> Markdown version of [/jobs/ext/3305287-principal-engineer-product-cybersecurity-compliance](https://www.wearedevelopers.com/jobs/ext/3305287-principal-engineer-product-cybersecurity-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Engineer - Product Cybersecurity Compliance - **Company:** JCB - **Location:** Rocester, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Systems Engineering, Cyber Security, Red Team (Cyber Security), Software Vulnerability Management - **Published:** September 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=4a54fbac59eea40f ## About the Role * You have extensive experience within an OEM, Tier 1 supplier, or similar embedded systems environment, working in cybersecurity, systems engineering, compliance or assurance. * You have proven experience in product cybersecurity governance, assurance, compliance assessment or cybersecurity auditing for embedded or cyber-physical products. * You possess strong working knowledge of ISO/SAE 21434 and ISO 24882 and can translate regulatory and standards requirements into practical engineering processes. * You have experience reviewing and assessing cybersecurity evidence, identifying risks and driving corrective actions with stakeholders. * You are an excellent communicator with the ability to influence, challenge and support teams at all levels. * You are recognised as a technical specialist who can lead and drive improvements without direct authority. * You are analytical, pragmatic and comfortable making risk-based decisions. * You enjoy mentoring others and helping teams build cybersecurity capability. * You are self-motivated, resilient and committed to continuous improvement. Even better if… * You have experience with Threat Analysis and Risk Assessment (TARA) methodologies and threat modelling techniques. * You have knowledge of vulnerability management processes and post-production cybersecurity governance. * You have experience of cybersecurity requirements engineering and cybersecurity testing activities, including evidence generation and assessment. * You understand the relationship between Functional Safety and Cybersecurity. * You have experience of embedded product technologies, including ECUs, CAN, J1939 and diagnostic protocols such as UDS. * You have knowledge of IEC 62443 and supplier cybersecurity assurance practices. * You are familiar with Cyber Resilience Act requirements and product security reporting obligations. * You have experience working with Software Bill of Materials (SBOMs) and vulnerability monitoring processes. * You have strong technical writing skills and are comfortable producing governance, assurance and compliance documentation. ## Description We're looking for a Principal Engineer - Product Cybersecurity Compliance, who'll play a critical role in defining, governing and continuously improving JCB's product cybersecurity compliance and assurance framework. As the Product Cybersecurity Compliance Owner, you'll provide technical leadership and independent assurance across product programmes and suppliers, ensuring compliance with internal requirements, industry standards and emerging regulations. You'll be accountable for delivering evidence-based cybersecurity assessments, driving a culture of "no place for second best", and ensuring cybersecurity is embedded throughout the entire product lifecycle, including post-production activities. This is a principal-level position that combines deep technical expertise with strategic leadership, influencing stakeholders across the business and providing direction to cybersecurity testing and vulnerability management activities. The role is instrumental in ensuring JCB's readiness for evolving regulatory requirements, including the Cyber Resilience Act (CRA) and associated reporting obligations. What does this role involve day to day? Lead Product Cybersecurity Governance & Compliance * Own and maintain JCB's product cybersecurity governance and assurance framework, ensuring alignment with wider engineering compliance processes. * Develop and maintain standards, templates, checklists and guidance to support consistent cybersecurity compliance across product programmes. * Create and deliver training, coaching and enablement activities that help engineering teams achieve compliance requirements efficiently and effectively. * Provide mentorship and expert guidance on cybersecurity assurance, governance and regulatory interpretation. Deliver Independent Compliance Assessment & Assurance * Plan and conduct cybersecurity compliance assessments for product programmes and suppliers, identifying risks, gaps and improvement opportunities. * Assess compliance against internal cybersecurity requirements and external standards and regulations, including ISO/SAE 21434, ISO 24882, IEC 62443 and the Cyber Resilience Act. * Review key cybersecurity work products, including Threat Analysis and Risk Assessments (TARA), cybersecurity requirements, architecture evidence, verification strategies and residual risk documentation. * Work collaboratively with engineering, software, systems, verification, manufacturing, service and supplier teams to drive closure of findings. * Act as the escalation point for complex cybersecurity compliance, assurance and regulatory challenges. Provide Technical Leadership for Cybersecurity Testing & Assurance * Define cybersecurity testing expectations, ensuring appropriate coverage, methodologies, reporting and remediation tracking. * Coordinate cybersecurity testing and Red Team assurance activities to support compliance objectives and evidence generation. * Identify and address gaps in testing capability and assurance coverage. Strengthen Vulnerability Management & Post-Production Assurance * Establish and oversee governance for post-production vulnerability management activities. * Ensure vulnerabilities from suppliers, security researchers, testing activities and PSIRT processes are appropriately monitored, assessed and routed. * Support Cyber Resilience Act readiness, including Article 14 reporting workflows and response processes for critical vulnerabilities. * Capture lessons learned and embed improvements into standards, guidance, checklists and training materials. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Automotive Security Challenges: A Supplier's View](https://www.wearedevelopers.com/videos/572-automotive-security-challenges-a-supplier-s-view) - [Model Based Systems Engineering in an Agile Product Development Process](https://www.wearedevelopers.com/videos/68-model-based-systems-engineering-in-an-agile-product-development-process) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Team Red vs. Team Blue: Creating an Internal Nemesis to Drive Innovation](https://www.wearedevelopers.com/videos/1254-team-red-vs-team-blue-creating-an-internal-nemesis-to-drive-innovation) - [Agile work at CARIAD – Creating a customer web application for controlling the vehicle ](https://www.wearedevelopers.com/videos/200-agile-work-at-cariad-creating-a-customer-web-application-for-controlling-the-vehicle) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How software is steering vehicle technology](https://www.wearedevelopers.com/magazine/515-how-software-is-steering-vehicle-technology) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Top Characteristics of a Software Engineer](https://www.wearedevelopers.com/magazine/166-top-characteristics-of-a-software-engineer)