Product Cybersecurity Engineer

3 days ago


Belfast ANT, United Kingdom Johnson Controls Full time

What you will do


Ensure all your application information is up to date and in order before applying for this opportunity.
  • Liaising with the Hardware/Firmware and Software engineering teams to schedule code reviews/scans as per guidelines outlined by JCI cyber Security Board.

  • Working with Senior Cyber architect to run and discuss results of scans, assess where the risks lie, how best to mitigate

  • Working with the development team to address cyber risks

  • Being the gatekeeper and working with the development team and our customers ensuring that all products and solutions released to the market adhere to the latest security standards.

How you will do it

You will work across multiple parallel project releases and work items and will have a strong desire to actively champion product cybersecurity best practices. The ideal candidate will take ownership of issues and work on own initiative, driving work items to successful completion. You will have good time-management and organizational skills and be a continual learner, aware of the ever-changing nature of cybersecurity and keen to stay on top of the latest developments.

What we look for

  • Ability to work in the Belfast office three days per week

  • Authorisation to work in Ireland

  • Basic familiarity with, and keen interest in, formal cybersecurity controls and best practices. E.g., OWASP Top 10, NIST 800-53.

  • Ability to liaise and negotiate amongst multiple product stakeholders, including:

    • Engineering management, architects, and lead engineers

    • Product Security Incident Response Team (PSIRT)

    • Global Cybersecurity architects

    • Product Management

    • Supplier Assessment Team

    • Site Reliability Engineering (SRE)

    • Legal (Software Copyright / Licensing Compliance, Trade Compliance)

    • Individual software and hardware engineers

  • Previous development experience, including familiarity with authentication, authorization, and SDKs and local and remote APIs.

  • Basic networking experience and understanding

  • Understanding of, including ability to reason about and explain common cybersecurity vulnerabilities. E.g., can (to some extent) compare and contrast SOME of:

    • Authentication vs. authorization

    • Vulnerability vs. weakness

    • Hashes vs. ciphers

    • SQL injection vs. OS injection

    • RNG vs. PRNG vs. cryptographic RNG

    • High entropy passwords vs. low entropy

    • HSM vs. TEE

    • TLS v3 vs. SSL v3

    • Stack overflow, buffer overflow, and integer overflow / wraparound.

    • Certificate vs. key

    • Signature vs. hash

Desirable:

  • Basic understanding of software release pipelines: e.g., VCS, branching/tagging, GitOps, software signing, versioning, CI/CD.

  • Cybersecurity qualifications, such as Security+, CCSP, CISSP, CEH, etc.

  • Familiarity with Common Vulnerability Enumerations (CVE’s), Common Weakness Enumerations (CWE’s).

  • Familiarity with multiple operating systems, including Windows and Linux

  • Degree (or equivalent experience) in a STEM subject, particularly cybersecurity, computer science, software engineering, or electronic engineering.

  • Basic understanding of software architecture diagrams, attack vectors, and threat modelling, including an ability to create threat models and reason about attack vectors involving multiple vulnerabilities.

  • Basic understanding of asymmetric vs. symmetric cryptography

  • A skilled communicator, able to liaise with multiple levels of engineering and management staff

  • A reasonable degree of previous project / ticket management experience. E.g., SCRUM management, sprint reviews, etc.

#LI-Hybrid

#GOSIA



  • Belfast, United Kingdom CV-Library Full time

    What you will do Liaising with the Hardware/Firmware and Software engineering teams to schedule code reviews/scans as per guidelines outlined by JCI cyber Security Board. Working with Senior Cyber architect to run and discuss results of scans, assess where the risks lie, how best to mitigate Working with the development team to address cyber risks Being...


  • Belfast, United Kingdom Johnson Controls Full time

    What you will do Liaising with the Hardware/Firmware and Software engineering teams to schedule code reviews/scans as per guidelines outlined by JCI cyber Security Board.Working with Senior Cyber architect to run and discuss results of scans, assess where the risks lie, how best to mitigate Working with the development team to address cyber risks Being the...


  • Belfast, United Kingdom Johnson Controls Full time

    What you will do Ensure all your application information is up to date and in order before applying for this opportunity.Liaising with the Hardware/Firmware and Software engineering teams to schedule code reviews/scans as per guidelines outlined by JCI cyber Security Board.Working with Senior Cyber architect to run and discuss results of scans, assess where...


  • Belfast, United Kingdom Johnson Controls Full time

    What you will do Liaising with the Hardware/Firmware and Software engineering teams to schedule code reviews/scans as per guidelines outlined by JCI cyber Security Board. Working with Senior Cyber architect to run and discuss results of scans, assess where the risks lie, how best to mitigate Working with the development team to address cyber risks...


  • Belfast, United Kingdom Johnson Controls Full time

    What you will doLiaising with the Hardware/Firmware and Software engineering teams to schedule code reviews/scans as per guidelines outlined by JCI cyber Security Board.Working with Senior Cyber architect to run and discuss results of scans, assess where the risks lie, how best to mitigateWorking with the development team to address cyber risksBeing the...


  • Belfast, United Kingdom Johnson Controls Full time

    What you will doLiaising with the Hardware/Firmware and Software engineering teams to schedule code reviews/scans as per guidelines outlined by JCI cyber Security Board.Working with Senior Cyber architect to run and discuss results of scans, assess where the risks lie, how best to mitigateWorking with the development team to address cyber risksBeing the...


  • Belfast, United Kingdom Johnson Controls Full time

    About the RoleWe are seeking a highly skilled Product Cybersecurity Engineer to join our team at Johnson Controls. As a key member of our cybersecurity team, you will play a critical role in ensuring the security and integrity of our products and solutions.ResponsibilitiesLiaise with cross-functional teams to schedule code reviews and scans according to...


  • Belfast, United Kingdom MCS Group Full time

    MCS Group is a leading recruitment agency in Northern Ireland, collaborating with startups and established companies to find the best talent. We are currently working with a new startup that is set to dominate the Cybersecurity scene, and we are seeking a Product Owner to join their close-knit team during this exciting time of expansion.The RoleIn this role,...


  • Belfast, United Kingdom Rapid7 Full time

    Rapid7 is revolutionizing the cybersecurity landscape by leveraging artificial intelligence (AI) to accelerate threat investigation, detection, and response capabilities. Our Belfast office is at the forefront of this innovation, with the formation of our AI Centre of Excellence, encompassing the full range of AI, ML, and data science.We're seeking an...


  • Belfast, United Kingdom Rapid7 Full time

    About the RoleAn Artificial Intelligence (AI) Engineer II at Rapid7 designs and implements systems to support and accelerate AI research, model development, and feature integration in our product portfolio. You will build these systems in the cloud using standard MLOps and DevOps tools, working closely with other members of the Centre of Excellence (CoE) to...


  • Belfast, United Kingdom Johnson Controls, Inc. Full time

    Job OverviewWe are seeking a skilled Cybersecurity Assurance Specialist to join our team at Johnson Controls, Inc. This role is responsible for ensuring the security of our products and solutions in the market.About YouYou will have a strong background in cybersecurity with a focus on formal controls and best practices.Able to liaise and negotiate amongst...


  • Belfast, United Kingdom Divvy Cloud Corp. Full time

    About the RoleAs a highly skilled AI Engineer II in MLOps, you will design and implement systems to support and enable AI research, accelerating and augmenting AI model development. You will build these systems in the cloud, using standard MLOps and DevOps tools, and collaborate with the AI Centre of Excellence team to build custom infrastructure where...


  • Belfast, United Kingdom Divvy Cloud Corp. Full time

    Annual Salary Range: $150,000 - $170,000About Divvy Cloud Corp.Divvy Cloud Corp. is a leading provider of cybersecurity solutions, dedicated to protecting our customers from cyber threats. Our mission is to create a safer digital world, and we believe that it's our responsibility to show up every day and give our best for our customers and the entire...


  • Belfast, ANT, United Kingdom Johnson Controls Full time

    Who we areIs this the next step in your career Find out if you are the right candidate by reading through the complete overview below.At Johnson Controls, we’re shaping the future to create a world that’s safe, comfortable, and sustainable. Our global team creates innovative, integrated solutions making the people, facilities, and assets safe with our...


  • Belfast, United Kingdom Rapid7 Full time

    About the Role As a seasoned AI/ML professional, you will play a pivotal role in designing and implementing cutting-edge AI models that drive innovation in our cybersecurity solutions. Your expertise will be instrumental in tackling complex challenges and delivering customer value through model development.Responsibilities You will research and develop...


  • Belfast, United Kingdom Rapid7 Full time

    Rapid7, a leader in cybersecurity, is making significant investments in its Belfast office with the establishment of an AI Centre of Excellence. This centre encompasses the full range of AI, ML, and data science, aiming to accelerate threat investigation, detection, and response capabilities of the Security Operations Centre (SOC).The company is seeking...


  • Belfast, United Kingdom Agio, Inc. Full time

    Cybersecurity Operations Analyst Role at Agio, Inc.Agio, Inc. is a leading provider of hybrid managed IT and cybersecurity solutions. As a Cybersecurity Operations Analyst, you will play a critical role in protecting our clients' data and infrastructure from cyber threats.Key ResponsibilitiesImplement measures to prevent breaches and protect the integrity...


  • Belfast, United Kingdom Divvy Cloud Corp. Full time

    About the RoleOur company is looking for a talented Software Engineer II in Test to join our growing Quality Engineering team. This role is at the forefront of ensuring the quality of our products and a shift left testing philosophy.We need a team player with a strong QA background in both manual and automated testing to ensure high quality delivery of...


  • Belfast, ANT, United Kingdom Johnson Controls Full time

    Job DescriptionReady to make your application Please do read through the description at least once before clicking on Apply.Johnson Controls is a global diversified technology and multi-industrial leader serving a wide range of customers in more than 150 countries. We create intelligent buildings, efficient energy solutions, integrated infrastructure and...


  • Belfast, United Kingdom VanRath Full time

    Estimate salary: £35,000 - £45,000 per annumAbout the roleWe are seeking a skilled Cybersecurity Threat Hunter to join our team at VanRath. As a key member of our cybersecurity unit, you will be responsible for identifying and mitigating potential threats to our systems and data.Key Responsibilities:Incident Analysis: Conduct thorough analysis of incidents...