Principal Engineer - Product Cybersecurity Compliance
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We’re looking for a Principal Engineer - Product Cybersecurity Compliance, who’ll play a critical role in defining, governing and continuously improving JCB’s product cybersecurity compliance and assurance framework.
As the Product Cybersecurity Compliance Owner, you’ll provide technical leadership and independent assurance across product programmes and suppliers, ensuring compliance with internal requirements, industry standards and emerging regulations. You’ll be accountable for delivering evidence-based cybersecurity assessments, driving a culture of “no place for second best”, and ensuring cybersecurity is embedded throughout the entire product lifecycle, including post-production activities.
This is a principal-level position that combines deep technical expertise with strategic leadership, influencing stakeholders across the business and providing direction to cybersecurity testing and vulnerability management activities. The role is instrumental in ensuring JCB’s readiness for evolving regulatory requirements, including the Cyber Resilience Act (CRA) and associated reporting obligations.
What does this role involve day to day?
Lead Product Cybersecurity Governance & Compliance
-
Own and maintain JCB’s product cybersecurity governance and assurance framework, ensuring alignment with wider engineering compliance processes.
-
Develop and maintain standards, templates, checklists and guidance to support consistent cybersecurity compliance across product programmes.
-
Create and deliver training, coaching and enablement activities that help engineering teams achieve compliance requirements efficiently and effectively.
-
Provide mentorship and expert guidance on cybersecurity assurance, governance and regulatory interpretation.
Deliver Independent Compliance Assessment & Assurance
-
Plan and conduct cybersecurity compliance assessments for product programmes and suppliers, identifying risks, gaps and improvement opportunities.
-
Assess compliance against internal cybersecurity requirements and external standards and regulations, including ISO/SAE 21434, ISO 24882, IEC 62443 and the Cyber Resilience Act.
-
Review key cybersecurity work products, including Threat Analysis and Risk Assessments (TARA), cybersecurity requirements, architecture evidence, verification strategies and residual risk documentation.
-
Work collaboratively with engineering, software, systems, verification, manufacturing, service and supplier teams to drive closure of findings.
-
Act as the escalation point for complex cybersecurity compliance, assurance and regulatory challenges.
Provide Technical Leadership for Cybersecurity Testing & Assurance
-
Define cybersecurity testing expectations, ensuring appropriate coverage, methodologies, reporting and remediation tracking.
-
Coordinate cybersecurity testing and Red Team assurance activities to support compliance objectives and evidence generation.
-
Identify and address gaps in testing capability and assurance coverage.
Strengthen Vulnerability Management & Post-Production Assurance
-
Establish and oversee governance for post-production vulnerability management activities.
-
Ensure vulnerabilities from suppliers, security researchers, testing activities and PSIRT processes are appropriately monitored, assessed and routed.
-
Support Cyber Resilience Act readiness, including Article 14 reporting workflows and response processes for critical vulnerabilities.
-
Capture lessons learned and embed improvements into standards, guidance, checklists and training materials.
Requirements
-
You have extensive experience within an OEM, Tier 1 supplier, or similar embedded systems environment, working in cybersecurity, systems engineering, compliance or assurance.
-
You have proven experience in product cybersecurity governance, assurance, compliance assessment or cybersecurity auditing for embedded or cyber-physical products.
-
You possess strong working knowledge of ISO/SAE 21434 and ISO 24882 and can translate regulatory and standards requirements into practical engineering processes.
-
You have experience reviewing and assessing cybersecurity evidence, identifying risks and driving corrective actions with stakeholders.
-
You are an excellent communicator with the ability to influence, challenge and support teams at all levels.
-
You are recognised as a technical specialist who can lead and drive improvements without direct authority.
-
You are analytical, pragmatic and comfortable making risk-based decisions.
-
You enjoy mentoring others and helping teams build cybersecurity capability.
-
You are self-motivated, resilient and committed to continuous improvement.
Even better if…
-
You have experience with Threat Analysis and Risk Assessment (TARA) methodologies and threat modelling techniques.
-
You have knowledge of vulnerability management processes and post-production cybersecurity governance.
-
You have experience of cybersecurity requirements engineering and cybersecurity testing activities, including evidence generation and assessment.
-
You understand the relationship between Functional Safety and Cybersecurity.
-
You have experience of embedded product technologies, including ECUs, CAN, J1939 and diagnostic protocols such as UDS.
-
You have knowledge of IEC 62443 and supplier cybersecurity assurance practices.
-
You are familiar with Cyber Resilience Act requirements and product security reporting obligations.
-
You have experience working with Software Bill of Materials (SBOMs) and vulnerability monitoring processes.
-
You have strong technical writing skills and are comfortable producing governance, assurance and compliance documentation.
Benefits & conditions
This is your chance to join a company that values expertise not only in rewards but also in real employee care. At JCB you don’t just get a competitive salary, 33 days’ holiday and access to our company pension-you can also use our onsite gym, in-house doctor and dentist. We have an ULEV car scheme available for our employees too. Then there’s the JCB Rewards Hub, which gives you discounts with high street retailers. Feel like biking to work? There’s our Cycle to Work Scheme.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How software is steering vehicle technology
The 12 Best Jobs for Software Engineers
9 Ways to Make Money Hacking
Now is the time for industrialized software development