230 and the EU Cyber Resilience Act, where cyber controls intersect with safety-critical functions, including alignment with IEC 62443 for industrial/OT product security.
- Deliver independent Information Assurance (IA) reviews and risk assessments on complex, high-impact projects, with emphasis on cyber-physical systems where compromise could cause physical harm.
- Review and guide security risk assessments, risk mitigation plans, mitigation gap analysis, and security management documentation to support system cybersecurity certification.
- Establish and maintain a Product Security Incident Response (PSIR) process, including coordinated vulnerability disclosure, patch deployment pipelines, and post-field incident analysis.
- Define and oversee security monitoring requirements for deployed fleets so field data feeds back into risk files and security artefacts in line with post-market surveillance obligations.
- Support product bid work packages by contributing product security scope descriptions and cost estimates for bids, services, and proposals.
- Represent Humanoid’s security posture in customer and partner engagements, including regulatory consultations and certification body interactions.
Requirements
- Proven hands-on experience with ISO 27001/27004/27005 and the NIST Risk Management Framework (RMF), applied to regulated hardware or embedded product programmes.
- Experience owning a security risk management system for highly regulated, safety-critical products, with background from automotive, commercial vehicle, or industrial automation environments.
- Working knowledge of IEC 62443, with the ability to adapt ISO/SAE 21434 lifecycle methodologies to a robotic or electromechanical context.
- Solid understanding of engineering development lifecycles and how product cybersecurity connects with systems engineering, functional safety, and hardware/software co-development.
- Ability to interpret penetration test reports and author Remediation Action Plans that address vulnerabilities in a structured, risk-prioritised manner.
- Clear, structured communication skills to explain complex security risk arguments to technical engineers and executive stakeholders.
Preferred
- Familiarity with TARA or equivalent threat modelling methodologies such as STRIDE and PASTA, applied to embedded or OT/IT convergent systems.
- Understanding of secure-by-design principles for AI/ML-enabled systems, including securing inference pipelines, model integrity, and cloud-to-edge communication paths.
- Exposure to security considerations for CAN bus, Ethernet backbone, or wireless interfaces in mobile, vehicular, or robotic systems.
- Experience contributing to or establishing a PSIRT process or coordinated vulnerability disclosure programme.
- Knowledge of UL 4600, UL 3300, or ISO 13482, including how cybersecurity evidence integrates into safety case arguments.
- Prior engagement with certification bodies such as TUV, UL, and BSI, or standards development organisations including ISO TC 184, IEC TC 65, SAE, and IEEE RAS.
Tools and technologies you’ll work with
- KinetIQ VLM/VLA-based AI framework
- KinetIQ AI inference pipeline
- Cloud-to-robot communication architecture
- IEC 62443, ISO 27001, ISO 27004, ISO 27005
- NIST Risk Management Framework (RMF), ISO/SAE 21434
- EU Machinery Regulation 2023/1230, EU Cyber Resilience Act
- TARA, STRIDE, PASTA
- CAN bus, Ethernet backbone, wireless interfaces
- UL 4600, UL 3300, ISO 13482
Benefits
- Comprehensive health coverage for US-based employees, including fully paid medical, dental, and vision insurance, plus virtual care and employee assistance resources.
- 23 days of PTO (accrued), separate sick leave, and paid company holidays.
- 401(k) retirement plan with 4% employer match.
- Competitive equity with stock options and meaningful upside as the company scales.
- Free daily catered lunch, snacks, and drinks in-office.
- Collaboration with top-tier engineers, researchers, and product experts in AI and robotics.
- Freedom to influence the product and own key initiatives.