Minneapolis, Minnesota
1 day ago
Sr. Product Security Engineer

Be a part of our mission! As a world leader in creating comfortable, sustainable, and efficient climate solutions for buildings, homes and transportation, it's our responsibility to put the planet first. For us at Trane Technologies, and through our businesses including Trane\u00AE\u00A0and\u00A0Thermo King, \u00A0sustainability is not just how we do business\u2014it is our business. \u00A0Do you dare to look at the world's challenges and see impactful possibilities? \u00A0Do you want to contribute to making a better future? \u00A0If the answer is yes, we invite you to consider joining us in boldly challenging what's possible for a sustainable world.

Learn about our benefits designed for you to Thrive at work and at home.\u00A0

We boldly go.

Where is the work:

Monday to Thursday, work onsite with your colleagues. Fridays, choose your work location, balancing what your work requires.

\u00A0

\u00A0

What\u2019s in it for you:

Thermo King is hiring an experienced\u00A0Senior Product Security Engineer to work on the creation and implementation of secure embedded software by demonstrating a comprehensive understanding of secure by design principles to support the next-generation transport refrigeration and mobile HVAC controls platform while meeting vehicle cybersecurity and software-update regulatory type-approval requirements.

\u00A0

In this role, you will lead the cross-product efforts to regularly assess threats and vulnerabilities, perform Security DFMEA, and review penetration tests & threat modeling reports on products throughout its lifecycle. You will use the findings from new threats to improve processes and productivity by providing guidance and implementing priority updates based on findings. Your tasks include developing and capturing requirements, coordinating implementation, and helping the team to deliver product security goals. You will work closely with Systems, Hardware, Software, and teams to understand customer needs, align product security with overall practices, and define effective product security solutions and oversee their development.

\u00A0

What you will do:

Risk Management:\u00A0Assess product security risks in a maintained register, develop comprehensive mitigation strategies, and evaluate technical and business trade-offs.Lead Security Activities:\u00A0Apply the Secure Development Lifecycle and lead product security processes including architectural analysis, threat modeling, security DFMEA, penetration testing, attack modeling and simulation, cybersecurity type-approval activities including TARA per ISO/SAE 21434, and data privacy impact assessments.Vulnerability Management:\u00A0Identify, evaluate, and verify security issues discovered through automated testing, penetration testing, and customer feedback. Maintain and track closure of vulnerability backlogs.Compliance & Standards:\u00A0Interpret and enforce product security requirements, conduct vulnerability reviews, and ensure compliance with automotive and industrial cybersecurity regulations and standards (UNECE R155, UNECE R156, ISO/SAE 21434, ISO 24089, GB 44495-2024, IEC 62443, NIST, and applicable regional data-privacy laws).Regulatory Type Approval & Management Systems:\u00A0Support vehicle cybersecurity and software-update type approval by maintaining Cyber Security Management System (CSMS) and Software Update Management System (SUMS) processes and evidence aligned to regulations and standards.Secure Updates & Cryptographic Assurance:\u00A0Define and validate secure over-the-air and service-tool update paths, covering secure boot, hardware root of trust, PKI and certificate management, code signing, and anti-rollback protection across the zonal architecture and independent modules.Data Privacy Compliance:\u00A0Apply privacy-by-design and support data-protection impact assessments to meet regional obligations such as GDPR, CCPA, LGPD, the EU Data Act, and California SB-327.Security Tools Oversight:\u00A0Monitor outputs and effectiveness from all security tools integrated within the software development lifecycle.Technical Guidance:\u00A0Advise, guide, and mentor cross-disciplinary engineering teams during the design, review, and implementation of security features.Assurance:\u00A0Validate that software meets all functional, security, regulatory (cybersecurity compliance), and quality benchmarks particularly within industrial and transportation environments.Multi-region travel up to 5% may be required.

\u00A0

What you will bring:

Bachelor's or Master's degree in computer engineering, computer science, electrical engineering or related technical field with 5+ years of experience.Preferred that the candidate have experience as an embedded product security engineer.Experience with automotive or vehicle cybersecurity and regulatory type approval (ISO/SAE 21434, UNECE R155/R156) and secure over-the-air software updates is strongly preferred.Experience with embedded software development and proficiency in relevant programming languages (e.g., C, C++, C#, Rust, Python).Embedded Systems Experience:\u00A0Demonstrated expertise in securing embedded controls platforms, with hands-on knowledge of Embedded Linux (e.g., Yocto) and RTOS environments (e.g., FreeRTOS, Zephyr Project, MicroC/OS-II).Connectivity Protocols:\u00A0Preferred background securing in-vehicle and telematics networks\u2014CAN J1939/CAN FD with SecOC, Automotive Ethernet/SPE (100Base-T1, 10Base-T1S) with MACsec and TLS 1.3, and MQTT with mutual TLS.Cryptography & Secure Boot:\u00A0Working knowledge of secure boot, hardware root of trust and secure elements, PKI, code signing, and key management for embedded systems.Automotive Cybersecurity Standards:\u00A0Familiarity with ISO/SAE 21434 TARA, UNECE R155 and R156, ISO 24089, and/or GB 44495-2024 type-approval expectations.Security Analysis:\u00A0Strong grasp of static analysis (SAST) and software composition analysis techniques for vulnerability detection and remediation.DevOps & Automation:\u00A0Familiarity with modern DevOps pipelines and tools (e.g., GitHub Actions, Azure DevOps, GIT), with practical knowledge of automated testing frameworks (e.g., CppUTest, Pluma).Communication & Collaboration:\u00A0Effective communicator with strong organizational skills, adept at working with cross-functional teams and presenting technical risks to varied audiences.Continuous Improvement:\u00A0Commitment to ongoing learning and driving continuous maturity in product security processes and technical strategies.

Annual Base Salary Range or Hourly Base Pay Range:

$105,228.33 - $168,700.00

Compensation Type:

Salary

Incentive Eligible:

No

Sales Commission Eligible:

No

Disclaimer: We strive to provide competitive compensation for this position, tailored to a variety of factors. The actual compensation will depend on elements such as seniority, merit, geographic location, education, experience, \u00A0travel requirements, and union designation. \u00A0 Our compensation range is generally based on the national average for the country. \u00A0Additionally, benefits may vary depending on the region, business alignment, union involvement, and employee status.

Thrive at work and at home:


Benefits kick in on DAY ONE for you and your family, including health insurance and holistic wellness programs that include generous incentives \u2013 WE DARE TO CARE!Family building benefits include fertility coverage and adoption/surrogacy assistance.Paid time off includes\u00A0 up to 15 vacation days, paid holidays, sick leave, and additional options to support volunteer and parental leave.\u00A0401K match up, educational and training opportunities through company programs along with tuition assistance and student debt support.\u00A0\u00A0\u00A0\u00A0

Disclaimer:\u00A0 Benefit offerings may vary by site as well as Collective Bargaining Agreements and local/state regulations


Safety Sensitive Role:

No

The company designates certain roles as Safety Sensitive. Safety Sensitive roles may require that you pass additional drug screening.

We offer competitive compensation and comprehensive benefits and programs. We are an equal opportunity employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, pregnancy, age, marital status, disability, status as a protected veteran, or any legally protected status.

Confirmar seu email: Enviar Email