Rockwell Automation Logo

Rockwell Automation

Senior Product Security Engineer

Reposted 2 Days Ago
Be an Early Applicant
In-Office or Remote
3 Locations
136K-204K Annually
Senior level
In-Office or Remote
3 Locations
136K-204K Annually
Senior level
The Senior Product Security Engineer will drive software security efforts, mentor development teams, conduct security assessments, and ensure adherence to secure development processes.
The summary above was generated by AI

Rockwell Automation is a global technology leader focused on helping the world’s manufacturers be more productive, sustainable, and agile. With more than 28,000 employees who make the world better every day, we know we have something special. Behind our customers - amazing companies that help feed the world, provide life-saving medicine on a global scale, and focus on clean water and green mobility - our people are energized problem solvers that take pride in how the work we do changes the world for the better.

We welcome all makers, forward thinkers, and problem solvers who are looking for a place to do their best work. And if that’s you we would love to have you join us!

Job Description

The Senior Product Security Engineer will drive software application security efforts across Verve's product development team. This will involve working closely with Verve's senior software engineering leadership, direct interaction with Verve's development teams, and serving as the primary interface with the broader security and compliance processes and teams within Verve's parent company, Rockwell Automation. You will report to the Team Lead, Staff Software Engineer and will be remote working anywhere in the United States.

Your Responsibilities:
  • Develop a deep expertise in Rockwell's established secure development processes. This position will be the primary interface between Verve's development organization and Rockwell's secure development assurance processes.
    • Drive timely and effective resolution of vulnerability reports in support of Rockwell's Product Security Incident Response Team (PSIRT).
    • Coordinate incident management and other reported security issues.
    • Drive risk reviews and risk analysis to identify systematic issues.
  • Evangelize and mentor secure software development practices within Verve's software product development teams.
    • Provide architecture and best practice guidance related to secure software development to product teams. Assist teams in process evolution required to achieve and maintain IEC 62443 certification.
    • Maintain current knowledge of security threats and vulnerabilities that could impact products.
    • Ensure adherence to security standards and provide guidance and input to standards enhancements.
  • Collaborate throughout the development lifecycle to verify and improve software security.
    • Perform threat modeling, security requirements review, secure code review and vulnerability assessments.
    • Lead and participate in security architecture and design review meetings. Review product architectures for security design gaps and vulnerabilities and consult with product teams to remediate or mitigate cyber risk.
    • Lead efforts with the development teams to quantify residual product risk and identification of appropriate security controls.
  • Contribute as appropriate to the continued development of the Verve software platform.
The Essentials - You Will Have:
  • Bachelors degree
  • Legal authorization to work in the U.S. We will not sponsor individuals for employment visas, now or in the future, for this job opening.
The Preferred - You Might Also Have:
  • 5+ years professional experience, with at least 3 years of experience, ideally involving web applications.
  • A BS in Computer Science or a similar field or equivalent experience.
  • Solid understanding of TCP/IP networking.
  • Strong foundational understanding of web application security, linux/unix system security, network security, applied cryptography, and OS-level hardening, with advanced knowledge in at least a few of these areas.
  • Experience working with development teams to review designs, construct threat models, and develop/maintain secure coding standards.
  • At least a basic understanding of object-oriented design and programming.
  • Familiarity with CVE, CPE, and CVSS.
  • Experience with Python, C#/.NET, and Angular.
  • A familiarity with OT devices and environments.
  • Experience with CI/CD environments.
  • Familiarity with containerization concepts.
  • Experience with various security assessment tools (SCA, SAST, DAST, and vulnerability scanners).
  • Industrial cybersecurity and/or information technology certifications such as (ISC)2 CISSP, or CSSLP, SANS GICSP.
What We Offer:
  • Health Insurance including Medical, Dental and Vision
  • 401k
  • Paid Time off
  • Parental and Caregiver Leave
  • Flexible Work Schedule where you will work with your manager to enjoy a work schedule that can be flexible with your personal life.
  • To learn more about our benefits package, please visit at www.raquickfind.com.

At Rockwell Automation we are dedicated to building a diverse, inclusive and authentic workplace, so if you're excited about this role but your experience doesn't align perfectly with every qualification in the job description, we encourage you to apply anyway. You may be just the right person for this or other roles.

For this role, the Base Salary Compensation is from $135,920.00 - 203,880.00 USD Annual with an annual target bonus of 5% of base salary. Our benefits for the US can be found here. Actual pay will be based on factors such as skills, knowledge, education, and experience.

This position is part of a job family. Experience will be the determining factor for position level and compensation.

#LI-Remote

#LI-AC1

We are an Equal Opportunity Employer including disability and veterans. 

If you are an individual with a disability and you need assistance or a reasonable accommodation during the application process, please contact our services team at +1 (844) 404-7247.

Top Skills

Angular
Applied Cryptography
C#/.Net
Linux/Unix
Network Security
Python
Tcp/Ip
Web Application Security

Similar Jobs

3 Days Ago
Remote or Hybrid
USA
140K-215K Annually
Senior level
140K-215K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
The role involves enhancing product security by identifying and fixing vulnerabilities in endpoint applications, collaborating with product teams, and improving security practices through threat modeling and testing.
Top Skills: CC++GoLinuxmacOSWindows
13 Days Ago
Easy Apply
Remote
United States
Easy Apply
135K-175K Annually
Senior level
135K-175K Annually
Senior level
Software
As a Senior Product Security Engineer, you will ensure product security, manage vulnerabilities, conduct security reviews, and provide guidance to development teams.
Top Skills: Application Security ToolingDynamic AnalysisGoJavaScriptSecurity LibrariesStatic Analysis
3 Hours Ago
Remote
United States
150K-180K Annually
Senior level
150K-180K Annually
Senior level
Software
Design and implement scalable SaaS applications using modern web frameworks, collaborate with teams, mentor engineers, and drive technology initiatives.
Top Skills: AWSGoogle Cloud PlatformMySQLNextjsNode.jsPostgresRuby on RailsReactSQL

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account