Job Description
Req ID:  51243
Job Location:  Nanjing, CN
Employment Type:  Full Time
Segment:  Danfoss Power Solutions Segment
Job Category:  R&D, Technology and Engineering
Work Location Type:  On-site
Job Title:  Cyber Security Engineer

The Impact You'll Make

1. Lead the completion of TARA (Threat Analysis and Risk Assessment) for the project, identify key assets, attack paths, and threat scenarios, define Cybersecurity Goals and Cybersecurity Requirements.

2.Guide hardware, software, and system teams in designing and implementing security mechanisms (such as secure boot, secure communication SecOC, secure debugging, secure flashing, HSM applications, etc.) to ensure that products comply with regulatory requirements such as UN R155/R156.

3.Establish and maintain the company's network security process (CSMS related parts), act as a cross departmental (system, software, hardware, testing, functional security) "security architect", and promote the implementation of the "Security by Design" concept.

What You’ll Be Doing

1.Lead TARA analysis for new projects/features, based on ISO/SAE 21434 methodology (such as STRIDE model), identify key assets, potential attack vectors, and threat scenarios at the ECU/system level, and evaluate their impact level and attack feasibility.

2.Based on the TARA results, define the network security objectives and concepts of the product, and refine them into traceable network security requirements (covering hardware, software, and system levels).

3. Deeply participate in system and software/hardware architecture design reviews, lead the design and implementation of security mechanisms, including but not limited to:Secure Boot、Secure OTA/Diagnostic Update、HSM intergaration、Secure Debug and Secure Logging etc.

4. Collaborate with the testing team to develop a network security verification plan, including fuzz testing, penetration testing, and vulnerability scanning, to ensure the effectiveness of security control measures.

5. Evaluate the network security capabilities of components provided by suppliers (Tier 1/Tier 2) such as MCUs, HSMs, and communication modules, and review their security manuals and compliance certificates.

6. Cooperate with the company's PSIRT (Product Safety Incident Response Team) mechanism to conduct impact assessments and response support for newly discovered vulnerabilities or security incidents in existing fleets.

What We're Looking For

1. Bachelor's degree or above, major in computer science, information security, electronic engineering, vehicle engineering, automation, or related fields.

2. Work experience:Over 3 years of work experience in network security or information security related to automotive electronics, industrial control, or embedded systems.Have at least one complete project of network security implementation experience (familiar with the entire process from TARA analysis to mass production SOP).

3. Competence:
     • Deeply understand the ISO/SAE 21434 standard and methodology, familiar with TARA analysis processes and tools (such as Medini Analyze, PTC Integrity, etc.).

   • Familiar with UN R155/R156 regulatory requirements and familiar with the compliance certification process under the WP.29 framework.

   • Proficient in commonly used communication protocols for vehicles (CAN, CAN-FD, LIN, FlexRay, Automotive Ethernet/SOE/IP) and their security extensions (such as SecOC).

   • Have a solid knowledge of embedded systems (MCU/SoC, RTOS/Linux) and understand the working principles of HSM (Hardware Security Module) and TEE (Trusted Execution Environment).

4. Language:Good English reading ability, good learning ability, communication ability, and teamwork spirit.

5. Personal characteristics:Strong team player, having a good character, diligent and dedicated, strong sense of
    work responsibility, and able to withstand work pressure.

What You'll Get from Us

 

  1. We promote from within and support your learning with mentoring, training, and access to global opportunities.
  2. You’ll have flexibility, autonomy, and support to do your best work while maintaining a healthy work-life balance. Your well-being matters to us.
  3. We strive to create an inclusive work environment where people of all backgrounds are respected, and valued for who they are.
  4. You’ll receive benefits like 13th salary, annual bonus, paid vacation, pension plans, personal insurance, and more. These vary by country and contract, but they’re worth asking about—we think they’re pretty great.

Ready to Make a Difference?

 

If this role excites you, we’d love to hear from you! Apply now to start the conversation and learn more about where your career can go with us.

Our Commitment to Transparency

Salary ranges listed reflect only primary location and currency. For local salary ranges and specific benefits in your preferred hiring location, please ask your Talent Acquisition representative for more information.

The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience, and location. Any benefits listed do not promise or guarantee any particular benefit or specific action. They may depend on country or contract specifics and are subject to change at any time without prior notice.

Want to know more? Please visit our FAQ Page.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or other protected category.

Information at a Glance