Senior Lead Engineer - Product Cyber Security

Unit 2A & 2B (Octave Block), 6th floor, Parcel - 4, Salarpuria Sattva - Knowledge City, Madhapur, Hyderabad, Telangana, India, Zip/Postal Code: 500081

Otis Elevator Co.

Otis is a leading manufacturer and maintainer of Elevators, Escalators, Moving Walkways with world class modernization tools & service packages for buildings

View all jobs at Otis Elevator Co.

Apply now Apply later

Date Posted:

2025-03-20

Country:

India

Location:

Unit 2A & 2B (Octave Block), 6th floor, Parcel - 4, Salarpuria Sattva - Knowledge City, Madhapur, Hyderabad, Telangana, India, Zip/Postal Code: 500081

Job Title: Senior Lead Engineer - Product Cyber Security

Years Of Experience: 8-12 Years

Role Overview:

The Security Sr Lead Engineer/Tech Specialist works with product development teams across all regions globally to ensure commitment to the cyber security strategy of minimizing flaws and improving product resiliency to cyber-attacks by ensuring adherence to the integrated secure development lifecycle process, which embodies a secure-by-design defense in depth philosophy. You will be a strong technical expert in matters related to pentesting and cyber controls and will report to a team manager responsible for product architecture review and testing. This role is part of the Product Cyber team (under the Global DT Cyber team) which focuses on continuously improving the cyber posture of products that are often installed in customer's environments.

On a typical day you will:

  • Perform DAST, SAST & Pentest for different products
  • Perform Threat Modeling and Architecture reviews for new products and design changes with existing products
  • Handle Product Cyber Incident Response activities and Active contribution to Risk Management
  • Work with product development teams towards secure DevOps activities and CI/CD integration issues with Security tools
  • Work with product development teams and carry out functional cyber risk assessments to support their cyber requirements throughout the entire development cycle.
  • Coordinate with quality and product development teams to periodically update cyber security design policies and ensure that these policies are incorporated into product design, with requirements for traceability and system validation and verification.
  • Interface with global teams and share best practices and lessons learned
  • Refine and support the standard work associated with product cyber security incident response management
  • Work closely with the product testing teams to validate recommended security controls
  • Continually enhance the capabilities of the Cyber security team:
  • Identification of technology and methodology gaps
  • Participation and leading technical and industry committees
  • Creation of discipline health score card.
  • Work in an environment of continuous improvement and lean process and product development. good to have knowledge in Agile methodologies.
  • Stay updated on latest cyber security hacking news, technologies and methodologies including:
  • The latest attack methodologies include penetration testing and red-team methodologies.
  • Latest forensic and incident response methodologies.
  • Attend security or hacker conferences and stay on the cutting edge

What You Will Need to be Successful:

  • Bachelor of Science/Engineering in cyber security, computer science or a related engineering discipline
  • 10+ years of product cyber security engineering and software systems development experience; at least 4 years hands-on experience with penetration testing methodologies and tools.
  • In depth knowledge of IEC 62443 and related cybersecurity standards.
  • In-depth knowledge of requirements captures, cyber security threat modeling and systematic discovery of threats, as part of Secure Development Lifecycle, with broad understanding of potential vulnerabilities at different layers of hierarchical systems
  • Cyber security certifications such as OSCP, GSEC, CEH
  • Knowledge of state-of-the-art security analysis tools and various product cyber security safeguards. These include threat modeling, source code analysis, dynamic analysis, penetration testing and audit/compliance tools
  • Excellent written and verbal communication and presentation skills. Adept at communicating with globally disperse cross functional teams.
  • (Preferred) Strong knowledge in various cryptographic systems and requirements for authentication, authorization and encryption for various types of systems
  • (Preferred) Intimate knowledge and experience with incident response management and risk assessment

If you live in a city, chances are we will give you a lift or play a role in keeping you moving every day. 

Otis is the world’s leading elevator and escalator manufacturing, installation, and service company. We move 2 billion people every day and maintain approximately 2.2 million customer units worldwide, the industry's largest Service portfolio.  

You may recognize our products in some of the world’s most famous landmarks including the Eiffel Tower, Empire State Building, Burj Khalifa and the Petronas Twin Towers! We are 69,000 people strong, including engineers, digital technology experts, sales, and functional specialists, as well as factory and field technicians, all committed to meeting the diverse needs of our customers and passengers in more than 200 countries and territories worldwide. We are proud to be a diverse, global team with a proven legacy of innovation that continues to be the bedrock of a fast-moving, high-performance company.  

When you join Otis, you become part of an innovative global industry leader with a resilient business model. You’ll belong to a diverse, trusted, and caring community where your contributions, and the skills and capabilities you’ll gain working alongside the best and brightest, keep us connected and on the cutting edge.  

We provide opportunities, training, and resources, that build leadership and capabilities in Sales, Field, Engineering and Major Projects and our Employee Scholar Program is a notable point of pride, through which Otis sponsors colleagues to pursue degrees or certification programs.   

Today, our focus more than ever is on people. As a global, people-powered company, we put people – passengers, customers, and colleagues – at the center of everything we do.  We are guided by our values that we call our Three Absolutes – prioritizing Safety, Ethics, Quality in all that we do. If you would like to learn more about environmental, social and governance (ESG) at Otis click here.  

Become a part of the Otis team and help us #Buildwhatsnext! 

Otis is An Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class. To request an accommodation in completing an employment application due to a special need or a disability, please contact us at careers@otis.com.

Privacy Policy and Terms:

Click on this link to read the Policy and Terms

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0

Tags: Agile CEH CI/CD Code analysis Compliance Computer Science DAST DevOps Encryption Governance GSEC IEC 62443 Incident response Octave OSCP Pentesting Privacy Risk assessment Risk management SAST Security analysis Security strategy Strategy Vulnerabilities

Perks/benefits: Conferences Team events

Region: Asia/Pacific
Country: India

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.