- Location
- Singapore Singapore (Corporation Road)
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Experience
- 5+ years
- Education
- Bachelor
- Closing date
- Today
- Source
- Workday
Description
Rockwell Automation is a global technology leader focused on helping the world’s manufacturers be more productive, sustainable, and agile. With more than 28,000 employees who make the world better every day, we know we have something special. Behind our customers - amazing companies that help feed the world, provide life-saving medicine on a global scale, and focus on clean water and green mobility - our people are energized problem solvers that take pride in how the work we do changes the world for the better.
We welcome all makers, forward thinkers, and problem solvers who are looking for a place to do their best work. And if that’s you we would love to have you join us!
Job Description
The Staff Firmware Security Engineer provide support, defining, develop and driving cybersecurity architecture, security strategy, and secure development practices across multiple embedded product platforms. This role provides technical leadership for cross-functional teams, influences product and technology roadmaps, mentors engineers, and ensures products comply with cybersecurity standards and regulatory requirements while maintaining high levels of quality and innovation.
Your Responsibilities:
- Lead & develop the architecture, design, and implementation of cybersecurity solutions across multiple embedded and industrial automation product platforms.
- Define product cybersecurity strategies and drive the integration of secure-by-design principles throughout the product development lifecycle.
- Provide technical leadership for embedded security technologies, including:Secure BootSecure Firmware UpdateCryptographic Key and Certification ManagementDevice Identity and AuthenticationSecure CommunicationsVulnerability ManagementProduct HardeningSecurity Monitoring and Logging
- Lead cybersecurity architecture reviews, threat modeling activities, security risk assessments, and mitigation planning.
- Establish technical direction for vulnerability remediation programs and product security improvements across multiple projects and product families.
- Guide compliance with cybersecurity standards and regulatory requirements such as IEC 62443, NIST, ISA/IEC industrial security requirements, and internal secure development lifecycle processes.
- Partner with product security, firmware, systems, hardware, and quality organisations to influence product architectures and long-term technology roadmaps.
- Be a subject matter expert and provide guidance on secure coding, threat mitigation strategies, cryptography, embedded security, and industrial cybersecurity best practices.
- Lead complex investigations of critical security vulnerabilities and field-reported cybersecurity issues, driving resolution across multiple teams.
- Develop enterprise-wide engineering processes, security verification methodologies, development standards, and best practices.
- Mentor firmware engineers and cybersecurity engineers, helping develop organisational cybersecurity capabilities.
- Evaluate latest cybersecurity technologies, industry trends, standards, and threats to influence future product security strategies.
- Lead product security certification efforts and technical engagements with customers, external security researchers, certification bodies, and industry working groups to achieve successful certification outcomes.
- Influence project planning, technology investment decisions, resource prioritisation, and security roadmap execution.
- Be a technical leader within globally distributed development teams and facilitate technical agreement across organisations.
- Ensure adherence to quality systems, secure development processes, information protection policies, intellectual property requirements, and regulatory compliance obligations.
The Essentials - You Will Have:
- Minimum with bachelor's degree in computer science, Computer Engineering, Electrical Engineering, or related field.
- 7+ years of embedded firmware development experience, including minimum 5+ years in firmware security or embedded cybersecurity.
- Demonstrated technical leadership across products or platforms.
- Experience driving cybersecurity initiatives and influencing architecture decisions.
- Expert in C/C++ and real-time embedded systems.
- Expert of:Secure BootCryptography and PKISecure Firmware UpdatesSecure StorageKey and Certification Management SystemsSecurity ProtocolsTCP/IP NetworkingDevice Authentication Frameworks
- Experience with threat modeling, security risk assessments, penetration testing, and vulnerability management.
- Proficiency in Python or similar scripting languages.
- Familiarity with DevSecOps and security automation practices.
The Preferred - You Might Also Have:
- Knowledge of IEC 62443 and industrial cybersecurity standards.
- Security certifications such as CISSP, GICSP, CSSLP, GIAC, or equivalent.
- Experience with industrial control systems and industrial automation products.
- Experience contributing to cybersecurity strategy and governance.
What We Offer:
Our benefits package includes …
- Comprehensive mindfulness programs with a premium membership to Calm
- Volunteer Paid Time off available after 6 months of employment for eligible employees.
- Company volunteer and donation matching program – Your volunteer hours or personal cash donations to an eligible charity can be matched with a charitable donation.
- Employee Assistance Program
- Personalized wellbeing programs through our OnTrack program
- On-demand digital course library for professional development
... and other local benefits!
At Rockwell Automation we are dedicated to building a diverse, inclusive and authentic workplace, so if you're excited about this role but your experience doesn't align perfectly with every qualification in the job description, we encourage you to apply anyway. You may be just the right person for this or other roles.
#LI-Hybrid
#LI-KV1
Rockwell Automation’s hybrid policy aligns that employees are expected to work at a Rockwell location at least Mondays, Tuesdays, and Thursdays unless they have a business obligation out of the office.