CybersecurityJobs.io
← Back to all jobs

Job Description

Emerson is seeking a Senior Product Security Engineer to provide product security leadership across industrial sensing, connectivity, software, and cloud programs. The role focuses on owning product security for a portfolio of industrial automation and cloud solutions while embedding security throughout the product lifecycle to help meet EU Cyber Resilience Act and IEC 62443 requirements.

This onsite position is located in Shakopee, MN. The salary range is USD 115,000 - 140,000 per year, and candidates should have 5+ years of relevant experience.

What you will do

  • Act as the Product Security Lead for assigned industrial automation products, connectivity platforms, software applications, and cloud solutions.
  • Drive secure development lifecycle (SDL) activities, ensuring product security requirements are defined, implemented, and verified through development.
  • Partner with hardware, firmware, software, and cloud engineering teams to design secure architectures and apply cybersecurity best practices.
  • Lead cybersecurity risk assessments, threat modeling, and product security planning to identify and mitigate security risks.
  • Support security testing activities, including vulnerability assessments, penetration testing, code analysis, and remediation efforts.
  • Manage product security vulnerabilities and coordinate cross-functionally to investigate, prioritize, and resolve cybersecurity issues.
  • Support compliance with industry cybersecurity standards, regulations, certifications, and customer security requirements.
  • Provide technical guidance, training, and mentorship to engineering teams while building a strong product cybersecurity culture.
  • Monitor emerging cybersecurity threats, technologies, and industry trends to continuously improve product security practices.

Required qualifications

  • Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, Cybersecurity, or a related field.
  • 5+ years of experience in software, firmware, systems engineering, or cybersecurity, including experience supporting product or embedded/IoT security.
  • Knowledge of SDL practices, threat modeling, security risk assessments, vulnerability management, and secure design principles.
  • Familiarity with cybersecurity frameworks and standards including CWE, CVE, CVSS, and OWASP.
  • Experience programming in languages such as C, C++, Java, or Python.
  • Working knowledge of Linux, networking fundamentals, and cybersecurity best practices.
  • Strong communication and collaboration skills, with the ability to work across global, cross-functional teams.
  • Legal authorization to work in the United States.

Work authorization note: Emerson will only employ candidates legally authorized to work in the United States, and this role is not eligible for sponsorship. Individuals with temporary visas (including E, F-1 including OPT or CPT, H-1, H-2, L-1, B, J, or TN) or who would require sponsorship for future authorization are not eligible.

Technologies

  • C, C++, Java, Python
  • Linux
  • CWE, CVE, CVSS, OWASP
  • IEC 62443, EU Cyber Resilience Act
  • SDL (secure development lifecycle)

Benefits

  • Medical insurance plans (variety of medical insurance plans)
  • Dental and vision coverage
  • Employee Assistance Program
  • Profit sharing retirement
  • Tuition reimbursement
  • Employee resource groups
  • Recognition
  • Flexible time off plans, including paid parental leave (maternal and paternal), vacation and holiday leave
  • Competitive base salary
  • Reward performance during annual merit review process

Preferred qualifications that set you apart

  • Experience securing industrial automation, industrial IoT, or operational technology (OT) products and protocols.
  • Knowledge of industry cybersecurity standards and regulations, including IEC 62443, NIST SSDF, and the EU Cyber Resilience Act.
  • Experience with cloud and container security technologies such as Azure, AWS, Docker, or Kubernetes.
  • Experience with penetration testing, fuzzing, vulnerability assessment, and code analysis tools.
  • Familiarity with SBOM standards, software supply chain security, and software composition analysis.
  • Industry certifications such as CISSP, CSSLP, GICSP, OSCP, or ISA/IEC 62443 Cybersecurity Expert.
  • Experience mentoring engineers and providing technical leadership on cybersecurity initiatives.

Similar Jobs