Systems Security Engineer
careers.actalentservices.com
Job Title: Systems Security Engineer Job Description This role focuses on product cybersecurity for next-generation industrial control and embedded systems, with a strong emphasis on achieving IEC 62443-4-2 certification. You will lead Threat Analysis and Risk Assessment (TARA) activities, translate findings into actionable security requirements, and manage those requirements within tools such as DOORS and Codebeamer.
Working closely with software and systems engineering teams, you will assess architectures, guide implementation of security controls, and support verification, validation, and cybersecurity test planning to ensure robust, certifiable product security. Responsibilities Perform full Threat Analysis and Risk Assessments (TARA) for industrial control and embedded products. Translate TARA findings into clear, actionable product cybersecurity requirements.
Create, manage, and maintain security requirements in requirements management tools such as DOORS and Codebeamer. Drive requirements development and ensure end-to-end requirements traceability for security-related features. Act as the cybersecurity subject matter expert while internal capability is being built, providing guidance and leadership on security best practices. Work directly with software engineering teams to negotiate, refine, and implement cybersecurity requirements.
Assess hardware and software architectures to identify compliance gaps and security weaknesses. Review and modify cybersecurity test plans to ensure adequate coverage of security controls and certification needs. Support verification and validation activities for industrial and embedded products from a cybersecurity perspective. Lead and coordinate IEC 62443-4-2 certification readiness activities for the product.
Conduct threat modeling exercises to identify potential attack vectors and mitigation strategies. Perform risk assessments and document findings in a clear, structured manner. Drive the creation of new security requirements based on risk assessment outcomes and evolving cybersecurity standards. Review implementation approaches proposed by developers and challenge them when necessary to uphold security standards.
Collaborate with cross-functional teams to ensure security requirements are integrated into product architecture and design. Essential Skills At least 3 years of experience supporting IEC product cybersecurity activities, with IEC 62443-4-1 and/or 62443-4-2 experience preferred. Demonstrated experience performing Threat Analysis and Risk Assessments (TARA) for industrial or embedded products. Proven ability to translate TARA results into detailed product security requirements.
Hands-on experience managing cybersecurity requirements within requirements management tools such as DOORS and Codebeamer. Ability to read and interpret software architecture and understand complex system designs. Capability to assess embedded software and system architectures and work directly with engineering teams to implement security requirements. Experience supporting verification, validation, and cybersecurity test plan reviews for industrial or embedded products.
Strong experience in requirements development, including security requirements definition. Experience with requirements traceability from high-level security objectives down to implementation details. Expertise in security requirements management throughout the product lifecycle. Ability to review implementation approaches and constructively challenge developers when needed to ensure secure solutions.
Skill in performing threat modeling and conducting structured risk assessments. Ability to document cybersecurity findings clearly and comprehensively. Strong communication and collaboration skills to work effectively with software and systems engineers. Additional Skills & Qualifications Experience with additional requirements management tools such as Polarion and Jama. Familiarity with IEC 62443-4-2 certification processes and readine