Work Model: Hybrid – approximately 2 days per week onsite
Role Overview
We are seeking a highly experienced Principal Engineer – Cybersecurity R&D to provide technical leadership and help build a team operating at the forefront of cybersecurity.
This role will focus on building and sustaining secure routers, switches, firewalls, and network operating systems, with responsibilities spanning system security, applied cryptography, security certifications, Secure Development Lifecycle (SDL), and AI-assisted vulnerability discovery and remediation.
Key Responsibilities
- Support product security certifications including NIST FIPS 140, Common Criteria, and the EU Cyber Resilience Act (CRA).
- Drive the development and enhancement of product security capabilities, including:
- Certification gap analysis
- Risk-based threat modeling
- Static and dynamic security analysis
- Penetration testing
- Hardware security assessments
- AI-enhanced vulnerability discovery and management
- Identify and evaluate emerging cybersecurity technologies that can strengthen product security and development processes.
- Partner with senior technical leaders and management to define the cybersecurity technology roadmap and lead hands-on execution.
- Influence key stakeholders across executive leadership, engineering, platform teams, product management, and customers.
- Provide technical guidance and mentorship to engineers while promoting excellence in secure design and development.
Education & Experience
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, or a related technical discipline.
- 10+ years of relevant cybersecurity or product security experience.
- Demonstrated experience providing technical leadership in complex security environments.
Technical Skills
- Deep expertise in cybersecurity, product security, and secure software development.
- Strong knowledge of networking and network security protocols, including TLS, SSH, and IPsec.
- Strong understanding of cryptography and its implementation within networking products.
- Programming experience with C and Python; Rust experience is highly desirable.
- Hands-on experience driving security certifications such as FIPS 140 and Common Criteria, including gap analysis, product preparation, pre-testing, third-party lab submission, and certification.
- Familiarity with the EU Cyber Resilience Act (CRA) or ability to quickly develop expertise in its requirements.
- Experience using AI systems for defensive cybersecurity, particularly vulnerability discovery, analysis, remediation, and vulnerability management.
- Understanding of AI governance and human-in-the-loop security practices.
- Experience with threat modeling, static analysis, dynamic analysis, penetration testing, and hardware security.
- Strong ability to adapt to rapidly evolving cybersecurity threats, technologies, and defensive strategies.
Leadership & Communication
- Ability to provide hands-on technical leadership for complex cybersecurity initiatives.
- Strong written and verbal technical communication skills.
- Ability to explain complex security concepts and influence both technical and executive stakeholders.
- Experience mentoring engineers and helping establish strong cybersecurity engineering practices.