The Division Cyber Security Champion - Lead Engineer will be part of a global team of security experts driving Security by Design philosophy in Eaton product and solutions.
"Division Cyber Security Champion - Lead Engineer will be part of a global team of Cybersecurity experts driving cybersecurity for Eaton Projects in CPS (Critical Power System) division.
He/she will be responsible for:
A. Working closely with CPS divison (Critical Power Systems mainly UPS product line) project teams to drive cybersecurity integration, deployment and monitoring in Eaton products.Act as the technical point-of-contact for product teams and customers; present security posture, roadmaps, and trade-offs to engineering and leadership.
B. Be accountable for identifying, reporting, and mitigating cybersecurity risks within the division, including impact assessments on financial, safety, and operational aspects.Translate customer/industry cybersecurity requirements into actionable product controls; assess impact on architecture, cost, and timelines
C. Driving Threat Modeling and Risk Assessment exercise with product teams early in the design and development phase to identify applicable cybersecurity requirements focusing embedded and cloud products, in line with various cybersecurity standards. Lead or facilitate architecture reviews and threat modeling; recommend mitigations across firmware, software, hardware, and connectivity.
D. Providing hands-on guidance to product teams as they implement complex cybersecurity features and requirements in their products, in line with various cybersecurity standards.
D. Evangelizing and providing technical security trainings to software developers and test engineers across the organization and evangelizing the importance of cybersecurity in other functions like product / project management & sales /services.
E. Monitoring evolving threat landscape, cybersecurity technologies, Power Management Systems, Embedded Containers security, standards, frameworks and drive continuous improvement in Eaton s cybersecurity requirements, frameworks and processes.
F. Working with project teams, to provide continuous threat modeling, risk assessment, Tool based assessments, SAST, SCA and other automated tool runs, in CI/CD pipelines across scrum teams doing product development in Agile mode. Own or co-author key cybersecurity documents (e.g., Cybersecurity Product Requirements, Detailed Requirements Annexure, Design & Implementation Review, Secure Configuration Guidance, Vulnerability Management Plan, EULA inputs)
G. Collaborate with product teams to define and interpret cybersecurity requirements, assess their impact on product design and development, and identify robust technical solutions to ensure compliance and security throughout the product lifecycle
H. Drive shift-left practices; onboard projects to enterprise platforms (Code Signing, Black Duck SCA, Coverity SAST) and enforce gating criteria.
I. Coach engineers and champion security culture; help define role-based training paths and uplift maturity."