Principal Product Cybersecurity Assurance Engineer
H
Humanoid
Уровень
Lead
Формат
Office
О роли
Описание вакансии
About the company
Humanoid is building the world's most capable, commercially-scalable, and safe humanoid robots.
The role sits within the Systems Engineering and Architecture Team, working on the HMND 01 platform family (Alpha Wheeled and Alpha Bipedal) powered by the KinetIQ VLM/VLA-based AI framework.
Responsibilities
Lead and develop a cross-functional team of security engineers, maintaining accountability for the delivery of product security services within product teams throughout the HMND 01 development lifecycle.
Define product security requirements and advise development teams on suitable implementation standards, techniques, and toolchains for embedded and AI-enabled robotic systems.
Partner with cross-functional teams to develop security protocols, tools, and processes.
Own and maintain key security artefacts: Security Management Plans, Threat Analysis and Risk Assessment (TARA) reports, Risk Assessments, and Remediation Action Plans.
Drive security assurance through the full product lifecycle.
Ensure compliance with cybersecurity obligations under the EU Machinery Regulation 2023/1230, IEC 62443, and the EU Cyber Resilience Act.
Provide independent Information Assurance (IA) reviews and risk assessments on complex, high-impact projects.
Establish and maintain a Product Security Incident Response (PSIR) process.
Define and oversee security monitoring requirements for deployed fleets.
Support the production of work package descriptions and cost estimates for product bids.
Represent Humanoid's security posture in customer and partner engagements.
Requirements
Proven, hands-on experience with ISO 27001/27004/27005 and the NIST Risk Management Framework (RMF), applied to regulated hardware or embedded product programmes.
Experience owning a security risk management system for highly regulated, safety-critical products (automotive, commercial vehicle, or industrial automation).
Working knowledge of IEC 62443, with the ability to adapt ISO/SAE 21434 lifecycle methodologies to robotic or electromechanical product context.
Solid understanding of engineering development lifecycles.
Ability to interpret Penetration Test reports and author Remediation Action Plans.
Clear, structured communication skills.
Conditions
Preferred: familiarity with TARA or equivalent threat modelling methodologies (STRIDE, PASTA) applied to embedded or OT/IT convergent systems.
Understanding of secure-by-design principles for AI/ML-enabled systems.
Exposure to CAN bus, Ethernet backbone, or wireless interface security in mobile, vehicular, or robotic systems.