
Junior Cyber Security Engineer
Actalent · Posted today
- Pune/Pimpri-Chinchwad Area (Hybrid)
- Hybrid
- Full-time
- 3-6 yrs
About the role
Job Title: Junior Cyber Security Engineer
Job Description
The Junior Cyber Security Engineer supports the secure development lifecycle across products by coordinating security activities, driving audits and assessments, and helping embed product security best practices into development and business processes. This role works closely with cross-functional teams and business units to identify, assess, and prioritize product risks, manage vulnerabilities, and support incident response activities. The position is ideal for a security-minded engineer with a strong foundation in electronics or related fields who wants to grow in product and industrial cyber security.
Responsibilities
- Coordinate and manage the implementation of secure development lifecycle activities across products and projects.
- Drive audits and assessments for new product development processes to ensure that cybersecurity deliverables are complete and effective.
- Participate in key projects as the product security functional representative, providing guidance on security requirements and controls.
- Collaborate with business units to inventory products and assist in prioritizing product risks based on business impact and threat exposure.
- Organize and manage product risk assessments, including TARA (Threat Analysis and Risk Assessment), vulnerability assessments, and threat modeling efforts.
- Support vulnerability management by helping to identify, track, and remediate security vulnerabilities in products and related systems.
- Create, organize, and participate in cross-functional and business unit communities that promote secure development and product security best practices.
- Maintain and update artifacts, documentation, and a central repository of communications and information related to product security functions and teams.
- Assist in analyzing product security market and technology trends to inform improvements to security processes, controls, and technologies.
- Support training and development efforts for various organizational functions, focusing on product security-related roles and responsibilities.
- Maintain familiarity with relevant industry standards and frameworks, such as IEC standards (including ISA99), ISO/IEC standards, the EU Cyber Resilience Act, and NIST SP 800-218, and apply them in day-to-day work.
- Support the organizational Product Security Incident Response Team (PSIRT) in handling product security incidents and coordinating responses.
- Assist in vulnerability management activities, including monitoring, triage, and coordination of remediation actions.
- Establish and enhance strong working relationships with business unit team members, organizational functions, and external business partners to advance product security objectives.
- Contribute to secure coding practices and code review processes by applying security principles and recognized security standards.
- Support the use and management of software bills of materials (SBOM) to improve transparency and control over software components used in products.
- Essential Skills
- Bachelor's degree and/or equivalent years of relative experience.
- 3 - 6 years of experience with product security standards and initiatives or practical work experience related to the implementation of products, services, and solutions.
- Hands-on experience with standards and risk management frameworks such as IEC standards (including ISA99), NIST SP 800-218, COBIT, and other NIST guidance.
- Practical experience in risk assessment, including Threat Analysis and Risk Assessment (TARA), vulnerability assessments, and gap analysis.
- Experience with threat modeling methodologies and tools for identifying and addressing product security threats.
- Knowledge of the Cyber Resilience Act and related regulatory or industry requirements affecting product security.
- Understanding of technology trends and current product security issues, particularly those specific to control systems and related industrial products.
- Experience with project management and development processes, including working within structured product development lifecycles.
- Experience working with recognized security-related standards and technologies relevant to product and industrial cyber security.
- Experience with software bills of material (SBOM), including their creation, maintenance, and use in vulnerability and risk management.
- Experience with secure coding practices and code review processes, including the ability to identify common security weaknesses in code.
- Prior experience in the industrial, factory automation, or control systems industry, with exposure to operational technology environments.
- Strong ability to collaborate with cross-functional teams and communicate security requirements and findings clearly.
- Additional Skills & Qualifications
- Familiarity with IEC (including ISA99), IEC, ISO/IEC, and other relevant international standards related to industrial and product cyber security.
- Awareness of emerging product security market and technology trends and their implications for secure product development.
- Experience contributing to or supporting Product Security Incident Response Teams (PSIRT) and vulnerability management programs.
- Ability to develop and deliver training or awareness materials related to product security roles and responsibilities.
- Experience participating in communities of practice or cross-functional working groups focused on secure development and product security.
- Interest in deepening expertise in control systems security, industrial automation, and secure product design.
- Strong organizational skills with the ability to maintain comprehensive documentation and centralized repositories of security artifacts.
- Work Environment
- The Junior Cyber Security Engineer works in a collaborative, cross-functional environment that spans engineering, product development, and business units focused on secure product design and lifecycle management. The role involves regular interaction with development teams, product managers, and security specialists to integrate security into product planning, design, implementation, and maintenance. You will use industry-standard frameworks and technologies, including IEC and ISO/IEC standards, NIST SP 800-218, COBIT, and tools that support risk assessment, TARA, vulnerability assessments, threat modeling, SBOM management, and secure coding practices. The work typically follows structured project and development processes, with a focus on documentation, audits, and continuous improvement of security practices. The position is primarily office- or hybrid-based, using standard business productivity and collaboration tools, and does not impose a specific dress code beyond typical professional or business-casual attire appropriate for a technical and corporate environment.
- Diversity, Equity & Inclusion
- At Actalent, Diversity And Inclusion Are a Bridge Towards The Equity And Success Of Our People. DE&I Is Embedded Into Our Culture Through
- Hiring diverse talent
- Maintaining an inclusive environment through persistent self-reflection
- Building a culture of care, engagement, and recognition with clear outcomes
- Ensuring growth opportunities for our people
- Actalent is an equal opportunity employer. About Actalent
- Actalent is a global leader in engineering and sciences services. For more than 40 years, weve helped visionary companies advance their goals. Headquartered in the United States, our teams span 150 offices across North America, EMEA, and APACwith four delivery centers in India led by 1,000+ extraordinary employees who connect their passion with purpose every day. Our Bangalore, Hyderabad, Pune, and Chennai delivery centers are hubs of engineering expertise, with core capabilities in mechanical and electrical engineering, systems and software, and manufacturing engineering. Our teams deliver work across multiple industries including transportation, consumer and industrial products, and life sciences. We serve more than 4,500 clients, including many Fortune 500 brands. Learn more about how we can work together at actalentservices.com.
Skills
Threat Analysis and Risk Assessment (TARA)Vulnerability assessmentsGap analysisProject managementSecure coding practicesCode review processesSBOM creation, maintenance, and use in vulnerability and risk management