- Location
- Poland Katowice (Francuska 46)
- Workplace
- Hybrid
- Type
- Full-time
- Experience
- 1+ years
- Education
- Master
- Source
- Workday
Description
Rockwell Automation is a global technology leader focused on helping the world’s manufacturers be more productive, sustainable, and agile. With more than 28,000 employees who make the world better every day, we know we have something special. Behind our customers - amazing companies that help feed the world, provide life-saving medicine on a global scale, and focus on clean water and green mobility - our people are energized problem solvers that take pride in how the work we do changes the world for the better.
We welcome all makers, forward thinkers, and problem solvers who are looking for a place to do their best work. And if that’s you we would love to have you join us!
Job Description
Rockwell Automation is looking for a Product Security Test Engineer - Ethical Hacker to join our engineering team.
The Safety, Sensing, and Industrial Components Business is a fast-growing part of Rockwell Automation that develops sensors, safety devices, power and motor control components, and software for industrial control applications. The most common markets for these products include factory automation applications such as pumps, conveyors, packaging machinery, and automated assembly.
As a Product Security Test Engineer, you will help design and complete security assessments of industrial control system (ICS) products, embedded devices, industrial software, and communication protocols. You will combine hands-on security feature testing, penetration testing, fuzz testing, and test automation to identify vulnerabilities and improve the security posture of Rockwell Automation products. You will collaborate with product development teams to integrate security throughout the product lifecycle while contributing to a comprehensive security verification and validation program.
You will report to the Manager located in USA and have a hybrid schedule working in Katowice, Poland.
Your Responsibilities:
- Based on product and industry standards, create security test plans, test cases, and test specifications that are traceable to product security requirements.
- Design procure security test tools, equipment, platforms, and environments needed to support security tests. Contribute to overall test architecture and tool development for security test automation.
- Develop schedules and estimate effort to support security tests.
- Perform security and penetration tests on sensors, safety devices, industrial components, and communication interfaces.
- Perform security tests on firmware, protocols, Windows-based industrial software, embedded web interfaces, and wireless technologies.
- Document test steps and reproducibility details for discovered product anomalies and vulnerabilities. , support research efforts to identify the causes for discovered product anomalies and vulnerabilities.
- Create formal security test reports and conduct test result reviews with the development team.
- Perform product vulnerability assessments and product security research on Rockwell Automation products.
The Essentials - You Will Have:
- Bachelor's degree in Computer Engineering, Computer Science, Electrical Engineering with a Computer Science emphasis, or a technical degree with a Cyber Security focus. Relevant coursework in software development and object-oriented design and implementation.
- 2+ years of penetration testing experience and a demonstrated understanding of penetration testing methods.
- Experience using multiple programming techniques and scripting languages, Python.
- Understanding of OSI and TCP/IP networking fundamentals and hands-on experience configuring computer networks.
- Familiarity with security verification and validation techniques on embedded products such as threat modeling, vulnerability scanning, fuzz testing (network, protocol, file format, API), and network resiliency testing.
- Understanding of security-by-design principles and fundamental-level security concepts.)
The Preferred - You Might Also Have:
- Master's Degree or advanced courses in Computer Science, Computer Engineering, or a technical degree with a Cyber Security focus.
- Experience programming in object-oriented languages such as C++ and C#.
- More than 1 year of experience with reverse engineering techniques for firmware and software.
- More than 1 year of experience applying AI tools to find security threats and vulnerabilities.
- Experience using security testing tools such as Burp Suite and Nmap.
- Experience with industrial networks and protocols such as CIP, EtherNet/IP, IO-Link, GuardLink, Modbus, and PROFINET.
- Familiarity with hardware debugging and embedded-system interfaces such as UART, SPI, I2C, JTAG and SWD.
- Technical specifications and protocol documentation, and experience with Wireshark-based protocol analysis and troubleshooting.
- Security Testing certifications such as Offensive Security Certified Professional (OSCP), GIAC Penetration Tester (GPEN), CEH Practical, CEH Master, and/or HTB Certified Penetration Testing Specialist HTB CPTS·
- Experience testing wireless technologies such as Wi-Fi, NFC, and Bluetooth.
- Experience performing security tests of Windows-based applications: input validation, authentication and authorization controls, memory corruption, privilege escalation, protocol handling, file parsing, and secure update mechanisms.
What We Offer:
Our benefits package includes …
- Volunteer Paid Time off available after 6 months of employment for eligible employees
- Company volunteer and donation matching program – Your volunteer hours or personal cash donations to an eligible charity can be matched with a charitable donation.
- On-demand digital course library for professional development
- Comprehensive mindfulness programs with a premium membership to Calm
- Employee Assistance Program
- Personalized wellbeing programs through our OnTrack program
... and other local benefits!
#LI-AW2
#LI-Hybrid
Rockwell Automation’s hybrid policy aligns that employees are expected to work at a Rockwell location at least Mondays, Tuesdays, and Thursdays unless they have a business obligation out of the office.