Senior Cybersecurity Lab Engineer
UL Solutions Bengaluru, Karnataka, India
Professional Services · 10,001+ employees
About the role
The role involves leading cybersecurity laboratory operations, conducting product security evaluations, and performing vulnerability assessments against regulatory standards. You will also manage ISO/IEC 17025 accreditation activities and provide technical leadership to engineering teams.
What they look for
Requirements
Candidates must hold a bachelor's degree in a relevant technical field and possess at least 7 years of experience in cybersecurity or product security testing. Proficiency in security standards, scripting languages, and hands-on experience with penetration testing and risk assessment tools is required.
Full description
We are seeking an experienced cybersecurity professional to support CRA, Product Security, and Cybersecurity Lab services. The role combines cybersecurity assessment, product security testing, regulatory compliance evaluation, and laboratory operations. The successful candidate will support customer projects, cybersecurity testing activities, ISO/IEC 17025 laboratory processes, and service expansion in CRA, IoT Security, and Medical Device Cybersecurity.
Responsibilities
- Conduct cybersecurity assessments, gap analyses, and technical documentation reviews against CRA and related cybersecurity standards.
- Perform vulnerability assessments, penetration testing, threat modeling, and product security evaluations.
- Review cybersecurity risk assessments, SBOMs, secure development lifecycle (SDLC) evidence, and vulnerability management processes.
- Develop and execute cybersecurity test plans, test procedures, and technical reports.
- Lead cybersecurity laboratory operations, test method development, validation activities, and quality processes.
- Lead ISO/IEC 17025 accreditation activities, internal audits, and laboratory readiness initiatives.
- Participate in customer technical discussions, workshops, assessments, and project delivery activities.
- Provide technical leadership, mentoring, and cybersecurity competency development for engineering teams.
- Support proposal development, service scoping, and pre-sales activities.
- Contribute to service development in CRA, IoT device security, and medical device cybersecurity.
Qualifications
Required
- Bachelor's degree in Cybersecurity, Computer Science, Information Security, Electrical/Electronic Engineering, or a related field.
- 7+ years of experience in cybersecurity, product security, security testing, assessment, or related disciplines.
- Strong understanding of:• Network security and communication protocols
- Secure software development practices and principles
- Vulnerability management and risk assessment
- Authentication, authorization, and cryptography
- IoT and embedded systems security
- Experience in Linux and scripting languages (Python, Bash, or PowerShell)
- Familiarity with firmware analysis, reverse engineering, and hardware security testing
- Hands-on experience with: • Vulnerability Assessment
- Penetration Testing
- Fuzz Testing
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Threat Modeling / TARA
- Security Risk Assessment
- Secure Software Development Lifecycle (SSDLC)
- Product Security Evaluation
- Technical Documentation Review
- Experience with one or more of the following standards or regulations: • CRA
- EN 18031
- ETSI EN 303 645
- IEC 62443
- ISO/SAE 21434
- Experience developing test plans, test procedures, and cybersecurity assessment reports.
- Experience supporting cybersecurity laboratory operations.
Preferred
- Experience with EN 18031 and ETSI EN 303 645 test method development, technical evaluation, or reporting for connected or radio-enabled products.
- Strong understanding of of OWASP Top 10, OWASP IoT Top 10, CWE, CVE, MITRE ATT&CK, secure coding principles, cryptography fundamentals, Authentication and authorization
- Experience with ISO/IEC 17025 accredited laboratories, including method validation and verification, internal audits, accreditation preparation, quality management systems, or laboratory operations.
- Knowledge of embedded Linux, RTOS, bootloaders, secure boot, firmware updates, hardware security, and Trusted Platform Module (TPM).
- Experience using security testing tools such as Burp Suite, Nessus, Nmap, Wireshark, tcpdump, Defensics, Checkmarx, Black Duck, Coverity, OWASP ZAP, or Metasploit.
- Relevant certifications such as OSCP, OSWE, CISSP, CompTIA Security+, CompTIA CySA+, or ISA/IEC 62443 Cybersecurity Expert.
Similar roles
-
Teamlead Data & Cybersecurity
Cosun Dinteloord, North Brabant, Netherlands · €56K–€74K/yr
-
Cybersecurity GRC Consultant - Categoria protetta L.68/99
BIP Consulting Palermo, Sicily, Italy · €28K–€34K/yr
-
OT Engineer Cybersecurity
Cosun Dinteloord, North Brabant, Netherlands · €54K–€71K/yr
-
Working Student, Security Engineer
GetYourGuide Zurich, Zurich, Switzerland
-
AI Cybersecurity Researcher
Check Point Software Technologies Tel-Aviv, Tel-Aviv District, Israel
-
Three SG - Apprentice Fire and Security Engineer
Apprenticeships at Skills for Security Castle Point, England, United Kingdom · £17K/yr