10+ Years of experience in Software Engineering involving secure product design.
Experience in performing threat modelling of a product
Experience in Software Composition Analysis (SCA) / Static Application Security Testing (SAST) / Dynamic Application Security Testing (DAST) tools, secure coding objectives and principles, vulnerability classification scoring and ranking systems
Implementing PKI infrastructure/Cryptographic Keys, secure boot, secure communications (BLE, WiFi, Zigbee, etc.), Identity management, secure firmware Development, secure firmware updates & patch management, configuration management
Hardening security for binary executable loaded on the device, memory protection process
Knowledge on Internal communications Protocols, Open ports, JTAG debugging, Exacting Firmware from EEPROM /FLASH memory, Tampering
Binary Analysis, Reverse Engineering, Analyzing different file system, Sensitive key and certificates, Firmware Modification
Radio Security Analysis
Secure onboarding & provisioning
Demonstrated experience of leading security tools adoptions such as Black Duck Hub, Coverity, etc. in a regulated environment.
Proficient with ANY of the Cyber Security Standards like ISO 27001/2, NERC, NIST, ISO 15408, ANSI / IEC 62443, GDPR, HIPAA, ISO/IEC 27032
Programming experiences in ANY one or more languages (scripting/functional/imperative -- C/C++, Java, Python, Scala, R, etc)
Hands-on experience with ANY of the encryption (IPSEC, AES, GRE, IKE, MD5, SHA, 3DES), cryptographic standards, communication protocols, security standards, and vulnerabilities
Responsible for entire security compliance of all engineering projects from the third party Security Audit perspective - lead implementation and compliance efforts necessary to achieve the same.
Keyskills: Cybersecurity IPSEC DAST IKE SAST Black Duck Hub AES firmware Development Coverity Binary Analysis GRE GDPR IEC 62443