施耐德电气
Cyber Security Tester
岗位职责
Review product cybersecurity
任职要求
, customer specifications, and applicable industry standards to ensure compliance with cybersecurity objectives throughout the product lifecycle. · Develop comprehensive cybersecurity test plans, test cases, and validation strategies based on product requirements, security risk assessments, and certification requirements. · Design, set up, and maintain cybersecurity test environments for industrial control systems, protection relays, RTUs, PLCs, gateways, communication devices, and related configuration tools. · Execute cybersecurity testing activities, including: o Understand threat modeling o Vulnerability assessment and scanning o Penetration testing o Fuzz testing o Authentication and authorization testing o RBAC (Role-Based Access Control) verification o Network protocol security testing o Secure communication validation o Device hardening verification o Security robustness and resilience testing Evaluate compliance with cybersecurity standards and certification requirements, including IEC 62443, IEC 62351, and other relevant industrial cybersecurity frameworks. Analyze network traffic, communication protocols, and security events using cybersecurity and packet analysis tools, and identify security risks and vulnerabilities. Record, reproduce, and track defects or vulnerabilities discovered during testing, working closely with R&D teams to support root cause analysis and corrective actions. Produce cybersecurity validation reports, vulnerability assessment reports, and certification evidence packages for internal and external stakeholders. Support third-party cybersecurity certification activities, including laboratory testing, audits, technical reviews, and certification evidence submissions. Collaborate with system architects, developers, validation engineers, and product managers to improve security-by-design practices and overall product robustness. Keep up to date with emerging cybersecurity threats, industrial cybersecurity standards, testing methodologies, and security tools to continuously improve product security and test effectiveness. Job Requirements Education Bachelor's degree or above in Cyber Security, Electrical Engineering, Power Systems, Computer Science, Information Security, or a related discipline. Experience Minimum 5 years of experience in cybersecurity advisor, testing, validation, certification, product security, or related engineering roles. Experience with industrial automation, power systems, protection and control devices, intelligent electronic devices (IEDs), is highly desirable. Experience in industrial product cybersecurity certification or cybersecurity testing is preferred. Experience supporting third-party certification laboratories, security audits, or compliance assessments is a plus. Technical Skills Strong understanding of industrial cybersecurity standards, especially IEC 62443 family standards and CRA requirements. Familiarity with related standards such as IEC 62351 , NERC CIP, Marine E27 or similar cybersecurity frameworks is an advantage. Solid knowledge of TCP/IP networking, OSI model, Ethernet technologies, routing, switching, and industrial communication architectures. Familiar with industrial communication protocols is preferred. such as: IEC 61850/ IEC60870-5-104/ Modbus/ DNP3/ OPC UA/ MQTT Security Testing Tools Hands-on experience with one or more of the following cybersecurity tools: Vulnerability scanners (Nessus, OpenVAS, Qualys, etc.) Penetration testing tools (Kali Linux, Metasploit, Burp Suite, Nmap, etc.) Industrial cybersecurity assessment tools (Achilles Test Platform or equivalent) Protocol and packet analysis tools (Wireshark, tcpdump) Fuzz testing tools Security log analysis and monitoring tools Automation & Scripting Proficiency in Python or other scripting languages for security test development, data analysis, and automation. Personal Attributes Strong analytical and problem-solving skills with a security-oriented mindset. Good communication and documentation skills in English. Ability to work independently and collaboratively within cross-functional international teams. Self-motivated with a passion for continuous learning in cybersecurity and industrial technologies. Preferred Qualifications Professional cybersecurity certifications such as GICSP, CISSP, IEC 62443 Cybersecurity Expert, or equivalent. Experience with cybersecurity certification programs such as IEC 62443 certification, Achilles Certification, or equivalent industrial security schemes.
信息来自企业官方招聘渠道
OfferSeek 对公开岗位信息进行聚合、去重和结构化整理,最终申请以企业官方页面为准。
