Product Security Engineer
Emerson · Pune, Maharashtra, India
Emerson · Pune, Maharashtra, India
**Job Summary:** This role is responsible to lead design, development, and testing of product security requirements for embedded industrial products. It demands strong technical expertise in secure development practices, security controls validation, and vulnerability assessment. Based in our Pune, India location, you will be part of the newly formed CrossPortfolio Technology and Innovation team within Emerson. You will be employed at the Emerson Innovation Centre, Pune (EICP). **In This Role, Your Responsibilities Will Be:** Lead execution of firmware, hardware integration, and product security testing activities. Define and review product security architectures including secure boot, firmware integrity, authentication, and vulnerability mitigation. Participate in firmware/software requirements analysis and documentation. Perform integration, system, regression, and advanced security testing (fuzzing, protocol security, cryptographic validation). Lead threat model validations and ensure mitigations are implemented and verified. Establish security testing metrics, KPIs, and verification strategies aligned with IEC 62443-4-1. Design and implement security test automation frameworks. Manage vulnerabilities (CVE/CWE), coordinate remediation, and track closure. Review automation code, test plans, and security implementation of team members. Support security incident investigation and root cause analysis. Mentor junior engineers on security tools, methodologies, and secure development practices. Collaborate with architecture and threat modeling teams on risk assessments. **WHO YOU ARE** You balance planning with actions. You stay aligned with your goals and stay productive. You take time to ask questions and define the problem and make learning a priority and a goal. You try different solutions for problems and learn from the results. You make new connections and build relationships in other areas and teams but can be an independent self-starter as needed. You are comfortable reaching out to experts on topics you may not fully understand yet. **For This Role, You Will Need:** - Bachelor's or Master's degree in computer science / Electronics/ Instrumentation or related field - Overall 6-8 yrs of experience in embedded systems Software Verification and Validation and Product Security testing **Required Qualifications:** Experience with hardware–firmware integration and industrial product security testing. Penetration testing expertise using tools such as Burp Suite, Metasploit, or Kali Linux. Experience with fuzzing frameworks (AFL, libFuzzer, Peach Fuzzer). Knowledge of OT/ICS security concepts and NIST Cybersecurity Framework. Experience with industrial protocol security (HART, Modbus, Fieldbus, Ethernet/IP, ProfiNet). Experience using threat modeling tools (e.g., ThreatModeler). Experience with Software Composition Analysis and SBOM management tools. Familiarity with CVE/CWE analysis and vulnerability disclosure processes. Relevant certifications: CEH, OSCP, GPEN, IEC 62443 Specialist.