The objective of R&D Product Security is to reduce the likelihood and potential impact of a cybersecurity incident on SEL and our customers over the next 5 years. Without cybersecurity, all three tenets of the SEL mission statement are imperiled: Making Electric Power Safer, More Reliable, and More Economical. The strategic pursuit of World-Class Product Security practices is a critical need for SEL and our customers in rising to the challenge of a rapidly evolving security landscape. To meet this need, R&D Product Security is expanding our team of experts to equip our product teams and oversee cybersecurity programs. We are seeking a passionate, seasoned leader to oversee the processes, tools, and systems that govern and manage the SEL Software Supply chain and automated security testing. This is a high-impact role, contributing to large corporate initiatives such as complying with the EU Cyber Resilience Act and improving the robustness of our Secure SDLC. You will lead, supervise, and grow a team of security-minded software engineers to deliver these outcomes. In this role, you will design and develop enterprise-grade approaches and best practices that enable SEL to deploy and demonstrate world-class management of its third-party and first-party firmware and software. This includes defining and governing our processes related to selecting components, ensuring secure provenance of components that we ingest, managing Software Bills of Materials, and managing licenses and risks associated with those components. This will also include defining programs for strengthening relationships with key vendors and sponsorship and/or contribution to key open-source projects. You will also oversee the SEL approach to programming languages and automated security QA, such as automated coding standards, linting, fuzzing and static analysis, that complement our software ingestion processes. You will identify best-in-class tools (as well as AI-driven approaches) and work with the Secure SDLC Automation, Dev Tools, and product teams to implement solutions and drive improved, efficient security outcomes. You will serve as a trusted advisor and consultant for product teams, ensuring that SEL continues to excel at delivering products with world-class security!
Essential Duties and Responsibilities:
Oversee and improve product security programs related to the SEL software supply chain and relevant standards and regulations (such as 62443-4-1 and the Cyber Resilience Act). Oversee the definition, selection, deployment, and associated product outcomes for automated security QA processes and tools. Maintain awareness of developing trends, technologies, and threats related to the secure SDLC. Supervise, lead, mentor, and grow a team of software engineers. Represent SEL at software industry conferences as needed. Model, teach, and apply SEL values and the Principles of Operations.
Required Qualifications:
B.S. degree in Computer Science or equivalent experience. 8+ years software product development experience across the full Secure SDLC, including at least one of the following areas: Embedded development, Cloud-native development, Web development 3+ years of experience with technical leadership in software development. Demonstrated proficiency with multiple programming languages Demonstrated experience with software supply chain practices and tools Excellent leadership and communication skills Ability to learn new skills and assume new responsibilities Willingness to travel occasionally (