- Company Name
- Integration International Inc.
- Job Title
- Cyber Security Engineer
- Job Description
-
**Job title**
Cyber Security Engineer
**Role Summary**
Advises on cybersecurity and data protection for product certification, ensuring compliance with IEC 62443, cloud, API, and privacy‑by‑design standards. Drives Secure Development Lifecycle (SDL v2) activities, performs risk assessments, threat modeling, and penetration test reviews, and acts as the internal SME for secure design and incident response. Works in an R&D environment, collaborating with cross‑functional teams on secure architecture and compliance documentation.
**Expactations**
- Deliver expert cybersecurity guidance aligned with IEC 62443 and industry best practices.
- Lead and coordinate security and privacy engagements throughout the product lifecycle.
- Produce and maintain artifacts for risk assessments, threat models, and SDL compliance.
- Communicate findings and recommendations to technical and non‑technical stakeholders.
- Independently manage multiple projects, ensuring timely completion and adherence to security standards.
**Key Responsibilities**
- Lead cybersecurity and privacy engagements during product certification.
- Define and implement IT/OT security and data protection requirements.
- Conduct risk assessments, threat modeling, and penetration test reviews.
- Drive SDL v2 activities, including vendor assessments and pre‑penetration testing.
- Deploy and manage SAST/DAST tools; generate SDL artifacts.
- Serve as cybersecurity SME; advise on secure design and implementation.
- Ensure compliance with risk‑based security practices and standards.
- Collaborate on secure architecture requirements with cross‑functional teams.
- Support incident response planning and validation activities.
- Maintain documentation for controls, processes, and compliance.
- Communicate with stakeholders to reinforce a strong security posture.
**Required Skills**
- IEC 62443 knowledge and experience.
- Cloud security, API security, and Privacy‑by‑Design principles.
- Penetration test reviews, threat modeling, and risk assessment.
- SDL v2 processes and tooling (SAST/DAST).
- Secure development practices for web, mobile, cloud, and API environments.
- Strong vulnerability management and reporting.
- Secure API, IoT, and connected device architecture design.
- Cryptography, authentication, authorization, PKI, and AI security fundamentals.
- Familiarity with DevSecOps, OWASP, threat modeling methodologies.
- Hands‑on with Coverity, SonarQube, Black Duck, Microsoft Threat Modeling Tool, jFrog, Jira, Confluence.
- Excellent communication and stakeholder management.
- Ability to work independently and multi‑task.
- Fluency in English (Spanish/French a plus).
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Minimum 3 years in cybersecurity roles, preferably in an R&D environment.
- ISA‑IEC 62443 Cybersecurity Expert certification (required).
- CSSLP, CISSP, or other relevant certifications (preferred).
Massachusetts, United states
Hybrid
Junior
20-11-2025